these 94 derivations will be built: /nix/store/0aznxyzb6x331csg7gjn8cw5xl2605pi-system-path.drv /nix/store/fa3m94n9x9h6rvcvv1b7xmbvzxxndg04-system-path.drv /nix/store/h8wqiaffc333h4n15l9fq1wrz4849l51-dbus-1.drv /nix/store/m5iwi6jigzhhka4fg48a5vdkd9b03dh5-X-Restart-Triggers-dbus-broker.drv /nix/store/c5ddj5j6j88aw15558234rxzaq62jifn-unit-dbus-broker.service.drv /nix/store/dgqk1h0g77qqw6hmicfx279cjhgmihaf-nss-cacert-3.126.drv /nix/store/rmyrlig3bhx4sq1lwsppdaymnhlcc82z-unit-nix-daemon.service.drv /nix/store/0f2as55c4gc04klb6r66p39glws5chdc-system-units.drv /nix/store/6855qyfnz0gs4rb5b4vjlakqwsx0c0pl-system-path.drv /nix/store/fic80krmpyc0vdr46jg8vn3n1f0g2j73-dbus-1.drv /nix/store/mrnpn8dw7zhx50b8swf2sk27a7pj7fa5-X-Restart-Triggers-dbus-broker.drv /nix/store/rkdgv9ib3kg999rh445ciz27785ymvsz-unit-dbus-broker.service.drv /nix/store/0ksihnydzfrkng1zyj3i8a7lx7djrxf7-user-units.drv /nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv /nix/store/pz8cs4lg35mq4mi7ck3am5chl70g70yx-firewall-start.drv /nix/store/1h3016b7n1wag10qh4dax4mdvk4hiydh-firewall-reload.drv /nix/store/79kfpjcg65c0rrnp43qfppivwzfx8yvi-10-acme.conf.drv /nix/store/3rxxn6h88dq0dw8c0jb09b175y7dx7ys-tmpfiles.d.drv /nix/store/gml8r4jzrx8pxi8kgp8dskjbyaw0a0fs-dbus-1.drv /nix/store/zaygn692fzw3y7hvi0y2nspp3vxdf4zf-X-Restart-Triggers-dbus-broker.drv /nix/store/k7p5hmpmjprhf8avpip5hqgwal6ynyar-unit-dbus-broker.service.drv /nix/store/5byjaqq8fvvhkpibph0xvk5464lnadf5-user-units.drv /nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv /nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv /nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv /nix/store/p58gpq8dlbza3dklkqrzwj7blz2knydv-nginx-recommended-proxy_set_header-headers.conf.drv /nix/store/nhdqpb9g186ppk9rw2dca68wblx9c55n-nginx.conf.drv /nix/store/8r2n0nnbw3cy9i4lhhp2rxgf92jr529b-unit-script-nginx-pre-start.drv /nix/store/6411lsfhmk6d5g1g3ycky8akcw2v4k1q-unit-nginx.service.drv /nix/store/hs99159j81qn0az4shv3wsg7w88r184r-ca.json.drv /nix/store/9k3l9cgj505i3vby9c2w4pi4ky144vh8-X-Restart-Triggers-step-ca.drv /nix/store/hs9qvq7pcc4n5vv0j6qbvbr8y0a84l63-unit-step-ca.service.drv /nix/store/if2dfikfrcj1g6phg8p3i4r8h3bh1h2i-unit-dbus-broker.service.drv /nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv /nix/store/j3lmyghsa4g7nacl7gf67lvx5m91k2br-unit-script-acme-setup-start.drv /nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv /nix/store/ra9f6mzgpig8bxfp26sd4f4dhdymamc3-unit-firewall.service.drv /nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv /nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv /nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv /nix/store/sg6xid8vdr82bvgaxxp97z15ijj6xlyh-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/wdrjpapm3vz3asakl6v1mj7l3ps5ri5r-unit-systemd-tmpfiles-resetup.service.drv /nix/store/84zk8lr7aaw16vfbnpb2r62817azip24-system-units.drv /nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv /nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv /nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv /nix/store/c2pygc22m06f5j91981i00smr1dw9d9f-user-generators.drv /nix/store/ikk469l2wssyvzhq1n3iyvza3f30jvc5-system-shutdown.drv /nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv /nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv /nix/store/kv244kzjv2wsq4aj781mgqyi03rkwppz-system-generators.drv /nix/store/30j4ddsz98cgqwacrzi767gyxkcbl773-etc.drv /nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv /nix/store/4d11adikk9i02khvknlf61i542avljxa-nginx.conf.drv /nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv /nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv /nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv /nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv /nix/store/kjql7xf5v2jlgmmrdnz87nan6jmlgyaj-unit-script-nginx-pre-start.drv /nix/store/ihcyabx8107x0z51x1p00ss738m1by4z-unit-nginx.service.drv /nix/store/ma7d068wl7r81dsprwq8db0ccvml111w-unit-dbus-broker.service.drv /nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv /nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv /nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv /nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv /nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv /nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv /nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv /nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv /nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/yigw63vah8mqdjzj83k0xrr5wjbifc99-system-units.drv /nix/store/cii4hg5k0z8vzdd13glsqjslcx0lhay4-etc.drv /nix/store/7ym358f59gg21gzjkm7gdgk0lpwzqxii-activate.drv /nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv /nix/store/k1skmcwrc73n0qpfb8n22k6qkbh3zpa1-nixos-system-server-test.drv /nix/store/88s87q1nv4kj42qdfng1cxgqcq8c15qf-run-server-nspawn.drv /nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv /nix/store/jxm6hpbyi9ja04zj89z6qzrwjy2pk16q-unit-dbus-broker.service.drv /nix/store/ya9vnsc16n65kc9lhqmjnniq63dvccgk-user-units.drv /nix/store/v8wvv1r4r7nwnh1nbn1l9kp83vxdqpf5-etc.drv /nix/store/k53rzjddsrbdy2xhfpblg3yq959aby47-activate.drv /nix/store/9wla7x05ifyzp0iwqppdqb8hfxr1ylmz-nixos-system-client-test.drv /nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv /nix/store/bm2jsgph9nmz6wx18fprjqgjzcyqhka8-activate.drv /nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv /nix/store/bxgsy2a412bgq6iq69s95ksjv35m8kgf-nixos-system-ca-test.drv /nix/store/ha7r36agq5q59aj2kfg2l9xsy7zszhhq-run-client-nspawn.drv /nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv /nix/store/p1s684niv0ig7yz60byr8bxwswmkhr6a-run-ca-nspawn.drv /nix/store/m832s016n7n1gr5fl7fg9hlqwkg6icmi-driverConfiguration.json.drv /nix/store/l6bd93a9wnshagla7yy47qdb8lsg31dc-nixos-test-driver-certificates.drv /nix/store/mpilmd6d638gwswmlkdcahqr5nb87467-container-test-run-certificates.drv these 9 paths will be fetched (37.9 MiB download, 131.9 MiB unpacked): /nix/store/3japwvq6a40ykrmxjjjvm695q2z6c66c-flock-0.4.0 /nix/store/6nr0a4775j5z9nr71ciasfd9pzz076zs-gixy-0.1.21 /nix/store/p12aczsxidgl3m4jkpc4dl4y7kzf8vck-lego-4.35.2 /nix/store/fqcqw4nlcg6q6n77z3gnxhgg3ll6gjvy-minica-1.1.0 /nix/store/g59y871mjn55fgjswdn72g51qc62j6wa-nginx-config-formatter-1.4.0 /nix/store/kjz0wmk9imvcj2nrm6ls5yd4mw8awajj-python3.14-cached-property-2.0.1 /nix/store/pfxx0s91wb2bhph7m1hdmzik1d8r9jn9-python3.14-configargparse-1.7.5 /nix/store/fdr01jdc50hn18dn90hx7q9p2jhkaw6m-python3.14-pyparsing-2.4.7 /nix/store/9zffz42v1gbfs8dwi61v4m09skszgl9x-step-ca-0.30.2 building '/nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0aznxyzb6x331csg7gjn8cw5xl2605pi-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6855qyfnz0gs4rb5b4vjlakqwsx0c0pl-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/fa3m94n9x9h6rvcvv1b7xmbvzxxndg04-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/79kfpjcg65c0rrnp43qfppivwzfx8yvi-10-acme.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p58gpq8dlbza3dklkqrzwj7blz2knydv-nginx-recommended-proxy_set_header-headers.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/pz8cs4lg35mq4mi7ck3am5chl70g70yx-firewall-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/j3lmyghsa4g7nacl7gf67lvx5m91k2br-unit-script-acme-setup-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hs99159j81qn0az4shv3wsg7w88r184r-ca.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dgqk1h0g77qqw6hmicfx279cjhgmihaf-nss-cacert-3.126.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/4d11adikk9i02khvknlf61i542avljxa-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv' building '/nix/store/p58gpq8dlbza3dklkqrzwj7blz2knydv-nginx-recommended-proxy_set_header-headers.conf.drv' building '/nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv' unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled building '/nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv' unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled building '/nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv' unit-acme-renew-test.foo.timer> structuredAttrs is enabled building '/nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv' building '/nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv' building '/nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv' building '/nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv' building '/nix/store/pz8cs4lg35mq4mi7ck3am5chl70g70yx-firewall-start.drv' building '/nix/store/1h3016b7n1wag10qh4dax4mdvk4hiydh-firewall-reload.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv' unit-acme-renew-ca.foo.timer> structuredAttrs is enabled building '/nix/store/j3lmyghsa4g7nacl7gf67lvx5m91k2br-unit-script-acme-setup-start.drv' building '/nix/store/nhdqpb9g186ppk9rw2dca68wblx9c55n-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/79kfpjcg65c0rrnp43qfppivwzfx8yvi-10-acme.conf.drv' building '/nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv' building '/nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv' building '/nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv' building '/nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kv244kzjv2wsq4aj781mgqyi03rkwppz-system-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ikk469l2wssyvzhq1n3iyvza3f30jvc5-system-shutdown.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/c2pygc22m06f5j91981i00smr1dw9d9f-user-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hs99159j81qn0az4shv3wsg7w88r184r-ca.json.drv' ca.json> structuredAttrs is enabled building '/nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv' building '/nix/store/9k3l9cgj505i3vby9c2w4pi4ky144vh8-X-Restart-Triggers-step-ca.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3rxxn6h88dq0dw8c0jb09b175y7dx7ys-tmpfiles.d.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dgqk1h0g77qqw6hmicfx279cjhgmihaf-nss-cacert-3.126.drv' nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/y8f08mi4a2a6iqczil92gljbfdmjx8hs-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/y8f08mi4a2a6iqczil92gljbfdmjx8hs-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/y8f08mi4a2a6iqczil92gljbfdmjx8hs-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/7n5akf9cxacnqbzrfv9svfl6q6c2bs9k-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/7n5akf9cxacnqbzrfv9svfl6q6c2bs9k-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/7n5akf9cxacnqbzrfv9svfl6q6c2bs9k-nss-cacert-3.126-unbundled nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/xix7i5bvh5vkj7vd3wd9179a697sy0kb-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/xix7i5bvh5vkj7vd3wd9179a697sy0kb-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/xix7i5bvh5vkj7vd3wd9179a697sy0kb-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/h31b32hmbl14jj0y9ifbx6r93fg83q6v-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/h31b32hmbl14jj0y9ifbx6r93fg83q6v-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/h31b32hmbl14jj0y9ifbx6r93fg83q6v-nss-cacert-3.126-hashed building '/nix/store/0aznxyzb6x331csg7gjn8cw5xl2605pi-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/4d11adikk9i02khvknlf61i542avljxa-nginx.conf.drv' nginx.conf> structuredAttrs is enabled nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/fa3m94n9x9h6rvcvv1b7xmbvzxxndg04-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/kjql7xf5v2jlgmmrdnz87nan6jmlgyaj-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6855qyfnz0gs4rb5b4vjlakqwsx0c0pl-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/rmyrlig3bhx4sq1lwsppdaymnhlcc82z-unit-nix-daemon.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/gml8r4jzrx8pxi8kgp8dskjbyaw0a0fs-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/fic80krmpyc0vdr46jg8vn3n1f0g2j73-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/h8wqiaffc333h4n15l9fq1wrz4849l51-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/1h3016b7n1wag10qh4dax4mdvk4hiydh-firewall-reload.drv' building '/nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv' building '/nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv' building '/nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv' building '/nix/store/ra9f6mzgpig8bxfp26sd4f4dhdymamc3-unit-firewall.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/nhdqpb9g186ppk9rw2dca68wblx9c55n-nginx.conf.drv' nginx.conf> structuredAttrs is enabled building '/nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv' building '/nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/kv244kzjv2wsq4aj781mgqyi03rkwppz-system-generators.drv' building '/nix/store/c2pygc22m06f5j91981i00smr1dw9d9f-user-generators.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv' building '/nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ikk469l2wssyvzhq1n3iyvza3f30jvc5-system-shutdown.drv' building '/nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv' building '/nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv' building '/nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/8r2n0nnbw3cy9i4lhhp2rxgf92jr529b-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/3rxxn6h88dq0dw8c0jb09b175y7dx7ys-tmpfiles.d.drv' building '/nix/store/9k3l9cgj505i3vby9c2w4pi4ky144vh8-X-Restart-Triggers-step-ca.drv' building '/nix/store/sg6xid8vdr82bvgaxxp97z15ijj6xlyh-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hs9qvq7pcc4n5vv0j6qbvbr8y0a84l63-unit-step-ca.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kjql7xf5v2jlgmmrdnz87nan6jmlgyaj-unit-script-nginx-pre-start.drv' building '/nix/store/h8wqiaffc333h4n15l9fq1wrz4849l51-dbus-1.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/rmyrlig3bhx4sq1lwsppdaymnhlcc82z-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled building '/nix/store/ra9f6mzgpig8bxfp26sd4f4dhdymamc3-unit-firewall.service.drv' unit-firewall.service> structuredAttrs is enabled building '/nix/store/gml8r4jzrx8pxi8kgp8dskjbyaw0a0fs-dbus-1.drv' building '/nix/store/fic80krmpyc0vdr46jg8vn3n1f0g2j73-dbus-1.drv' building '/nix/store/ihcyabx8107x0z51x1p00ss738m1by4z-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/m5iwi6jigzhhka4fg48a5vdkd9b03dh5-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled building '/nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv' unit-acme-ca.foo.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/mrnpn8dw7zhx50b8swf2sk27a7pj7fa5-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv' building '/nix/store/zaygn692fzw3y7hvi0y2nspp3vxdf4zf-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv' unit-acme-test.foo.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/hs9qvq7pcc4n5vv0j6qbvbr8y0a84l63-unit-step-ca.service.drv' unit-step-ca.service> structuredAttrs is enabled building '/nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv' building '/nix/store/sg6xid8vdr82bvgaxxp97z15ijj6xlyh-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' building '/nix/store/wdrjpapm3vz3asakl6v1mj7l3ps5ri5r-unit-systemd-tmpfiles-resetup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv' unit-acme-order-renew-test.foo.service> structuredAttrs is enabled building '/nix/store/8r2n0nnbw3cy9i4lhhp2rxgf92jr529b-unit-script-nginx-pre-start.drv' building '/nix/store/6411lsfhmk6d5g1g3ycky8akcw2v4k1q-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ihcyabx8107x0z51x1p00ss738m1by4z-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/mrnpn8dw7zhx50b8swf2sk27a7pj7fa5-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/m5iwi6jigzhhka4fg48a5vdkd9b03dh5-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/ma7d068wl7r81dsprwq8db0ccvml111w-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rkdgv9ib3kg999rh445ciz27785ymvsz-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/c5ddj5j6j88aw15558234rxzaq62jifn-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jxm6hpbyi9ja04zj89z6qzrwjy2pk16q-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/zaygn692fzw3y7hvi0y2nspp3vxdf4zf-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/if2dfikfrcj1g6phg8p3i4r8h3bh1h2i-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/k7p5hmpmjprhf8avpip5hqgwal6ynyar-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wdrjpapm3vz3asakl6v1mj7l3ps5ri5r-unit-systemd-tmpfiles-resetup.service.drv' unit-systemd-tmpfiles-resetup.service> structuredAttrs is enabled building '/nix/store/6411lsfhmk6d5g1g3ycky8akcw2v4k1q-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/c5ddj5j6j88aw15558234rxzaq62jifn-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ma7d068wl7r81dsprwq8db0ccvml111w-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/jxm6hpbyi9ja04zj89z6qzrwjy2pk16q-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/rkdgv9ib3kg999rh445ciz27785ymvsz-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/0ksihnydzfrkng1zyj3i8a7lx7djrxf7-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ya9vnsc16n65kc9lhqmjnniq63dvccgk-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/if2dfikfrcj1g6phg8p3i4r8h3bh1h2i-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/0f2as55c4gc04klb6r66p39glws5chdc-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/yigw63vah8mqdjzj83k0xrr5wjbifc99-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/84zk8lr7aaw16vfbnpb2r62817azip24-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/k7p5hmpmjprhf8avpip5hqgwal6ynyar-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/0ksihnydzfrkng1zyj3i8a7lx7djrxf7-user-units.drv' building '/nix/store/ya9vnsc16n65kc9lhqmjnniq63dvccgk-user-units.drv' building '/nix/store/5byjaqq8fvvhkpibph0xvk5464lnadf5-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/yigw63vah8mqdjzj83k0xrr5wjbifc99-system-units.drv' building '/nix/store/0f2as55c4gc04klb6r66p39glws5chdc-system-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/84zk8lr7aaw16vfbnpb2r62817azip24-system-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/5byjaqq8fvvhkpibph0xvk5464lnadf5-user-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/30j4ddsz98cgqwacrzi767gyxkcbl773-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v8wvv1r4r7nwnh1nbn1l9kp83vxdqpf5-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/cii4hg5k0z8vzdd13glsqjslcx0lhay4-etc.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/cii4hg5k0z8vzdd13glsqjslcx0lhay4-etc.drv' building '/nix/store/7ym358f59gg21gzjkm7gdgk0lpwzqxii-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/30j4ddsz98cgqwacrzi767gyxkcbl773-etc.drv' building '/nix/store/v8wvv1r4r7nwnh1nbn1l9kp83vxdqpf5-etc.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/k53rzjddsrbdy2xhfpblg3yq959aby47-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7ym358f59gg21gzjkm7gdgk0lpwzqxii-activate.drv' building '/nix/store/k1skmcwrc73n0qpfb8n22k6qkbh3zpa1-nixos-system-server-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bm2jsgph9nmz6wx18fprjqgjzcyqhka8-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/k53rzjddsrbdy2xhfpblg3yq959aby47-activate.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/9wla7x05ifyzp0iwqppdqb8hfxr1ylmz-nixos-system-client-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/k1skmcwrc73n0qpfb8n22k6qkbh3zpa1-nixos-system-server-test.drv' nixos-system-server-test> structuredAttrs is enabled building '/nix/store/9wla7x05ifyzp0iwqppdqb8hfxr1ylmz-nixos-system-client-test.drv' nixos-system-client-test> structuredAttrs is enabled building '/nix/store/ha7r36agq5q59aj2kfg2l9xsy7zszhhq-run-client-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/88s87q1nv4kj42qdfng1cxgqcq8c15qf-run-server-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bm2jsgph9nmz6wx18fprjqgjzcyqhka8-activate.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/88s87q1nv4kj42qdfng1cxgqcq8c15qf-run-server-nspawn.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/bxgsy2a412bgq6iq69s95ksjv35m8kgf-nixos-system-ca-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ha7r36agq5q59aj2kfg2l9xsy7zszhhq-run-client-nspawn.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/bxgsy2a412bgq6iq69s95ksjv35m8kgf-nixos-system-ca-test.drv' nixos-system-ca-test> structuredAttrs is enabled building '/nix/store/p1s684niv0ig7yz60byr8bxwswmkhr6a-run-ca-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/p1s684niv0ig7yz60byr8bxwswmkhr6a-run-ca-nspawn.drv' building '/nix/store/m832s016n7n1gr5fl7fg9hlqwkg6icmi-driverConfiguration.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/m832s016n7n1gr5fl7fg9hlqwkg6icmi-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/l6bd93a9wnshagla7yy47qdb8lsg31dc-nixos-test-driver-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/l6bd93a9wnshagla7yy47qdb8lsg31dc-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! building '/nix/store/mpilmd6d638gwswmlkdcahqr5nb87467-container-test-run-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/mpilmd6d638gwswmlkdcahqr5nb87467-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> ca: systemd-nspawn running (pid 53) container-test-run-certificates> server: systemd-nspawn running (pid 54) container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> client: systemd-nspawn running (pid 55) container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> ca # [6785532.270870] ca systemd-journald[78]: Journal started container-test-run-certificates> ca # [6785532.270931] ca systemd-journald[78]: Runtime Journal (/run/log/journal/7e63e525c42b4810985f5ce7a02d0425) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> ca # [6785532.278395] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [6785532.279225] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [6785532.279878] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [6785532.288663] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/7e63e525c42b4810985f5ce7a02d0425 is 1.243ms for 5 entries. container-test-run-certificates> ca # [6785532.288663] ca systemd-journald[78]: System Journal (/var/log/journal/7e63e525c42b4810985f5ce7a02d0425) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [6785532.299830] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [6785532.300504] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [6785532.300624] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [6785532.301469] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [6785532.301515] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6785532.302415] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [6785532.302456] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [6785532.302994] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [6785532.304694] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [6785532.319267] ca systemd-tmpfiles[124]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [6785532.319478] ca systemd-tmpfiles[124]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [6785532.319617] ca systemd-tmpfiles[124]: fchmod() of /var/log/journal/7e63e525c42b4810985f5ce7a02d0425 failed: Operation not permitted container-test-run-certificates> ca # [6785532.319865] ca systemd-tmpfiles[124]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [6785532.321254] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [6785532.322360] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [6785532.323106] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [6785532.339019] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [6785532.345619] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [6785532.347338] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [6785532.357740] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [6785532.413438] ca systemd[1]: Finished Firewall. container-test-run-certificates> ca # [6785532.413666] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [6785532.413909] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [6785532.414997] ca systemd[1]: Starting Network Management... container-test-run-certificates> client # [6785532.253314] client systemd-journald[69]: Journal started container-test-run-certificates> client # [6785532.253367] client systemd-journald[69]: Runtime Journal (/run/log/journal/767e071c2fc24b09b5f983d2f3fac17d) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> client # [6785532.259507] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [6785532.268164] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [6785532.269058] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [6785532.269768] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [6785532.279200] client systemd-journald[69]: Time spent on flushing to /var/log/journal/767e071c2fc24b09b5f983d2f3fac17d is 953us for 6 entries. container-test-run-certificates> client # [6785532.279200] client systemd-journald[69]: System Journal (/var/log/journal/767e071c2fc24b09b5f983d2f3fac17d) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [6785532.286495] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [6785532.286776] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [6785532.286866] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [6785532.287611] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [6785532.287654] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6785532.288596] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [6785532.288634] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [6785532.292686] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [6785532.294148] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [6785532.308947] client systemd-tmpfiles[115]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [6785532.309119] client systemd-tmpfiles[115]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [6785532.309238] client systemd-tmpfiles[115]: fchmod() of /var/log/journal/767e071c2fc24b09b5f983d2f3fac17d failed: Operation not permitted container-test-run-certificates> client # [6785532.309415] client systemd-tmpfiles[115]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [6785532.310787] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [6785532.311878] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [6785532.312763] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> client # [6785532.325682] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [6785532.254081] server systemd-journald[69]: Journal started container-test-run-certificates> client # [6785532.332430] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [6785532.333599] client systemd[1]: Starting Update is Completed... container-test-run-certificates> client # [6785532.343627] client systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [6785532.394300] client systemd[1]: Finished Firewall. container-test-run-certificates> client # [6785532.394446] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [6785532.394666] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [6785532.254130] server systemd-journald[69]: Runtime Journal (/run/log/journal/d2eae9343c444187b5ef88dfcf0b8f0b) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> server # [6785532.262420] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> server # [6785532.271972] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [6785532.395808] client systemd[1]: Starting Network Management... container-test-run-certificates> server # [6785532.272841] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> server # [6785532.273542] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> server # [6785532.280735] server systemd-journald[69]: Time spent on flushing to /var/log/journal/d2eae9343c444187b5ef88dfcf0b8f0b is 996us for 6 entries. container-test-run-certificates> server # [6785532.280735] server systemd-journald[69]: System Journal (/var/log/journal/d2eae9343c444187b5ef88dfcf0b8f0b) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [6785532.286463] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [6785532.287135] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [6785532.287250] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [6785532.288156] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [6785532.288204] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6785532.289061] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [6785532.289096] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [6785532.292737] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [6785532.294157] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [6785532.311660] server systemd-tmpfiles[116]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [6785532.311890] server systemd-tmpfiles[116]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [6785532.312075] server systemd-tmpfiles[116]: fchmod() of /var/log/journal/d2eae9343c444187b5ef88dfcf0b8f0b failed: Operation not permitted container-test-run-certificates> server # [6785532.312329] server systemd-tmpfiles[116]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [6785532.314241] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [6785532.315350] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [6785532.316157] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [6785532.328221] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [6785532.334584] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [6785532.335704] server systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [6785532.347402] server systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [6785532.415853] server systemd[1]: Finished Firewall. container-test-run-certificates> server # [6785532.416055] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [6785532.416345] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [6785532.417625] server systemd[1]: Starting Network Management... container-test-run-certificates> client # [6785532.821044] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [6785532.821367] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [6785532.827139] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [6785533.237897] ca systemd-networkd[195]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6785533.243219] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [6785533.237989] ca systemd-networkd[195]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6785533.256900] server systemd-networkd[186]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6785533.245211] ca systemd-networkd[195]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6785533.256990] server systemd-networkd[186]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6785533.245374] ca systemd-networkd[195]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6785533.264607] server systemd-networkd[186]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6785533.245540] ca systemd-networkd[195]: lo: Link UP container-test-run-certificates> server # [6785533.264772] server systemd-networkd[186]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6785533.245546] ca systemd-networkd[195]: lo: Gained carrier container-test-run-certificates> server # [6785533.264945] server systemd-networkd[186]: lo: Link UP container-test-run-certificates> ca # [6785533.245757] ca systemd-networkd[195]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [6785533.264948] server systemd-networkd[186]: lo: Gained carrier container-test-run-certificates> ca # [6785533.246130] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [6785533.246200] ca systemd-networkd[195]: eth1: Link UP container-test-run-certificates> ca # [6785533.246407] ca systemd-networkd[195]: eth1: Gained carrier container-test-run-certificates> ca # [6785533.247122] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [6785533.254609] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [6785533.278371] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [6785533.265140] server systemd-networkd[186]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [6785533.265525] server systemd[1]: Started Network Management. container-test-run-certificates> server # [6785533.265647] server systemd-networkd[186]: eth1: Link UP container-test-run-certificates> server # [6785533.265961] server systemd-networkd[186]: eth1: Gained carrier container-test-run-certificates> server # [6785533.266757] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [6785533.294525] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [6785533.181608] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6785533.181702] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6785533.204579] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6785533.204744] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6785533.204913] client systemd-networkd[182]: lo: Link UP container-test-run-certificates> client # [6785533.204917] client systemd-networkd[182]: lo: Gained carrier container-test-run-certificates> client # [6785533.205129] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [6785533.205537] client systemd[1]: Started Network Management. container-test-run-certificates> client # [6785533.205600] client systemd-networkd[182]: eth1: Link UP container-test-run-certificates> client # [6785533.205925] client systemd-networkd[182]: eth1: Gained carrier container-test-run-certificates> client # [6785533.207231] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [6785533.242584] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> client # [6785533.252442] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [6785533.566611] ca systemd-resolved[102]: Positive Trust Anchors: container-test-run-certificates> ca # [6785533.566622] ca systemd-resolved[102]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [6785533.566626] ca systemd-resolved[102]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [6785533.566661] ca systemd-resolved[102]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [6785533.589635] ca systemd-resolved[102]: Using system hostname 'ca'. container-test-run-certificates> ca # [6785533.591084] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [6785533.591186] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [6785533.591262] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [6785533.591319] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [6785533.591589] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [6785533.591625] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6785533.591656] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [6785533.591685] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [6785533.591860] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [6785533.592053] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [6785533.592218] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [6785533.592243] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [6785533.592304] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [6785533.593869] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [6785533.594860] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [6785533.594915] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [6785533.595940] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [6785533.597170] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [6785533.628802] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [6785533.666614] ca systemd[1]: lastlog2-import.service: Failed to spawn executor: No such file or directory container-test-run-certificates> ca # [6785533.666645] ca systemd[1]: lastlog2-import.service: Failed to spawn 'start-post' task: No such file or directory container-test-run-certificates> ca # [6785533.666685] ca systemd[1]: lastlog2-import.service: Failed with result 'resources'. container-test-run-certificates> ca # [6785533.666748] ca systemd[1]: Failed to start Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [6785533.772744] ca acme-setup-privileged[201]: + set -euo pipefail container-test-run-certificates> ca # [6785533.772744] ca acme-setup-privileged[201]: + cd /var/lib/acme container-test-run-certificates> ca # [6785533.772744] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [6785533.774681] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [6785533.776180] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6785533.776257] ca acme-setup-privileged[201]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [6785533.776257] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6785533.776257] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [6785533.816437] ca nsncd[203]: Aug 26 12:15:59.869 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [6785533.816542] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [6785533.816622] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [6785533.816691] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [6785533.569978] client systemd-resolved[94]: Positive Trust Anchors: container-test-run-certificates> client # [6785533.569990] client systemd-resolved[94]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [6785533.569994] client systemd-resolved[94]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [6785533.570036] client systemd-resolved[94]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [6785533.592544] client systemd-resolved[94]: Using system hostname 'client'. container-test-run-certificates> client # [6785533.593928] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [6785533.594004] client systemd[1]: Reached target Network. container-test-run-certificates> client # [6785533.594068] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [6785533.594112] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6785533.594136] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [6785533.594152] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [6785533.594274] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [6785533.594461] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [6785533.594578] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [6785533.594599] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [6785533.594635] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [6785533.595742] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [6785533.596610] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [6785533.597768] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [6785533.643931] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [6785533.795278] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [6785533.795342] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [6785533.795445] client nsncd[189]: Aug 26 12:15:59.848 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [6785533.795401] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [6785533.593404] server systemd-resolved[97]: Positive Trust Anchors: container-test-run-certificates> server # [6785533.593415] server systemd-resolved[97]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [6785533.593419] server systemd-resolved[97]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [6785533.593454] server systemd-resolved[97]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [6785533.615770] server systemd-resolved[97]: Using system hostname 'server'. container-test-run-certificates> server # [6785533.617202] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [6785533.617292] server systemd[1]: Reached target Network. container-test-run-certificates> server # [6785533.617348] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [6785533.617393] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [6785533.617619] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [6785533.617658] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6785533.617682] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [6785533.617699] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [6785533.617841] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [6785533.617961] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [6785533.618072] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [6785533.618092] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [6785533.618130] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [6785533.628902] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [6785533.629926] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [6785533.629978] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [6785533.630902] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [6785533.632194] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [6785533.647446] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [6785533.767516] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> server # [6785533.767516] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [6785533.767909] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> server # [6785533.769424] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> server # [6785533.770801] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [6785533.770829] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> server # [6785533.770829] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [6785533.770829] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> server # [6785533.788937] server nsncd[194]: Aug 26 12:15:59.842 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [6785533.789013] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [6785533.789083] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [6785533.789141] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [6785533.826405] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [6785533.827296] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [6785533.837090] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [6785533.838842] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [6785533.838890] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [6785533.838912] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [6785533.826865] client systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [6785533.826614] ca systemd[1]: Starting User Login Management... container-test-run-certificates> client # [6785533.827897] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [6785533.827515] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [6785533.837093] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [6785533.837353] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [6785533.838391] client systemd[1]: Started Console Getty. container-test-run-certificates> ca # [6785533.838433] ca systemd[1]: Started Console Getty. container-test-run-certificates> client # [6785533.838444] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [6785533.838479] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [6785533.838473] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [6785533.838497] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [6785533.973203] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [6785533.967802] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [6785533.973875] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [6785533.969130] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [6785533.973875] client dbus-broker-launch[190]: Invalid user-name in /nix/store/zrbrcrcf4ksfm9isn90jq44dzyd6g8f3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [6785533.969130] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/gj5k0v2rcdsvmwzrdidpx1a8s0szjk65-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [6785533.974243] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [6785533.969521] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [6785533.982715] client dbus-broker-launch[190]: Ready container-test-run-certificates> ca # [6785533.976923] ca dbus-broker-launch[205]: Ready container-test-run-certificates> server # [6785533.958953] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [6785533.960117] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [6785533.960117] server dbus-broker-launch[195]: Invalid user-name in /nix/store/qlm5ds27nygd7kx149cwgpvarjrvks9s-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [6785533.960537] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [6785533.967364] server dbus-broker-launch[195]: Ready container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> client # [6785534.492242] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [6785534.492446] client systemd[1]: Started User Login Management. container-test-run-certificates> ca # [6785534.508939] ca systemd-logind[229]: New seat seat0. container-test-run-certificates> client # [6785534.493781] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [6785534.532115] client systemd-networkd[182]: eth1: Gained IPv6LL container-test-run-certificates> client # [6785534.572172] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [6785534.572339] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [6785534.572797] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [6785534.573096] client systemd[1]: Startup finished in 2.698s. container-test-run-certificates> ca # [6785534.509145] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [6785534.565226] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [6785534.582725] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [6785534.582827] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [6785534.584887] ca acme-setup-start[217]: + set -euo pipefail container-test-run-certificates> ca # [6785534.584887] ca acme-setup-start[217]: + test -e ca/key.pem container-test-run-certificates> ca # [6785534.585163] ca acme-setup-start[217]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [6785534.603603] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [6785534.605602] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> server # [6785534.491127] server systemd-logind[220]: New seat seat0. container-test-run-certificates> server # [6785534.491340] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [6785534.492679] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [6785534.573345] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [6785534.573613] server systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [6785534.596835] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> server # [6785534.596835] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> server # [6785534.597216] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [6785534.616241] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [6785534.617765] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> ca # [6785534.782937] ca step-ca[204]: badger 2026/08/26 12:16:00 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [6785534.791208] ca step-ca[204]: 2026/08/26 12:16:00 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [6785534.799707] ca step-ca[204]: 2026/08/26 12:16:00 Starting Smallstep CA/0.30.2 (linux/arm64) container-test-run-certificates> ca # [6785534.799707] ca step-ca[204]: 2026/08/26 12:16:00 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [6785534.799707] ca step-ca[204]: 2026/08/26 12:16:00 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [6785534.799707] ca step-ca[204]: 2026/08/26 12:16:00 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [6785534.799840] ca step-ca[204]: 2026/08/26 12:16:00 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [6785534.799840] ca step-ca[204]: 2026/08/26 12:16:00 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [6785534.799840] ca step-ca[204]: 2026/08/26 12:16:00 X.509 Root Fingerprint: 7a856cf932568ccf9b2e70d04a3169330937fca36c9d131456048caa7c0dc90f container-test-run-certificates> ca # [6785534.800261] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [6785534.800471] ca step-ca[204]: 2026/08/26 12:16:00 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> server # [6785535.013991] server systemd-networkd[186]: eth1: Gained IPv6LL container-test-run-certificates> server # [6785535.182745] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6785535.185996] server acme-test.foo-start[245]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6785535.186047] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6785535.196486] server acme-test.foo-start[255]: + cd test.foo container-test-run-certificates> server # [6785535.196833] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6785535.197800] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6785535.198036] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6785535.199096] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6785535.199312] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6785535.200836] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6785535.202351] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6785535.204168] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [6785535.204168] server acme-test.foo-start[245]: + '[' -d out ']' container-test-run-certificates> server # [6785535.204168] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6785535.205830] server acme-test.foo-start[245]: + chown -R acme:nginx out container-test-run-certificates> server # [6785535.208604] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [6785535.208628] server acme-test.foo-start[245]: + '[' -d certificates ']' container-test-run-certificates> server # [6785535.211667] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6785535.213202] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [6785535.108132] ca systemd-networkd[195]: eth1: Gained IPv6LL container-test-run-certificates> ca # [6785535.176680] ca acme-ca.foo-start[254]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6785535.179293] ca acme-ca.foo-start[254]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [6785535.179364] ca acme-ca.foo-start[254]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [6785535.190243] ca acme-ca.foo-start[292]: + cd ca.foo container-test-run-certificates> ca # [6785535.190556] ca acme-ca.foo-start[292]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [6785535.191740] ca acme-ca.foo-start[293]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [6785535.192090] ca acme-ca.foo-start[292]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [6785535.193368] ca acme-ca.foo-start[292]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [6785535.193612] ca acme-ca.foo-start[254]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [6785535.195062] ca acme-ca.foo-start[254]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [6785535.196647] ca acme-ca.foo-start[254]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6785535.198183] ca acme-ca.foo-start[254]: + for fixpath in out certificates container-test-run-certificates> ca # [6785535.198211] ca acme-ca.foo-start[254]: + '[' -d out ']' container-test-run-certificates> ca # [6785535.198211] ca acme-ca.foo-start[254]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6785535.200154] ca acme-ca.foo-start[254]: + chown -R acme:nginx out container-test-run-certificates> ca # [6785535.203261] ca acme-ca.foo-start[254]: + for fixpath in out certificates container-test-run-certificates> ca # [6785535.203289] ca acme-ca.foo-start[254]: + '[' -d certificates ']' container-test-run-certificates> ca # [6785535.206976] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [6785535.209793] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> server # [6785535.919414] server nginx-pre-start[267]: nginx: the configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf syntax is ok container-test-run-certificates> server # [6785535.919755] server nginx-pre-start[267]: nginx: configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf test is successful container-test-run-certificates> server # [6785535.930430] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [6785535.930827] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [6785535.932140] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [6785535.934246] ca nginx-pre-start[304]: nginx: the configuration file /nix/store/y7l31xmgdb36n6qsx9xzk3vs64xjpv8v-nginx.conf syntax is ok container-test-run-certificates> ca # [6785535.934570] ca nginx-pre-start[304]: nginx: configuration file /nix/store/y7l31xmgdb36n6qsx9xzk3vs64xjpv8v-nginx.conf test is successful container-test-run-certificates> ca # [6785535.941039] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [6785535.942480] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [6785535.944767] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca # [6785536.550516] ca acme-order-renew-ca.foo-start[307]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6785536.553530] ca acme-order-renew-ca.foo-start[307]: + set -euo pipefail container-test-run-certificates> ca # [6785536.553612] ca acme-order-renew-ca.foo-start[307]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6785536.553727] ca acme-order-renew-ca.foo-start[307]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6785536.554911] ca acme-order-renew-ca.foo-start[307]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [6785536.569652] ca acme-order-renew-ca.foo-start[318]: 2026/08/26 12:16:02 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [6785536.570132] ca acme-order-renew-ca.foo-start[318]: 2026/08/26 12:16:02 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [6785536.600078] ca step-ca[204]: time="2026-08-26T12:16:02Z" level=info duration="179.402µs" duration-ns=179402 fields.time="2026-08-26T12:16:02Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=ec7bf55f-39d7-4ed0-b938-043889afd872 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6785536.600499] ca acme-order-renew-ca.foo-start[318]: 2026/08/26 12:16:02 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [6785536.675204] ca step-ca[204]: time="2026-08-26T12:16:02Z" level=info duration=74.57445ms duration-ns=74574450 fields.time="2026-08-26T12:16:02Z" method=HEAD name=ca nonce=N1pia1hEQWFEc3hYcXRXUzFud3pYTldnb3BEQ0Nkbkw path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=45034aa7-06e0-4507-95b6-1633379f40e9 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6785536.677645] ca step-ca[204]: time="2026-08-26T12:16:02Z" level=info duration=1.380779ms duration-ns=1380779 fields.time="2026-08-26T12:16:02Z" method=POST name=ca nonce=d0RsUXI3cUsxV0JBVExXN2ZQY3ZqeGo4QVN6d3BVS1U path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=9abc5c22-98f7-4df5-8967-fbe492897780 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/D7v5xIHEsyxNBDGnM8ILm6BAE8QyptkV/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6785536.678057] ca acme-order-renew-ca.foo-start[318]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [6785536.678057] ca acme-order-renew-ca.foo-start[318]: Your account credentials have been saved in your container-test-run-certificates> ca # [6785536.678057] ca acme-order-renew-ca.foo-start[318]: configuration directory at "accounts". container-test-run-certificates> ca # [6785536.678057] ca acme-order-renew-ca.foo-start[318]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [6785536.678057] ca acme-order-renew-ca.foo-start[318]: configuration directory will also contain private keys container-test-run-certificates> ca # [6785536.678057] ca acme-order-renew-ca.foo-start[318]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [6785536.678057] ca acme-order-renew-ca.foo-start[318]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [6785536.678373] ca acme-order-renew-ca.foo-start[318]: 2026/08/26 12:16:02 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [6785536.682742] ca step-ca[204]: time="2026-08-26T12:16:02Z" level=info duration=3.951215ms duration-ns=3951215 fields.time="2026-08-26T12:16:02Z" method=POST name=ca nonce=T2xWeUE3U3Btd0lwT1Ayd1YxRjAwMXY1QkNuOHVYczg path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=65f4bd6d-ae1a-42cc-8895-b2ebe884f386 response="{\"id\":\"uTV1wruqVLnvaqDaqgrKWV70Vu2S2igp\",\"status\":\"pending\",\"expires\":\"2026-08-27T12:16:02Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-26T12:15:02Z\",\"notAfter\":\"2026-11-24T12:16:02Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/XG0wS6ZsLKmT4s3YRQareDDl5DhTpRCd\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/uTV1wruqVLnvaqDaqgrKWV70Vu2S2igp/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6785536.741699] ca step-ca[204]: time="2026-08-26T12:16:02Z" level=info duration=1.948668ms duration-ns=1948668 fields.time="2026-08-26T12:16:02Z" method=POST name=ca nonce=ck9NUnp0RVlpcDg1Q291UGc3T1BXM3ZRamtodFltMDU path=/acme/acme/authz/XG0wS6ZsLKmT4s3YRQareDDl5DhTpRCd protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=6f92427a-a8a6-4f40-b91c-42e20ed58829 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"l27M4lucLdtaIwaVUfC2GqAjlbQiahTT\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/XG0wS6ZsLKmT4s3YRQareDDl5DhTpRCd/rq6cv9uCicGVXZnieTJKEf8BImckd7tn\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"l27M4lucLdtaIwaVUfC2GqAjlbQiahTT\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/XG0wS6ZsLKmT4s3YRQareDDl5DhTpRCd/D42RXDrvMo40aTkE7MvRQBJ0Ce2RkJvN\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"l27M4lucLdtaIwaVUfC2GqAjlbQiahTT\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/XG0wS6ZsLKmT4s3YRQareDDl5DhTpRCd/Cdom49XcQOqA6Ex4r4Wy8L5q4u0Miz9D\"}],\"wildcard\":false,\"expires\":\"2026-08-27T12:16:02Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6785536.741999] ca acme-order-renew-ca.foo-start[318]: 2026/08/26 12:16:02 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/XG0wS6ZsLKmT4s3YRQareDDl5DhTpRCd container-test-run-certificates> ca # [6785536.741999] ca acme-order-renew-ca.foo-start[318]: 2026/08/26 12:16:02 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [6785536.741999] ca acme-order-renew-ca.foo-start[318]: 2026/08/26 12:16:02 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [6785536.741999] ca acme-order-renew-ca.foo-start[318]: 2026/08/26 12:16:02 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [6785536.745827] ca step-ca[204]: time="2026-08-26T12:16:02Z" level=info duration=3.377568ms duration-ns=3377568 fields.time="2026-08-26T12:16:02Z" method=POST name=ca nonce=QzV6aHJBbEk0c0NXbHFIbFg4aHNlN1A2VmxZaElCVFk path=/acme/acme/challenge/XG0wS6ZsLKmT4s3YRQareDDl5DhTpRCd/D42RXDrvMo40aTkE7MvRQBJ0Ce2RkJvN protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=6a44c20b-bac7-42ce-9411-ddcac93c8b56 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"l27M4lucLdtaIwaVUfC2GqAjlbQiahTT\",\"validated\":\"2026-08-26T12:16:02Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/XG0wS6ZsLKmT4s3YRQareDDl5DhTpRCd/D42RXDrvMo40aTkE7MvRQBJ0Ce2RkJvN\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6785536.746200] ca acme-order-renew-ca.foo-start[318]: 2026/08/26 12:16:02 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [6785536.746317] ca acme-order-renew-ca.foo-start[318]: 2026/08/26 12:16:02 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [6785536.754241] ca step-ca[204]: time="2026-08-26T12:16:02Z" level=info duration=6.183247ms duration-ns=6183247 fields.time="2026-08-26T12:16:02Z" method=POST name=ca nonce=U0JJeU5nVVI2ZGlJVnlCc3BQTTBVeUdQOFRhU0tTVFQ path=/acme/acme/order/uTV1wruqVLnvaqDaqgrKWV70Vu2S2igp/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=4050e44e-fa68-4234-a10b-81b8c15bf85c response="{\"id\":\"uTV1wruqVLnvaqDaqgrKWV70Vu2S2igp\",\"status\":\"valid\",\"expires\":\"2026-08-27T12:16:02Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-26T12:15:02Z\",\"notAfter\":\"2026-11-24T12:16:02Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/XG0wS6ZsLKmT4s3YRQareDDl5DhTpRCd\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/uTV1wruqVLnvaqDaqgrKWV70Vu2S2igp/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/M6eJzLDpNSnlYazXMmfnmWeEPRfptCFH\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6785536.756675] ca step-ca[204]: time="2026-08-26T12:16:02Z" level=info certificate="MIIB1DCCAXqgAwIBAgIRAMnNYbZb4rpPiy7WTZga9bYwCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODI2MTIxNTAyWhcNMjYxMTI0MTIxNjAyWjARMQ8wDQYDVQQDEwZjYS5mb28wWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAS7NDuDqGo9+NaysmkgI07KbwbD9RiszeM8Xu5Wc4NpJHoG1e7O1omITymAsoOxvFqv3cSG7EXR8i/Yt9PnNT/Zo4GkMIGhMA4GA1UdDwEB/wQEAwIHgDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHQYDVR0OBBYEFAHjBREIJeX40rDu2mof7KpMewMjMB8GA1UdIwQYMBaAFFhS1wyNYKB84hY5AYxPLJisTA6QMBEGA1UdEQQKMAiCBmNhLmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSAAwRQIgV8/5PXUx8y93koYpiLfvuZY9B7yvb13ZuqwT2oLGSbQCIQD9I2QZUarg2XIm0qk5iC7DS0JsMgWW8JUSf3UrlPmOKQ==" duration=1.4249ms duration-ns=1424900 fields.time="2026-08-26T12:16:02Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=amdVQklwME8zenFwV2l3Y1AwQThjWk40bkhvcVk5Tkk path=/acme/acme/certificate/M6eJzLDpNSnlYazXMmfnmWeEPRfptCFH protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=0728d696-d04b-492a-ae52-2e15d52d2631 sans="map[dns:[ca.foo]]" serial=268241229850462094882117627845669483958 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-26T12:15:02Z" valid-to="2026-11-24T12:16:02Z" container-test-run-certificates> ca # [6785536.756872] ca acme-order-renew-ca.foo-start[318]: 2026/08/26 12:16:02 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [6785536.760749] ca acme-order-renew-ca.foo-start[307]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6785536.762650] ca acme-order-renew-ca.foo-start[307]: + touch out/acme-success container-test-run-certificates> ca # [6785536.764667] ca acme-order-renew-ca.foo-start[307]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6785536.765714] ca acme-order-renew-ca.foo-start[307]: + touch out/renewed container-test-run-certificates> ca # [6785536.767100] ca acme-order-renew-ca.foo-start[307]: + echo Installing new certificate container-test-run-certificates> ca # [6785536.767100] ca acme-order-renew-ca.foo-start[307]: Installing new certificate container-test-run-certificates> ca # [6785536.767100] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6785536.768909] ca acme-order-renew-ca.foo-start[350]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [6785536.769268] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [6785536.770454] ca acme-order-renew-ca.foo-start[351]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [6785536.770760] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [6785536.772578] ca acme-order-renew-ca.foo-start[352]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [6785536.772887] ca acme-order-renew-ca.foo-start[307]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [6785536.774346] ca acme-order-renew-ca.foo-start[307]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6785536.776310] ca acme-order-renew-ca.foo-start[307]: + for fixpath in out certificates container-test-run-certificates> ca # [6785536.776310] ca acme-order-renew-ca.foo-start[307]: + '[' -d out ']' container-test-run-certificates> ca # [6785536.776407] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6785536.778146] ca acme-order-renew-ca.foo-start[307]: + chown -R acme:nginx out container-test-run-certificates> ca # [6785536.780794] ca acme-order-renew-ca.foo-start[307]: + for fixpath in out certificates container-test-run-certificates> ca # [6785536.780794] ca acme-order-renew-ca.foo-start[307]: + '[' -d certificates ']' container-test-run-certificates> ca # [6785536.780892] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6785536.782261] ca acme-order-renew-ca.foo-start[307]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6785536.784944] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> server # [6785536.527567] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6785536.530949] server acme-order-renew-test.foo-start[270]: + set -euo pipefail container-test-run-certificates> server # [6785536.531023] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6785536.531135] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6785536.532222] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6785536.565463] server acme-order-renew-test.foo-start[281]: 2026/08/26 12:16:02 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [6785536.565894] server acme-order-renew-test.foo-start[281]: 2026/08/26 12:16:02 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> server # [6785536.601119] server acme-order-renew-test.foo-start[281]: 2026/08/26 12:16:02 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [6785536.602739] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6785536.602739] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6785536.602739] server acme-order-renew-test.foo-start[270]: + exit 10 container-test-run-certificates> server # [6785536.608534] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [6785536.608628] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [6785536.608916] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [6785536.609318] server systemd[1]: Startup finished in 4.733s. container-test-run-certificates> ca # [6785536.909722] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [6785536.913553] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6785536.913722] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca # [6785538.237724] ca nginx[368]: nginx: the configuration file /nix/store/y7l31xmgdb36n6qsx9xzk3vs64xjpv8v-nginx.conf syntax is ok container-test-run-certificates> ca # [6785538.238121] ca nginx[368]: nginx: configuration file /nix/store/y7l31xmgdb36n6qsx9xzk3vs64xjpv8v-nginx.conf test is successful container-test-run-certificates> ca # [6785538.821446] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [6785538.821825] ca systemd[1]: Startup finished in 6.936s. container-test-run-certificates> ca # [6785539.101950] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 5.69 seconds) container-test-run-certificates> ca # [6785539.899104] ca acme-order-renew-ca.foo-start[383]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6785539.901727] ca acme-order-renew-ca.foo-start[383]: + set -euo pipefail container-test-run-certificates> ca # [6785539.901805] ca acme-order-renew-ca.foo-start[383]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6785539.901917] ca acme-order-renew-ca.foo-start[383]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6785539.903117] ca acme-order-renew-ca.foo-start[383]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [6785539.903159] ca acme-order-renew-ca.foo-start[383]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [6785539.903544] ca acme-order-renew-ca.foo-start[391]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [6785539.905744] ca acme-order-renew-ca.foo-start[383]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [6785539.905782] ca acme-order-renew-ca.foo-start[383]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [6785539.943964] ca step-ca[204]: time="2026-08-26T12:16:05Z" level=info duration="89.001µs" duration-ns=89001 fields.time="2026-08-26T12:16:05Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=2c4d91d3-ca4a-4440-9bf9-9f422da1ea95 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6785539.944412] ca acme-order-renew-ca.foo-start[392]: 2026/08/26 12:16:05 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [6785539.944412] ca acme-order-renew-ca.foo-start[392]: 2026/08/26 12:16:05 [INFO] [ca.foo] The certificate expires at 2026-11-24T12:16:02Z, the renewal can be performed in 1439h59m36.002541756s: no renewal. container-test-run-certificates> ca # [6785539.945067] ca acme-order-renew-ca.foo-start[383]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6785539.946873] ca acme-order-renew-ca.foo-start[383]: + touch out/acme-success container-test-run-certificates> ca # [6785539.948429] ca acme-order-renew-ca.foo-start[383]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6785539.949537] ca acme-order-renew-ca.foo-start[383]: + for fixpath in out certificates container-test-run-certificates> ca # [6785539.949537] ca acme-order-renew-ca.foo-start[383]: + '[' -d out ']' container-test-run-certificates> ca # [6785539.949608] ca acme-order-renew-ca.foo-start[383]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6785539.950967] ca acme-order-renew-ca.foo-start[383]: + chown -R acme:nginx out container-test-run-certificates> ca # [6785539.953757] ca acme-order-renew-ca.foo-start[383]: + for fixpath in out certificates container-test-run-certificates> ca # [6785539.953757] ca acme-order-renew-ca.foo-start[383]: + '[' -d certificates ']' container-test-run-certificates> ca # [6785539.953757] ca acme-order-renew-ca.foo-start[383]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6785539.955186] ca acme-order-renew-ca.foo-start[383]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6785539.957713] ca acme-order-renew-ca.foo-start[383]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6785540.134539] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6785540.140263] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [6785543.161181] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6785543.161398] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [6785543.162309] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [6785543.163960] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 1.24 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1008 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [110 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 26 12:16:01 2026 GMT container-test-run-certificates> * expire date: Sep 25 12:16:01 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 4bb5c8 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6785544.338381] server acme-test.foo-start[315]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6785544.341113] server acme-test.foo-start[315]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6785544.341152] server acme-test.foo-start[315]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6785544.351910] server acme-test.foo-start[325]: + cd test.foo container-test-run-certificates> server # [6785544.352320] server acme-test.foo-start[325]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6785544.353502] server acme-test.foo-start[326]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6785544.353884] server acme-test.foo-start[325]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6785544.355396] server acme-test.foo-start[325]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6785544.355477] server acme-test.foo-start[315]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6785544.356992] server acme-test.foo-start[315]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6785544.358501] server acme-test.foo-start[315]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6785544.360069] server acme-test.foo-start[315]: + for fixpath in out certificates container-test-run-certificates> server # [6785544.360069] server acme-test.foo-start[315]: + '[' -d out ']' container-test-run-certificates> server # [6785544.360111] server acme-test.foo-start[315]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6785544.361490] server acme-test.foo-start[315]: + chown -R acme:nginx out container-test-run-certificates> server # [6785544.363905] server acme-test.foo-start[315]: + for fixpath in out certificates container-test-run-certificates> server # [6785544.363927] server acme-test.foo-start[315]: + '[' -d certificates ']' container-test-run-certificates> server # [6785544.384577] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6785544.387310] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1008 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 26 12:16:01 2026 GMT container-test-run-certificates> * expire date: Sep 25 12:16:01 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 4bb5c8 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6785545.431972] server acme-order-renew-test.foo-start[333]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6785545.434467] server acme-order-renew-test.foo-start[333]: + set -euo pipefail container-test-run-certificates> server # [6785545.434548] server acme-order-renew-test.foo-start[333]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6785545.434668] server acme-order-renew-test.foo-start[333]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6785545.435886] server acme-order-renew-test.foo-start[333]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6785545.475046] server acme-order-renew-test.foo-start[341]: 2026/08/26 12:16:11 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [6785545.483084] server acme-order-renew-test.foo-start[341]: !!!! HEADS UP !!!! container-test-run-certificates> server # [6785545.483084] server acme-order-renew-test.foo-start[341]: Your account credentials have been saved in your container-test-run-certificates> server # [6785545.483084] server acme-order-renew-test.foo-start[341]: configuration directory at "accounts". container-test-run-certificates> server # [6785545.483084] server acme-order-renew-test.foo-start[341]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [6785545.483084] server acme-order-renew-test.foo-start[341]: configuration directory will also contain private keys container-test-run-certificates> server # [6785545.483084] server acme-order-renew-test.foo-start[341]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [6785545.483084] server acme-order-renew-test.foo-start[341]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [6785545.483316] server acme-order-renew-test.foo-start[341]: 2026/08/26 12:16:11 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [6785545.548145] server acme-order-renew-test.foo-start[341]: 2026/08/26 12:16:11 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/lFaJuAh8QZ7u2JUrcQ6iVlFDw4POer0U container-test-run-certificates> server # [6785545.548145] server acme-order-renew-test.foo-start[341]: 2026/08/26 12:16:11 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [6785545.548145] server acme-order-renew-test.foo-start[341]: 2026/08/26 12:16:11 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [6785545.548145] server acme-order-renew-test.foo-start[341]: 2026/08/26 12:16:11 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [6785545.554011] server acme-order-renew-test.foo-start[341]: 2026/08/26 12:16:11 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [6785545.554100] server acme-order-renew-test.foo-start[341]: 2026/08/26 12:16:11 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [6785545.570670] server acme-order-renew-test.foo-start[341]: 2026/08/26 12:16:11 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [6785545.576300] server acme-order-renew-test.foo-start[333]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [6785545.578221] server acme-order-renew-test.foo-start[333]: + touch out/acme-success container-test-run-certificates> server # [6785545.579993] server acme-order-renew-test.foo-start[333]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6785545.580978] server acme-order-renew-test.foo-start[333]: + touch out/renewed container-test-run-certificates> server # [6785545.582527] server acme-order-renew-test.foo-start[333]: + echo Installing new certificate container-test-run-certificates> server # [6785545.582527] server acme-order-renew-test.foo-start[333]: Installing new certificate container-test-run-certificates> server # [6785545.582571] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6785545.584131] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [6785545.584368] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [6785545.585993] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [6785545.586244] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [6785545.588247] server acme-order-renew-test.foo-start[375]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [6785545.588573] server acme-order-renew-test.foo-start[333]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [6785545.590360] server acme-order-renew-test.foo-start[333]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6785545.592011] server acme-order-renew-test.foo-start[333]: + for fixpath in out certificates container-test-run-certificates> server # [6785545.592034] server acme-order-renew-test.foo-start[333]: + '[' -d out ']' container-test-run-certificates> server # [6785545.592051] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6785545.593750] server acme-order-renew-test.foo-start[333]: + chown -R acme:nginx out container-test-run-certificates> server # [6785545.605638] server acme-order-renew-test.foo-start[333]: + for fixpath in out certificates container-test-run-certificates> server # [6785545.605725] server acme-order-renew-test.foo-start[333]: + '[' -d certificates ']' container-test-run-certificates> server # [6785545.605725] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [6785545.607602] server acme-order-renew-test.foo-start[333]: + chown -R acme:nginx certificates container-test-run-certificates> server # [6785545.615011] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6785545.474621] ca step-ca[204]: time="2026-08-26T12:16:11Z" level=info duration="41.281µs" duration-ns=41281 fields.time="2026-08-26T12:16:11Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=52ad4777-54ce-4962-970b-ac80fa841065 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6785545.478089] ca step-ca[204]: time="2026-08-26T12:16:11Z" level=info duration="837.131µs" duration-ns=837131 fields.time="2026-08-26T12:16:11Z" method=HEAD name=ca nonce=ZHlVTVlhUkl2S2ZHaEhiM2hOaVM1cGdaWmh6b0I3V0U path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=f1d03e5f-cf5c-47cf-9550-77d83a2655a6 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6785545.482672] ca step-ca[204]: time="2026-08-26T12:16:11Z" level=info duration=2.082789ms duration-ns=2082789 fields.time="2026-08-26T12:16:11Z" method=POST name=ca nonce=RWFadzBpN01QcXhseFUxZDY3OTN5emFFaGVhZk1OcXI path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=881bd361-d120-4be0-b8d1-ffdceb922997 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/8axzW5GdqbXyPn7FR20OjyL6wTP4ERqP/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6785545.487310] ca step-ca[204]: time="2026-08-26T12:16:11Z" level=info duration=2.314313ms duration-ns=2314313 fields.time="2026-08-26T12:16:11Z" method=POST name=ca nonce=cVR6VmlvRTR5OXBtdThnOGhyTGVDbkdtSXZ6cHUwUFE path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=b11d283c-f3e3-4d9c-bf2b-e92a1814cf36 response="{\"id\":\"JAULuF60olOy5jd5EVSXhiSX0mCAXg5h\",\"status\":\"pending\",\"expires\":\"2026-08-27T12:16:11Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-26T12:15:11Z\",\"notAfter\":\"2026-11-24T12:16:11Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/lFaJuAh8QZ7u2JUrcQ6iVlFDw4POer0U\"],\"finalize\":\"https://ca.foo/acme/acme/order/JAULuF60olOy5jd5EVSXhiSX0mCAXg5h/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6785545.547714] ca step-ca[204]: time="2026-08-26T12:16:11Z" level=info duration=1.40666ms duration-ns=1406660 fields.time="2026-08-26T12:16:11Z" method=POST name=ca nonce=MkhrRVJFMkN6S2NFOU11a2ZYUkdWUEliWlVYUVBkRUQ path=/acme/acme/authz/lFaJuAh8QZ7u2JUrcQ6iVlFDw4POer0U protocol=HTTP/1.1 referer= remote-address="::1" request-id=2cedd9ec-0a6a-41a2-9aae-b61294dfc20f response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"3AkNm0wANSBhMgeJUfWWvlACNEyujZDx\",\"url\":\"https://ca.foo/acme/acme/challenge/lFaJuAh8QZ7u2JUrcQ6iVlFDw4POer0U/3evSENTl9XNAxeyLpMgdEw1HMY2yM3OT\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"3AkNm0wANSBhMgeJUfWWvlACNEyujZDx\",\"url\":\"https://ca.foo/acme/acme/challenge/lFaJuAh8QZ7u2JUrcQ6iVlFDw4POer0U/HvdtXgNyMLJZdPXPz2qBZ4yYw8oI98ux\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"3AkNm0wANSBhMgeJUfWWvlACNEyujZDx\",\"url\":\"https://ca.foo/acme/acme/challenge/lFaJuAh8QZ7u2JUrcQ6iVlFDw4POer0U/xOJz1YZ11TfuXWnAuLzzliXvMuY26hN2\"}],\"wildcard\":false,\"expires\":\"2026-08-27T12:16:11Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6785545.553411] ca step-ca[204]: time="2026-08-26T12:16:11Z" level=info duration=3.245005ms duration-ns=3245005 fields.time="2026-08-26T12:16:11Z" method=POST name=ca nonce=MnlrNTFVM2NUN0M5RDRRbmNaSmJCSUpvazNmZ2hib0Q path=/acme/acme/challenge/lFaJuAh8QZ7u2JUrcQ6iVlFDw4POer0U/HvdtXgNyMLJZdPXPz2qBZ4yYw8oI98ux protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=b33289a2-d757-48e8-92c9-6c6ae7a1bfb7 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"3AkNm0wANSBhMgeJUfWWvlACNEyujZDx\",\"validated\":\"2026-08-26T12:16:11Z\",\"url\":\"https://ca.foo/acme/acme/challenge/lFaJuAh8QZ7u2JUrcQ6iVlFDw4POer0U/HvdtXgNyMLJZdPXPz2qBZ4yYw8oI98ux\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6785545.566104] ca step-ca[204]: time="2026-08-26T12:16:11Z" level=info duration=7.976392ms duration-ns=7976392 fields.time="2026-08-26T12:16:11Z" method=POST name=ca nonce=a29ldHhhQ05ZVGNPZXM4cW95d2ZCOVUxclBzd3VCTW4 path=/acme/acme/order/JAULuF60olOy5jd5EVSXhiSX0mCAXg5h/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=19d2fdcf-4df1-4f19-8882-3640e9568a24 response="{\"id\":\"JAULuF60olOy5jd5EVSXhiSX0mCAXg5h\",\"status\":\"valid\",\"expires\":\"2026-08-27T12:16:11Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-26T12:15:11Z\",\"notAfter\":\"2026-11-24T12:16:11Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/lFaJuAh8QZ7u2JUrcQ6iVlFDw4POer0U\"],\"finalize\":\"https://ca.foo/acme/acme/order/JAULuF60olOy5jd5EVSXhiSX0mCAXg5h/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/UIOBwsXwlIyzqfDa2wY0BMPSfTsp18pP\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6785545.570228] ca step-ca[204]: time="2026-08-26T12:16:11Z" level=info certificate="MIIB2DCCAX6gAwIBAgIRAMb2nDRdoZMAEpuFB7BL/nswCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODI2MTIxNTExWhcNMjYxMTI0MTIxNjExWjATMREwDwYDVQQDEwh0ZXN0LmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABKP9hI3Ab1RpZXLGuKmYvTlv6yHfjBJ8ZCqWK3yitJ6VfABA8dU7NfcxAXVoB6oN1fHXN6BIq+v5QoAHGME+2h6jgaYwgaMwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUaAyQMu+U6L2ivGEw8sxJPUQ9OnEwHwYDVR0jBBgwFoAUWFLXDI1goHziFjkBjE8smKxMDpAwEwYDVR0RBAwwCoIIdGVzdC5mb28wHQYMKwYBBAGCpGTGKEABBA0wCwIBBgQEYWNtZQQAMAoGCCqGSM49BAMCA0gAMEUCIGSOFOqNqXnW4z/a/4T3BZSlzEduRtQZET599LxX11U1AiEA3985pVwCpYGuP4eq3P1Tzl7ba0Qrk/bz6NdRLcTUVlc=" duration=1.228098ms duration-ns=1228098 fields.time="2026-08-26T12:16:11Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=R2tyV2J1Ynlhckp2RUNuQlVFb3J1b3lMMXd1Y0djZ1g path=/acme/acme/certificate/UIOBwsXwlIyzqfDa2wY0BMPSfTsp18pP protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=a46b932a-1677-4503-938c-f24bbbae2458 sans="map[dns:[test.foo]]" serial=264467616397352967993460830776503041659 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-26T12:15:11Z" valid-to="2026-11-24T12:16:11Z" container-test-run-certificates> server # [6785545.827676] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [6785545.831559] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6785545.831748] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1008 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [112 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 26 12:16:01 2026 GMT container-test-run-certificates> * expire date: Sep 25 12:16:01 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 4bb5c8 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6785546.546111] server nginx[391]: nginx: the configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf syntax is ok container-test-run-certificates> server # [6785546.546479] server nginx[391]: nginx: configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf test is successful container-test-run-certificates> server # [6785547.181700] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [931 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [79 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 26 12:15:11 2026 GMT container-test-run-certificates> * expire date: Nov 24 12:16:11 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 53342 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 797 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 3.16 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> c6:f6:9c:34:5d:a1:93:00:12:9b:85:07:b0:4b:fe:7b container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Aug 26 12:15:11 2026 GMT container-test-run-certificates> Not After : Nov 24 12:16:11 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:a3:fd:84:8d:c0:6f:54:69:65:72:c6:b8:a9:98: container-test-run-certificates> bd:39:6f:eb:21:df:8c:12:7c:64:2a:96:2b:7c:a2: container-test-run-certificates> b4:9e:95:7c:00:40:f1:d5:3b:35:f7:31:01:75:68: container-test-run-certificates> 07:aa:0d:d5:f1:d7:37:a0:48:ab:eb:f9:42:80:07: container-test-run-certificates> 18:c1:3e:da:1e container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> 68:0C:90:32:EF:94:E8:BD:A2:BC:61:30:F2:CC:49:3D:44:3D:3A:71 container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> 58:52:D7:0C:8D:60:A0:7C:E2:16:39:01:8C:4F:2C:98:AC:4C:0E:90 container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:45:02:20:64:8e:14:ea:8d:a9:79:d6:e3:3f:da:ff:84:f7: container-test-run-certificates> 05:94:a5:cc:47:6e:46:d4:19:11:3e:7d:f4:bc:57:d7:55:35: container-test-run-certificates> 02:21:00:df:df:39:a5:5c:02:a5:81:ae:3f:87:aa:dc:fd:53: container-test-run-certificates> ce:5e:db:6b:44:2b:93:f6:f3:e8:d7:51:2d:c4:d4:56:57 container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.04 seconds) container-test-run-certificates> (finished: run the VM test script, in 16.14 seconds) container-test-run-certificates> test script finished in 16.23s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 53) container-test-run-certificates> kill NspawnMachine (pid 55) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> Container server terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.64 seconds) post-build step Upload to niks3: ok time=2026-08-26T12:16:14.903Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-26T12:16:15.432Z level=INFO msg="Uploading 1 narinfos" time=2026-08-26T12:16:15.550Z level=INFO msg="Upload complete. (785ms)"