these 91 derivations will be built: /nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv /nix/store/a0fjq2lmggzgmdqmw61ppvcrk0ns78lv-firewall-start.drv /nix/store/05l61ybxsccw6az5wkv1yr6i1znk7973-firewall-reload.drv /nix/store/0dazh70qwhpgsvnf5ws7zfdbrmzlhg6l-users-groups.json.drv /nix/store/1jalkn3dm5wbs39sppkxd2wllx073kfn-ca.json.drv /nix/store/nmwkd9rbaz11m00amisn6fc8kqzzmf95-system-path.drv /nix/store/pg4s5a7kkvw6djddjxlfmcsn2ya7laab-dbus-1.drv /nix/store/yl0v25cmi7rhvhlfavl9h9ix619h8xq4-X-Restart-Triggers-dbus-broker.drv /nix/store/2b20aiq8sa50pk3pm5zdzywvmx360iv9-unit-dbus-broker.service.drv /nix/store/33ysc61mi11kshcq09hc1x9hpw72sbi0-X-Restart-Triggers-acme-test.foo.drv /nix/store/jxb6x753fqh9qsdfr6kd1dd06snj68sb-unit-script-acme-test.foo-start.drv /nix/store/300lzbbn313vjl4xwmbp5fij40zhv6w6-unit-acme-test.foo.service.drv /nix/store/53hnawxj96bx7praki7i4v57slvk3nl8-system-path.drv /nix/store/9s6z42mqv300c0zqsy258gi9lpdmq6my-users-groups.json.drv /nix/store/fwdgn1p9i71a2z91qy80lx5m46vnj148-etc-hostname.drv /nix/store/hd50zk417rykvdbbfgngqwkgwfp7m6d9-system-shutdown.drv /nix/store/hx1vv9x2bvhhvsgxz8wbknybbsvqp4f0-tmpfiles.d.drv /nix/store/i30rzaj5iwfdzlrlxm0rhlar4xp6k7n7-system-generators.drv /nix/store/ivblry47xynlrmn3f7xplcdykhz54kb5-user-generators.drv /nix/store/w4jznbvj0c5lpf7v624b7cysb34qd5xp-X-Restart-Triggers-step-ca.drv /nix/store/3g5xmv9s59bbs68b2wn6082a8j4ildgj-unit-step-ca.service.drv /nix/store/vnvlniy3jw707y5758y6vkgmxgja643k-acme-setup-privileged.drv /nix/store/c32hn00sk7i5n3iwl5dwlg87kqv8hgm5-unit-acme-setup.service.drv /nix/store/d2avhjb4s4fnivfvc5m03l7w0paydb6b-unit-acme-renew-ca.foo.timer.drv /nix/store/zsn174ml6x7wb3j8gs0s8rkwhf8rn00v-nginx.conf.drv /nix/store/hf16y9if9kfdyvyssa0ymx73q9y1a29b-unit-script-nginx-pre-start.drv /nix/store/drg6haz2i0nlig69ja36h53i40zygma3-unit-nginx.service.drv /nix/store/kp8dljswwwkqk7w5ngkh88cqwvv8vfmw-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/h92cs5q4q590p6vvaxjf9f83ashdimxp-unit-systemd-tmpfiles-resetup.service.drv /nix/store/x3i9qpwy7sx46p4fzrsrjc4pjkh6idgf-dbus-1.drv /nix/store/kjmkg96s7i10bkdcw918a5qfjz4yscmd-X-Restart-Triggers-dbus-broker.drv /nix/store/mjcag0kvnj4h286hg3rvrgwgz6kwa4w9-unit-dbus-broker.service.drv /nix/store/3cdmcd9isw2rag9rhnb76hi2wgz276m7-acme-postrun.drv /nix/store/mbmq2fnjrl6rjd4f5chjqn21h72n6g51-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/n132wcg6ip1grxd37ychp1006wkzhcza-unit-acme-order-renew-ca.foo.service.drv /nix/store/n39dh7sylyqlcvpjh8g9wsmdb5n21w5q-nss-cacert-3.126.drv /nix/store/qvwm149dv8dh35lc7fw67idf42c9xcba-unit-nix-daemon.service.drv /nix/store/qxpp164gsfgzyas2kmd8wg3qyakqzavi-unit-nginx-config-reload.service.drv /nix/store/x7d0nslv3qznin20gmhr0c5qnwnavwp2-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/4sfz05hhn9cnswrfbqhr9r41zizqd315-unit-script-acme-ca.foo-start.drv /nix/store/ab41sxhfkmh965c1b96j4zmzrjccdw2x-X-Restart-Triggers-acme-ca.foo.drv /nix/store/yj1akmznrbkvc723n3iypygm9ahzqsak-unit-acme-ca.foo.service.drv /nix/store/yw288val3xcd0lvrg7fj24317b904nz9-unit-firewall.service.drv /nix/store/j0iq5qa1sy6q08kwglspfz1kayll5pb2-system-units.drv /nix/store/yr14jpn42fdik55sz046ycmpk4myrss7-unit-dbus-broker.service.drv /nix/store/k3wap5inj84acy6l6jh9112p23whxx0x-user-units.drv /nix/store/lylvrr8cbsf0k9h5jlbg5h2n5bhljsq8-extra-hosts.drv /nix/store/qfsrvg58wd78nr87mq8fs9vjav0bx7h7-string-hosts.drv /nix/store/p5f8qdav49r8y6hj0x3nbp79b23vrx5j-hosts.drv /nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv /nix/store/mgg0rz6qfqcxc83sxkfi7djzrvh0ryrk-etc.drv /nix/store/9vvaqhadnyxwp2vb92s22vzh9j93hlps-activate.drv /nix/store/varyvj2bd1w0xikmym53l2lbay5pcz6z-dry-activate.drv /nix/store/mwypvb12v05pi22hvf2nwdfb2zvdhccs-nixos-system-ca-test.drv /nix/store/448kfn50adks5505ifq7m38m26rzhmxh-run-ca-nspawn.drv /nix/store/4npi5hfjyzgqr0fgxwpcaif1ll5qvl6l-user-units.drv /nix/store/c6028b7d6mzlxrwdh9hvwz3fnc81n86b-hosts.drv /nix/store/jrln6ldic7lf2wk4m78mymqw3g9ikjl8-nginx.conf.drv /nix/store/7irk03vanc5xlvca6i17vaq7j2pk794x-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/bfnbi0ivq2qlkdya7mfcyrgal3l75f72-unit-acme-renew-test.foo.timer.drv /nix/store/s7iyb8q0dvr6dgpffrcyslvjnwlzkh7x-acme-postrun.drv /nix/store/xk1djxalc44cx697ca7p2vaj698dpczg-unit-script-acme-order-renew-test.foo-start.drv /nix/store/cg3qqfszqzzbmw4dm4jxz0c07i07blyy-unit-acme-order-renew-test.foo.service.drv /nix/store/fw9zzn8p2819xmxzbwjbp5b5nng9h5sj-unit-nginx-config-reload.service.drv /nix/store/hxjsdq5h221qjz2yv66s48292zr5572v-acme-setup-privileged.drv /nix/store/iw0qimh0h18z57rx7946jnvg2z4y6wmh-unit-acme-setup.service.drv /nix/store/3sx1ynm5g6cjrl5y260pg0ppp0v4d4wa-unit-script-nginx-pre-start.drv /nix/store/n0i5fnzbsb0zkkiw16301r4q69pzkdmc-unit-nginx.service.drv /nix/store/n5lgd8kjn863127n3hw4a4m51iiqdncz-unit-dbus-broker.service.drv /nix/store/qa9w36pyw1iv60nas6fhm2rs155dlh4j-system-units.drv /nix/store/6bsmj4bpxkqvf4c1p6q5mnvy15j5zh90-etc.drv /nix/store/mc79y5var5c7ca794a080m1x27i7s3kf-activate.drv /nix/store/p665x5g4cf75qyf0riiwhgjzp3qzi5c6-dry-activate.drv /nix/store/3vkw169vimhciv3kygvxq1a54rpmh5mn-nixos-system-server-test.drv /nix/store/dqxv2f07ym2pwkqam1fh3014yn61gf0s-run-server-nspawn.drv /nix/store/i9dp3pxhd8i3wwisb7p3hyb99pazmsf8-system-path.drv /nix/store/7rfsbl4zr4jzakgvvbz6aqcgka7wmk3j-dbus-1.drv /nix/store/i24rhm6bgwms3ib5b4b2cqgl5sxm2n6c-hosts.drv /nix/store/frqjymwgfg7lwzcla6s2c5d36jj3zsnn-X-Restart-Triggers-dbus-broker.drv /nix/store/g3pbjwbabwkr9akggrlfgxyx1fyfz5lf-unit-dbus-broker.service.drv /nix/store/qgciair8g6hxi7i3lispy9i41fycaqgq-user-units.drv /nix/store/wbjwlajk0a2j6c39hgmd5g319ljv0wn9-unit-dbus-broker.service.drv /nix/store/z08iz8mlcd0h8q66qxzgz96s2waymx7l-system-units.drv /nix/store/brmnpi9iksbxvcv9ay6zjpmcfdjj1hyy-etc.drv /nix/store/qlzj0kxk3653885fhwx65vzsnqavkyiq-activate.drv /nix/store/gb3dff3awpkz8c47k7xi004wvyijlbxr-nixos-system-client-test.drv /nix/store/ird5vdqzky04ps9cdq3aqlmfkpq08c5z-run-client-nspawn.drv /nix/store/qq6ms440xlly2q027kys1f9j2bh6yy0i-test-script.drv /nix/store/nk7hakbkffsd7rfl30c2h3kzll6ps7im-driverConfiguration.json.drv /nix/store/32282nriz94623l775x7w2x8z9bajnj4-nixos-test-driver-certificates.drv /nix/store/fsvd5jlca59dhfijblgw76an1fg2n3pa-container-test-run-certificates.drv this path will be fetched (21.7 MiB download, 71.4 MiB unpacked): /nix/store/dlpj6bc50h35a0glvslc6vnrq4xgp93j-step-ca-0.30.2 building '/nix/store/qq6ms440xlly2q027kys1f9j2bh6yy0i-test-script.drv' building '/nix/store/53hnawxj96bx7praki7i4v57slvk3nl8-system-path.drv' building '/nix/store/i9dp3pxhd8i3wwisb7p3hyb99pazmsf8-system-path.drv' building '/nix/store/nmwkd9rbaz11m00amisn6fc8kqzzmf95-system-path.drv' building '/nix/store/fwdgn1p9i71a2z91qy80lx5m46vnj148-etc-hostname.drv' building '/nix/store/jrln6ldic7lf2wk4m78mymqw3g9ikjl8-nginx.conf.drv' building '/nix/store/zsn174ml6x7wb3j8gs0s8rkwhf8rn00v-nginx.conf.drv' building '/nix/store/hx1vv9x2bvhhvsgxz8wbknybbsvqp4f0-tmpfiles.d.drv' building '/nix/store/lylvrr8cbsf0k9h5jlbg5h2n5bhljsq8-extra-hosts.drv' building '/nix/store/qfsrvg58wd78nr87mq8fs9vjav0bx7h7-string-hosts.drv' nginx.conf> structuredAttrs is enabled nginx.conf> structuredAttrs is enabled system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment building '/nix/store/mbmq2fnjrl6rjd4f5chjqn21h72n6g51-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/xk1djxalc44cx697ca7p2vaj698dpczg-unit-script-acme-order-renew-test.foo-start.drv' building '/nix/store/jxb6x753fqh9qsdfr6kd1dd06snj68sb-unit-script-acme-test.foo-start.drv' building '/nix/store/kp8dljswwwkqk7w5ngkh88cqwvv8vfmw-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' building '/nix/store/hxjsdq5h221qjz2yv66s48292zr5572v-acme-setup-privileged.drv' building '/nix/store/vnvlniy3jw707y5758y6vkgmxgja643k-acme-setup-privileged.drv' building '/nix/store/a0fjq2lmggzgmdqmw61ppvcrk0ns78lv-firewall-start.drv' building '/nix/store/4sfz05hhn9cnswrfbqhr9r41zizqd315-unit-script-acme-ca.foo-start.drv' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/c6028b7d6mzlxrwdh9hvwz3fnc81n86b-hosts.drv' building '/nix/store/i24rhm6bgwms3ib5b4b2cqgl5sxm2n6c-hosts.drv' building '/nix/store/p5f8qdav49r8y6hj0x3nbp79b23vrx5j-hosts.drv' building '/nix/store/n39dh7sylyqlcvpjh8g9wsmdb5n21w5q-nss-cacert-3.126.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/ab41sxhfkmh965c1b96j4zmzrjccdw2x-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/33ysc61mi11kshcq09hc1x9hpw72sbi0-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/3cdmcd9isw2rag9rhnb76hi2wgz276m7-acme-postrun.drv' building '/nix/store/s7iyb8q0dvr6dgpffrcyslvjnwlzkh7x-acme-postrun.drv' building '/nix/store/1jalkn3dm5wbs39sppkxd2wllx073kfn-ca.json.drv' building '/nix/store/7rfsbl4zr4jzakgvvbz6aqcgka7wmk3j-dbus-1.drv' building '/nix/store/pg4s5a7kkvw6djddjxlfmcsn2ya7laab-dbus-1.drv' building '/nix/store/x3i9qpwy7sx46p4fzrsrjc4pjkh6idgf-dbus-1.drv' building '/nix/store/0dazh70qwhpgsvnf5ws7zfdbrmzlhg6l-users-groups.json.drv' building '/nix/store/9s6z42mqv300c0zqsy258gi9lpdmq6my-users-groups.json.drv' ca.json> structuredAttrs is enabled building '/nix/store/05l61ybxsccw6az5wkv1yr6i1znk7973-firewall-reload.drv' building '/nix/store/i30rzaj5iwfdzlrlxm0rhlar4xp6k7n7-system-generators.drv' building '/nix/store/hd50zk417rykvdbbfgngqwkgwfp7m6d9-system-shutdown.drv' building '/nix/store/c32hn00sk7i5n3iwl5dwlg87kqv8hgm5-unit-acme-setup.service.drv' building '/nix/store/iw0qimh0h18z57rx7946jnvg2z4y6wmh-unit-acme-setup.service.drv' building '/nix/store/3sx1ynm5g6cjrl5y260pg0ppp0v4d4wa-unit-script-nginx-pre-start.drv' building '/nix/store/hf16y9if9kfdyvyssa0ymx73q9y1a29b-unit-script-nginx-pre-start.drv' unit-acme-setup.service> structuredAttrs is enabled unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/frqjymwgfg7lwzcla6s2c5d36jj3zsnn-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/kjmkg96s7i10bkdcw918a5qfjz4yscmd-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/yl0v25cmi7rhvhlfavl9h9ix619h8xq4-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/yj1akmznrbkvc723n3iypygm9ahzqsak-unit-acme-ca.foo.service.drv' building '/nix/store/n132wcg6ip1grxd37ychp1006wkzhcza-unit-acme-order-renew-ca.foo.service.drv' building '/nix/store/300lzbbn313vjl4xwmbp5fij40zhv6w6-unit-acme-test.foo.service.drv' building '/nix/store/h92cs5q4q590p6vvaxjf9f83ashdimxp-unit-systemd-tmpfiles-resetup.service.drv' building '/nix/store/ivblry47xynlrmn3f7xplcdykhz54kb5-user-generators.drv' building '/nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' unit-acme-ca.foo.service> structuredAttrs is enabled unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled unit-acme-test.foo.service> structuredAttrs is enabled unit-systemd-tmpfiles-resetup.service> structuredAttrs is enabled building '/nix/store/w4jznbvj0c5lpf7v624b7cysb34qd5xp-X-Restart-Triggers-step-ca.drv' building '/nix/store/p665x5g4cf75qyf0riiwhgjzp3qzi5c6-dry-activate.drv' building '/nix/store/cg3qqfszqzzbmw4dm4jxz0c07i07blyy-unit-acme-order-renew-test.foo.service.drv' building '/nix/store/yw288val3xcd0lvrg7fj24317b904nz9-unit-firewall.service.drv' building '/nix/store/qxpp164gsfgzyas2kmd8wg3qyakqzavi-unit-nginx-config-reload.service.drv' building '/nix/store/drg6haz2i0nlig69ja36h53i40zygma3-unit-nginx.service.drv' unit-acme-order-renew-test.foo.service> structuredAttrs is enabled unit-firewall.service> structuredAttrs is enabled unit-nginx-config-reload.service> structuredAttrs is enabled unit-nginx.service> structuredAttrs is enabled building '/nix/store/7irk03vanc5xlvca6i17vaq7j2pk794x-unit-acme-account-2c44cb477b4787b2cf13.target.drv' building '/nix/store/x7d0nslv3qznin20gmhr0c5qnwnavwp2-unit-acme-account-d22a46d9459bf683a338.target.drv' building '/nix/store/d2avhjb4s4fnivfvc5m03l7w0paydb6b-unit-acme-renew-ca.foo.timer.drv' building '/nix/store/bfnbi0ivq2qlkdya7mfcyrgal3l75f72-unit-acme-renew-test.foo.timer.drv' building '/nix/store/wbjwlajk0a2j6c39hgmd5g319ljv0wn9-unit-dbus-broker.service.drv' building '/nix/store/fw9zzn8p2819xmxzbwjbp5b5nng9h5sj-unit-nginx-config-reload.service.drv' unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled unit-acme-renew-ca.foo.timer> structuredAttrs is enabled unit-acme-renew-test.foo.timer> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/2b20aiq8sa50pk3pm5zdzywvmx360iv9-unit-dbus-broker.service.drv' building '/nix/store/g3pbjwbabwkr9akggrlfgxyx1fyfz5lf-unit-dbus-broker.service.drv' building '/nix/store/yr14jpn42fdik55sz046ycmpk4myrss7-unit-dbus-broker.service.drv' building '/nix/store/3g5xmv9s59bbs68b2wn6082a8j4ildgj-unit-step-ca.service.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/mjcag0kvnj4h286hg3rvrgwgz6kwa4w9-unit-dbus-broker.service.drv' building '/nix/store/n5lgd8kjn863127n3hw4a4m51iiqdncz-unit-dbus-broker.service.drv' building '/nix/store/n0i5fnzbsb0zkkiw16301r4q69pzkdmc-unit-nginx.service.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-step-ca.service> structuredAttrs is enabled building '/nix/store/4npi5hfjyzgqr0fgxwpcaif1ll5qvl6l-user-units.drv' building '/nix/store/k3wap5inj84acy6l6jh9112p23whxx0x-user-units.drv' building '/nix/store/qgciair8g6hxi7i3lispy9i41fycaqgq-user-units.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv' building '/nix/store/n39dh7sylyqlcvpjh8g9wsmdb5n21w5q-nss-cacert-3.126.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/lc0m26vj9f305v447s6ygqxxfpw0755m-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/lc0m26vj9f305v447s6ygqxxfpw0755m-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/lc0m26vj9f305v447s6ygqxxfpw0755m-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/ig1djpldwx1g9p5ryj4sb92hpkhcinc3-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/ig1djpldwx1g9p5ryj4sb92hpkhcinc3-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/ig1djpldwx1g9p5ryj4sb92hpkhcinc3-nss-cacert-3.126-unbundled nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/66xilgarg2l6kkr936b9wmhhd3wx93h7-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/66xilgarg2l6kkr936b9wmhhd3wx93h7-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/66xilgarg2l6kkr936b9wmhhd3wx93h7-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/qr532cg2zzyxb1s2ry6za260vv4dgml4-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/qr532cg2zzyxb1s2ry6za260vv4dgml4-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/qr532cg2zzyxb1s2ry6za260vv4dgml4-nss-cacert-3.126-hashed building '/nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv' building '/nix/store/varyvj2bd1w0xikmym53l2lbay5pcz6z-dry-activate.drv' building '/nix/store/qvwm149dv8dh35lc7fw67idf42c9xcba-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled building '/nix/store/j0iq5qa1sy6q08kwglspfz1kayll5pb2-system-units.drv' building '/nix/store/qa9w36pyw1iv60nas6fhm2rs155dlh4j-system-units.drv' building '/nix/store/z08iz8mlcd0h8q66qxzgz96s2waymx7l-system-units.drv' building '/nix/store/6bsmj4bpxkqvf4c1p6q5mnvy15j5zh90-etc.drv' building '/nix/store/brmnpi9iksbxvcv9ay6zjpmcfdjj1hyy-etc.drv' building '/nix/store/mgg0rz6qfqcxc83sxkfi7djzrvh0ryrk-etc.drv' building '/nix/store/mc79y5var5c7ca794a080m1x27i7s3kf-activate.drv' building '/nix/store/9vvaqhadnyxwp2vb92s22vzh9j93hlps-activate.drv' building '/nix/store/qlzj0kxk3653885fhwx65vzsnqavkyiq-activate.drv' building '/nix/store/3vkw169vimhciv3kygvxq1a54rpmh5mn-nixos-system-server-test.drv' building '/nix/store/mwypvb12v05pi22hvf2nwdfb2zvdhccs-nixos-system-ca-test.drv' building '/nix/store/gb3dff3awpkz8c47k7xi004wvyijlbxr-nixos-system-client-test.drv' nixos-system-ca-test> structuredAttrs is enabled nixos-system-server-test> structuredAttrs is enabled building '/nix/store/dqxv2f07ym2pwkqam1fh3014yn61gf0s-run-server-nspawn.drv' nixos-system-client-test> structuredAttrs is enabled building '/nix/store/448kfn50adks5505ifq7m38m26rzhmxh-run-ca-nspawn.drv' building '/nix/store/ird5vdqzky04ps9cdq3aqlmfkpq08c5z-run-client-nspawn.drv' building '/nix/store/nk7hakbkffsd7rfl30c2h3kzll6ps7im-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/32282nriz94623l775x7w2x8z9bajnj4-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! building '/nix/store/fsvd5jlca59dhfijblgw76an1fg2n3pa-container-test-run-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/fsvd5jlca59dhfijblgw76an1fg2n3pa-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> ca: systemd-nspawn running (pid 53) container-test-run-certificates> client: systemd-nspawn running (pid 54) container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> server: systemd-nspawn running (pid 58) container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> client # [7524793.039959] client systemd-journald[69]: Journal started container-test-run-certificates> ca # [7524793.043094] ca systemd-journald[78]: Journal started container-test-run-certificates> client # [7524793.039993] client systemd-journald[69]: Runtime Journal (/run/log/journal/4c3551a942b0410c927d52c5a844707e) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> ca # [7524793.043122] ca systemd-journald[78]: Runtime Journal (/run/log/journal/d180ed2d4fdf497081685fbf47951641) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> client # [7524793.041136] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [7524793.045482] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [7524793.046631] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [7524793.050012] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [7524793.047117] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [7524793.050351] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [7524793.047518] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [7524793.050642] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [7524793.052676] client systemd-journald[69]: Time spent on flushing to /var/log/journal/4c3551a942b0410c927d52c5a844707e is 1.018ms for 6 entries. container-test-run-certificates> ca # [7524793.055194] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/d180ed2d4fdf497081685fbf47951641 is 1.050ms for 6 entries. container-test-run-certificates> client # [7524793.052676] client systemd-journald[69]: System Journal (/var/log/journal/4c3551a942b0410c927d52c5a844707e) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [7524793.055194] ca systemd-journald[78]: System Journal (/var/log/journal/d180ed2d4fdf497081685fbf47951641) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [7524793.056514] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [7524793.062895] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [7524793.056932] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [7524793.063229] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [7524793.056985] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [7524793.063282] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [7524793.057452] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [7524793.063711] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [7524793.057478] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [7524793.063746] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [7524793.057933] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [7524793.064070] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [7524793.057952] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [7524793.064086] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [7524793.069130] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [7524793.073876] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [7524793.069764] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [7524793.074651] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [7524793.080951] client systemd-tmpfiles[122]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [7524793.086288] ca systemd-tmpfiles[129]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [7524793.081111] client systemd-tmpfiles[122]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [7524793.081211] client systemd-tmpfiles[122]: fchmod() of /var/log/journal/4c3551a942b0410c927d52c5a844707e failed: Operation not permitted container-test-run-certificates> ca # [7524793.086440] ca systemd-tmpfiles[129]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [7524793.081359] client systemd-tmpfiles[122]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [7524793.086544] ca systemd-tmpfiles[129]: fchmod() of /var/log/journal/d180ed2d4fdf497081685fbf47951641 failed: Operation not permitted container-test-run-certificates> server # [7524793.044373] server systemd-journald[69]: Journal started container-test-run-certificates> ca # [7524793.086692] ca systemd-tmpfiles[129]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [7524793.044400] server systemd-journald[69]: Runtime Journal (/run/log/journal/66e7eb00f54044ee82c3d2296c4139bf) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> client # [7524793.082409] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [7524793.046359] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [7524793.083168] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [7524793.087796] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [7524793.083587] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [7524793.051560] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [7524793.088467] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [7524793.052048] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [7524793.090933] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [7524793.052404] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [7524793.095946] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [7524793.088764] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> client # [7524793.096412] client systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [7524793.056755] server systemd-journald[69]: Time spent on flushing to /var/log/journal/66e7eb00f54044ee82c3d2296c4139bf is 1.046ms for 6 entries. container-test-run-certificates> client # [7524793.104150] client systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [7524793.095679] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [7524793.128327] client systemd[1]: Finished Firewall. container-test-run-certificates> server # [7524793.056755] server systemd-journald[69]: System Journal (/var/log/journal/66e7eb00f54044ee82c3d2296c4139bf) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [7524793.128552] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [7524793.066705] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [7524793.104606] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [7524793.067167] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [7524793.128697] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [7524793.067222] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [7524793.105362] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [7524793.067685] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [7524793.129220] client systemd[1]: Starting Network Management... container-test-run-certificates> server # [7524793.067712] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [7524793.110436] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [7524793.068220] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [7524793.140720] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [7524793.068236] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [7524793.420737] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [7524793.138361] ca systemd[1]: Finished Firewall. container-test-run-certificates> client # [7524793.420806] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [7524793.073855] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [7524793.426014] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [7524793.138431] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [7524793.074519] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [7524793.426159] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [7524793.087052] server systemd-tmpfiles[121]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [7524793.426218] client systemd-networkd[182]: lo: Link UP container-test-run-certificates> server # [7524793.087230] server systemd-tmpfiles[121]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [7524793.138570] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [7524793.426222] client systemd-networkd[182]: lo: Gained carrier container-test-run-certificates> server # [7524793.087354] server systemd-tmpfiles[121]: fchmod() of /var/log/journal/66e7eb00f54044ee82c3d2296c4139bf failed: Operation not permitted container-test-run-certificates> ca # [7524793.139175] ca systemd[1]: Starting Network Management... container-test-run-certificates> server # [7524793.087543] server systemd-tmpfiles[121]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [7524793.426357] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [7524793.140694] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [7524793.088593] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [7524793.426577] client systemd[1]: Started Network Management. container-test-run-certificates> ca # [7524793.422652] ca systemd-networkd[195]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [7524793.426613] client systemd-networkd[182]: eth1: Link UP container-test-run-certificates> server # [7524793.089168] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [7524793.426727] client systemd-networkd[182]: eth1: Gained carrier container-test-run-certificates> ca # [7524793.422727] ca systemd-networkd[195]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [7524793.427148] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [7524793.427698] ca systemd-networkd[195]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [7524793.447918] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [7524793.089458] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [7524793.427842] ca systemd-networkd[195]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [7524793.427906] ca systemd-networkd[195]: lo: Link UP container-test-run-certificates> ca # [7524793.427909] ca systemd-networkd[195]: lo: Gained carrier container-test-run-certificates> ca # [7524793.428050] ca systemd-networkd[195]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [7524793.428273] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [7524793.428351] ca systemd-networkd[195]: eth1: Link UP container-test-run-certificates> server # [7524793.096720] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [7524793.428353] ca systemd-networkd[195]: eth1: Gained carrier container-test-run-certificates> ca # [7524793.428912] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [7524793.104590] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [7524793.435578] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [7524793.105297] server systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [7524793.111789] server systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [7524793.136702] server systemd[1]: Finished Firewall. container-test-run-certificates> server # [7524793.136836] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [7524793.136998] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [7524793.137587] server systemd[1]: Starting Network Management... container-test-run-certificates> server # [7524793.141490] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [7524793.425156] server systemd-networkd[186]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [7524793.425218] server systemd-networkd[186]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [7524793.430205] server systemd-networkd[186]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [7524793.430347] server systemd-networkd[186]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [7524793.430400] server systemd-networkd[186]: lo: Link UP container-test-run-certificates> server # [7524793.430403] server systemd-networkd[186]: lo: Gained carrier container-test-run-certificates> server # [7524793.430508] server systemd-networkd[186]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [7524793.430738] server systemd[1]: Started Network Management. container-test-run-certificates> server # [7524793.430763] server systemd-networkd[186]: eth1: Link UP container-test-run-certificates> server # [7524793.430878] server systemd-networkd[186]: eth1: Gained carrier container-test-run-certificates> server # [7524793.431463] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [7524793.453996] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [7524793.575313] server systemd-resolved[93]: Positive Trust Anchors: container-test-run-certificates> server # [7524793.575320] server systemd-resolved[93]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [7524793.575324] server systemd-resolved[93]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [7524793.575340] server systemd-resolved[93]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [7524793.585705] server systemd-resolved[93]: Using system hostname 'server'. container-test-run-certificates> server # [7524793.586704] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [7524793.586775] server systemd[1]: Reached target Network. container-test-run-certificates> server # [7524793.586814] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [7524793.586848] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [7524793.587037] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [7524793.587061] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [7524793.587079] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [7524793.587094] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [7524793.587190] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [7524793.587263] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [7524793.587343] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [7524793.587358] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [7524793.587382] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [7524793.600239] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [7524793.600807] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [7524793.600828] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [7524793.601379] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [7524793.602586] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [7524793.610692] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [7524793.672156] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> server # [7524793.672156] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [7524793.672521] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> server # [7524793.673399] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> server # [7524793.674504] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [7524793.674538] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> server # [7524793.674538] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [7524793.674538] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> ca # [7524793.571377] ca systemd-resolved[101]: Positive Trust Anchors: container-test-run-certificates> ca # [7524793.571384] ca systemd-resolved[101]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [7524793.571388] ca systemd-resolved[101]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [7524793.571410] ca systemd-resolved[101]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [7524793.582065] ca systemd-resolved[101]: Using system hostname 'ca'. container-test-run-certificates> ca # [7524793.582944] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [7524793.582994] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [7524793.583033] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [7524793.583062] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [7524793.583202] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [7524793.583219] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [7524793.583233] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [7524793.583245] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [7524793.583330] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [7524793.583405] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [7524793.583477] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [7524793.583488] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [7524793.583507] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [7524793.584210] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [7524793.584541] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [7524793.584561] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [7524793.584928] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [7524793.585390] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [7524793.586059] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [7524793.608130] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [7524793.681936] ca acme-setup-privileged[201]: + set -euo pipefail container-test-run-certificates> ca # [7524793.681936] ca acme-setup-privileged[201]: + cd /var/lib/acme container-test-run-certificates> ca # [7524793.681936] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> client # [7524793.587276] client systemd-resolved[94]: Positive Trust Anchors: container-test-run-certificates> client # [7524793.587285] client systemd-resolved[94]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [7524793.587289] client systemd-resolved[94]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [7524793.587305] client systemd-resolved[94]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [7524793.598207] client systemd-resolved[94]: Using system hostname 'client'. container-test-run-certificates> client # [7524793.599162] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [7524793.599218] client systemd[1]: Reached target Network. container-test-run-certificates> client # [7524793.599254] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [7524793.599286] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [7524793.599301] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [7524793.599312] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [7524793.599391] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [7524793.599447] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [7524793.599516] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [7524793.599525] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [7524793.599545] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [7524793.600241] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [7524793.600797] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [7524793.601386] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [7524793.612285] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [7524793.682368] client nsncd[189]: Aug 26 12:14:11.048 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [7524793.682517] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [7524793.682556] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [7524793.682592] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [7524793.700649] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [7524793.701163] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [7524793.708059] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [7524793.708515] client systemd[1]: Started Console Getty. container-test-run-certificates> client # [7524793.708536] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [7524793.708548] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [7524793.757915] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [7524793.758305] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [7524793.758305] client dbus-broker-launch[190]: Invalid user-name in /nix/store/n25qs0cxdhj6rld8wlnm0r6dhj2cw2r3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [7524793.758581] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [7524793.761963] client dbus-broker-launch[190]: Ready container-test-run-certificates> ca # [7524793.683125] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [7524793.684106] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [7524793.684106] ca acme-setup-privileged[201]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [7524793.684157] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [7524793.684157] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [7524793.690323] ca nsncd[203]: Aug 26 12:14:11.055 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [7524793.700456] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [7524793.700567] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [7524793.700603] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [7524793.701184] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [7524793.701531] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [7524793.707484] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [7524793.708226] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [7524793.708250] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [7524793.708264] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [7524793.767288] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [7524793.767573] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [7524793.767573] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/dyyq5fj9d2iyrp213l8wpy3imn4cyazg-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [7524793.767796] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [7524793.771051] ca dbus-broker-launch[205]: Ready container-test-run-certificates> ca # [7524794.037384] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [7524793.686144] server nsncd[194]: Aug 26 12:14:11.051 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [7524793.686194] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [7524793.686241] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [7524793.686276] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [7524793.700882] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [7524793.701349] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [7524793.707816] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [7524793.708594] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [7524793.708618] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [7524793.708630] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [7524793.757664] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [7524793.758137] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [7524793.758137] server dbus-broker-launch[195]: Invalid user-name in /nix/store/3998vwjgq9b8mfq8zd315f0dx0zdhk3x-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [7524793.758419] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [7524793.762061] server dbus-broker-launch[195]: Ready container-test-run-certificates> ca # [7524794.073547] ca systemd-logind[230]: New seat seat0. container-test-run-certificates> ca # [7524794.073681] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [7524794.074444] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [7524794.106607] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [7524794.106887] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [7524794.109330] ca acme-setup-start[219]: + set -euo pipefail container-test-run-certificates> ca # [7524794.109330] ca acme-setup-start[219]: + test -e ca/key.pem container-test-run-certificates> ca # [7524794.109554] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [7524794.116334] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [7524794.117389] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> ca # [7524794.237194] ca step-ca[204]: badger 2026/08/26 12:14:11 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [7524794.238949] ca step-ca[204]: 2026/08/26 12:14:11 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [7524794.240939] ca step-ca[204]: 2026/08/26 12:14:11 Starting Smallstep CA/0.30.2 (linux/amd64) container-test-run-certificates> ca # [7524794.240939] ca step-ca[204]: 2026/08/26 12:14:11 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [7524794.240939] ca step-ca[204]: 2026/08/26 12:14:11 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [7524794.240939] ca step-ca[204]: 2026/08/26 12:14:11 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [7524794.241023] ca step-ca[204]: 2026/08/26 12:14:11 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [7524794.241023] ca step-ca[204]: 2026/08/26 12:14:11 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [7524794.241023] ca step-ca[204]: 2026/08/26 12:14:11 X.509 Root Fingerprint: b15329739d4cc68f6a1e958f05562a19c01fcb4a3dcaf5c0f2d06a6cd05e1ad4 container-test-run-certificates> ca # [7524794.241125] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [7524794.241173] ca step-ca[204]: 2026/08/26 12:14:11 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> client # [7524794.033315] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> client # [7524794.072634] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [7524794.072822] client systemd[1]: Started User Login Management. container-test-run-certificates> client # [7524794.073708] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [7524794.106494] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [7524794.106594] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [7524794.107014] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [7524794.107118] client systemd[1]: Startup finished in 1.336s. container-test-run-certificates> server # [7524794.039096] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [7524794.090535] server systemd-logind[221]: New seat seat0. container-test-run-certificates> server # [7524794.090629] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [7524794.100153] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> server # [7524794.100153] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> server # [7524794.100507] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [7524794.101230] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [7524794.108050] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [7524794.108861] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server # [7524794.108981] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [7524794.109019] server systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [7524794.507936] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [7524794.509340] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [7524794.509383] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [7524794.515007] ca acme-ca.foo-start[283]: + cd ca.foo container-test-run-certificates> ca # [7524794.515299] ca acme-ca.foo-start[283]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [7524794.515867] ca acme-ca.foo-start[284]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [7524794.516019] ca acme-ca.foo-start[283]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [7524794.516834] ca acme-ca.foo-start[283]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [7524794.516978] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [7524794.517997] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [7524794.519044] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [7524794.519889] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [7524794.519915] ca acme-ca.foo-start[256]: + '[' -d out ']' container-test-run-certificates> ca # [7524794.519915] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [7524794.520804] ca acme-ca.foo-start[256]: + chown -R acme:nginx out container-test-run-certificates> ca # [7524794.522278] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [7524794.522278] ca acme-ca.foo-start[256]: + '[' -d certificates ']' container-test-run-certificates> ca # [7524794.524460] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [7524794.525347] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> server # [7524794.511388] server acme-test.foo-start[244]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7524794.512838] server acme-test.foo-start[244]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [7524794.512901] server acme-test.foo-start[244]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [7524794.518131] server acme-test.foo-start[256]: + cd test.foo container-test-run-certificates> server # [7524794.518387] server acme-test.foo-start[256]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [7524794.518929] server acme-test.foo-start[257]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [7524794.519067] server acme-test.foo-start[256]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [7524794.519696] server acme-test.foo-start[256]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [7524794.519834] server acme-test.foo-start[244]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [7524794.520725] server acme-test.foo-start[244]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [7524794.521605] server acme-test.foo-start[244]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [7524794.522501] server acme-test.foo-start[244]: + for fixpath in out certificates container-test-run-certificates> server # [7524794.522686] server acme-test.foo-start[244]: + '[' -d out ']' container-test-run-certificates> server # [7524794.522686] server acme-test.foo-start[244]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [7524794.523673] server acme-test.foo-start[244]: + chown -R acme:nginx out container-test-run-certificates> server # [7524794.525245] server acme-test.foo-start[244]: + for fixpath in out certificates container-test-run-certificates> server # [7524794.525256] server acme-test.foo-start[244]: + '[' -d certificates ']' container-test-run-certificates> server # [7524794.527066] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [7524794.527859] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> server # [7524794.686093] server systemd-networkd[186]: eth1: Gained IPv6LL container-test-run-certificates> client # [7524794.814094] client systemd-networkd[182]: eth1: Gained IPv6LL container-test-run-certificates> server # [7524794.922191] server nginx-pre-start[268]: nginx: the configuration file /nix/store/nfgk30pbmji62whlqlbylrn263ifbnzr-nginx.conf syntax is ok container-test-run-certificates> ca # [7524794.926269] ca nginx-pre-start[295]: nginx: the configuration file /nix/store/740f3fnhqb0xvq046dzffrr5vswlq3w9-nginx.conf syntax is ok container-test-run-certificates> server # [7524794.922502] server nginx-pre-start[268]: nginx: configuration file /nix/store/nfgk30pbmji62whlqlbylrn263ifbnzr-nginx.conf test is successful container-test-run-certificates> ca # [7524794.926566] ca nginx-pre-start[295]: nginx: configuration file /nix/store/740f3fnhqb0xvq046dzffrr5vswlq3w9-nginx.conf test is successful container-test-run-certificates> server # [7524794.924575] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [7524794.944216] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [7524794.924791] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [7524794.944502] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [7524794.925355] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [7524794.945451] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> server # [7524795.295319] server acme-order-renew-test.foo-start[271]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7524795.297103] server acme-order-renew-test.foo-start[271]: + set -euo pipefail container-test-run-certificates> server # [7524795.297172] server acme-order-renew-test.foo-start[271]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [7524795.297251] server acme-order-renew-test.foo-start[271]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [7524795.298041] server acme-order-renew-test.foo-start[271]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [7524795.306832] server acme-order-renew-test.foo-start[282]: 2026/08/26 12:14:12 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [7524795.307081] server acme-order-renew-test.foo-start[282]: 2026/08/26 12:14:12 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> server # [7524795.320760] server acme-order-renew-test.foo-start[282]: 2026/08/26 12:14:12 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [7524795.320924] server acme-order-renew-test.foo-start[271]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [7524795.320924] server acme-order-renew-test.foo-start[271]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [7524795.320924] server acme-order-renew-test.foo-start[271]: + exit 10 container-test-run-certificates> server # [7524795.322470] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [7524795.322556] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [7524795.322740] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [7524795.322914] server systemd[1]: Startup finished in 2.552s. container-test-run-certificates> ca # [7524795.302563] ca acme-order-renew-ca.foo-start[298]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [7524795.303869] ca acme-order-renew-ca.foo-start[298]: + set -euo pipefail container-test-run-certificates> ca # [7524795.303902] ca acme-order-renew-ca.foo-start[298]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [7524795.303957] ca acme-order-renew-ca.foo-start[298]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [7524795.304556] ca acme-order-renew-ca.foo-start[298]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [7524795.312891] ca acme-order-renew-ca.foo-start[309]: 2026/08/26 12:14:12 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [7524795.313100] ca acme-order-renew-ca.foo-start[309]: 2026/08/26 12:14:12 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [7524795.324878] ca step-ca[204]: time="2026-08-26T12:14:12Z" level=info duration="74.371µs" duration-ns=74371 fields.time="2026-08-26T12:14:12Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=4b17e9b3-3a78-473d-a93d-661844578985 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7524795.325138] ca acme-order-renew-ca.foo-start[309]: 2026/08/26 12:14:12 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [7524795.325967] ca step-ca[204]: time="2026-08-26T12:14:12Z" level=info duration="800.498µs" duration-ns=800498 fields.time="2026-08-26T12:14:12Z" method=HEAD name=ca nonce=RnVvUUVQRFMwczR1TGJsSjNKRGVTWnlIUm84aENMUFc path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=32afc83f-dcd0-45a4-992e-e33e33e2346e size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7524795.326946] ca step-ca[204]: time="2026-08-26T12:14:12Z" level=info duration="699.728µs" duration-ns=699728 fields.time="2026-08-26T12:14:12Z" method=POST name=ca nonce=dUZ2UTU5S0JiamdBdTlnNGd5Z3Rjc01SZ2JwdEV4bGk path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=c8528e94-4aad-49f0-b98f-0b1eec010db1 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/8HT6bkNE44KFdXo3aKIPz9lIAhLrezsJ/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7524795.327112] ca acme-order-renew-ca.foo-start[309]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [7524795.327112] ca acme-order-renew-ca.foo-start[309]: Your account credentials have been saved in your container-test-run-certificates> ca # [7524795.327112] ca acme-order-renew-ca.foo-start[309]: configuration directory at "accounts". container-test-run-certificates> ca # [7524795.327112] ca acme-order-renew-ca.foo-start[309]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [7524795.327112] ca acme-order-renew-ca.foo-start[309]: configuration directory will also contain private keys container-test-run-certificates> ca # [7524795.327112] ca acme-order-renew-ca.foo-start[309]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [7524795.327112] ca acme-order-renew-ca.foo-start[309]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [7524795.327221] ca acme-order-renew-ca.foo-start[309]: 2026/08/26 12:14:12 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [7524795.328510] ca step-ca[204]: time="2026-08-26T12:14:12Z" level=info duration=1.163933ms duration-ns=1163933 fields.time="2026-08-26T12:14:12Z" method=POST name=ca nonce=UVViZ0hqTlA5b0UwOVRyeG9JR1pxQ1VRZHhpbDlneDU path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=a9d38484-573e-430d-84f1-4618d5521bf4 response="{\"id\":\"0zCykSniVDBngJLrxqAGvghpaMNThoZf\",\"status\":\"pending\",\"expires\":\"2026-08-27T12:14:12Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-26T12:13:12Z\",\"notAfter\":\"2026-11-24T12:14:12Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/f0NPSb59FZoiNs28bn5bNM9LWG764e7k\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/0zCykSniVDBngJLrxqAGvghpaMNThoZf/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7524795.385311] ca step-ca[204]: time="2026-08-26T12:14:12Z" level=info duration="718.043µs" duration-ns=718043 fields.time="2026-08-26T12:14:12Z" method=POST name=ca nonce=NXhJako1MWxzQ0FCOTRiSHdqTjlsbTViYVRnbnp0OGk path=/acme/acme/authz/f0NPSb59FZoiNs28bn5bNM9LWG764e7k protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=27eb0421-1554-4e6a-99b8-836831e0d6e5 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"I3RGbGwfayW2eOfHYC8D0oQ8OxuHiWgN\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/f0NPSb59FZoiNs28bn5bNM9LWG764e7k/XDxrIR1xb7HnhY9Tvfoax0eFXXwFK7NR\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"I3RGbGwfayW2eOfHYC8D0oQ8OxuHiWgN\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/f0NPSb59FZoiNs28bn5bNM9LWG764e7k/b7zAUafRYP2bJHSrhi1hKuTorNMKmEUw\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"I3RGbGwfayW2eOfHYC8D0oQ8OxuHiWgN\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/f0NPSb59FZoiNs28bn5bNM9LWG764e7k/FsXZA7MVzF4oRXq47lbfi4HugTyEDPxm\"}],\"wildcard\":false,\"expires\":\"2026-08-27T12:14:12Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7524795.385526] ca acme-order-renew-ca.foo-start[309]: 2026/08/26 12:14:12 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/f0NPSb59FZoiNs28bn5bNM9LWG764e7k container-test-run-certificates> ca # [7524795.385526] ca acme-order-renew-ca.foo-start[309]: 2026/08/26 12:14:12 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [7524795.385562] ca acme-order-renew-ca.foo-start[309]: 2026/08/26 12:14:12 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [7524795.385562] ca acme-order-renew-ca.foo-start[309]: 2026/08/26 12:14:12 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [7524795.387407] ca step-ca[204]: time="2026-08-26T12:14:12Z" level=info duration=1.620422ms duration-ns=1620422 fields.time="2026-08-26T12:14:12Z" method=POST name=ca nonce=MFBBaFh1NXVTOTFuYk8xRzZNazBrMWxtTlV4Q3BFdmI path=/acme/acme/challenge/f0NPSb59FZoiNs28bn5bNM9LWG764e7k/b7zAUafRYP2bJHSrhi1hKuTorNMKmEUw protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=31e3c033-3902-46ca-a9a8-5033c18e1f37 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"I3RGbGwfayW2eOfHYC8D0oQ8OxuHiWgN\",\"validated\":\"2026-08-26T12:14:12Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/f0NPSb59FZoiNs28bn5bNM9LWG764e7k/b7zAUafRYP2bJHSrhi1hKuTorNMKmEUw\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7524795.387511] ca acme-order-renew-ca.foo-start[309]: 2026/08/26 12:14:12 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [7524795.387544] ca acme-order-renew-ca.foo-start[309]: 2026/08/26 12:14:12 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [7524795.389789] ca step-ca[204]: time="2026-08-26T12:14:12Z" level=info duration=1.957297ms duration-ns=1957297 fields.time="2026-08-26T12:14:12Z" method=POST name=ca nonce=VXRmVFBmdTFEUGN0RWlwT0xhcGtKeW9OOG1XbXhpWlk path=/acme/acme/order/0zCykSniVDBngJLrxqAGvghpaMNThoZf/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=350f4c94-bce7-4d2d-8819-589ca6f69db3 response="{\"id\":\"0zCykSniVDBngJLrxqAGvghpaMNThoZf\",\"status\":\"valid\",\"expires\":\"2026-08-27T12:14:12Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-26T12:13:12Z\",\"notAfter\":\"2026-11-24T12:14:12Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/f0NPSb59FZoiNs28bn5bNM9LWG764e7k\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/0zCykSniVDBngJLrxqAGvghpaMNThoZf/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/8POEcSRYDeTM7UYSJavedJjcGpSE3EiX\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7524795.390565] ca step-ca[204]: time="2026-08-26T12:14:12Z" level=info certificate="MIIB1DCCAXqgAwIBAgIRAJIlfoQZyppecFPfsxmRmoowCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODI2MTIxMzEyWhcNMjYxMTI0MTIxNDEyWjARMQ8wDQYDVQQDEwZjYS5mb28wWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAQwKB+xhJ5uMiEKqso0kc5XyPI5przZOrKb7Yx1H/EMrJLIcktPiMq1OIlGm+tDt2NezehoA9xchLeXx2p/cMkHo4GkMIGhMA4GA1UdDwEB/wQEAwIHgDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHQYDVR0OBBYEFHIn0HPAUN3+EMLRaiOgbvpNAguwMB8GA1UdIwQYMBaAFCmxz2kcxir9PK00/f5mRtjCyoEGMBEGA1UdEQQKMAiCBmNhLmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSAAwRQIhAMkkzwrJPKhSEuvis5EKsY4NCFkn3x/4ES4ieq2ql9EqAiBi0B4FFS+GePfsgVY5JSSh6CeV5dslxbbqLWCpgEi63w==" duration="569.392µs" duration-ns=569392 fields.time="2026-08-26T12:14:12Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=QnFDQmhGV2dRQjhGZUlVVlhiZUVobTlsbDdzTnBtUzk path=/acme/acme/certificate/8POEcSRYDeTM7UYSJavedJjcGpSE3EiX protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=d4f2f4ab-1cbc-4461-b174-ed2e52b99ae2 sans="map[dns:[ca.foo]]" serial=194261968418073075307199584447681895050 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-08-26T12:13:12Z" valid-to="2026-11-24T12:14:12Z" container-test-run-certificates> ca # [7524795.390696] ca acme-order-renew-ca.foo-start[309]: 2026/08/26 12:14:12 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [7524795.393463] ca acme-order-renew-ca.foo-start[298]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [7524795.394418] ca acme-order-renew-ca.foo-start[298]: + touch out/acme-success container-test-run-certificates> ca # [7524795.395200] ca acme-order-renew-ca.foo-start[298]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [7524795.395749] ca acme-order-renew-ca.foo-start[298]: + touch out/renewed container-test-run-certificates> ca # [7524795.396463] ca acme-order-renew-ca.foo-start[298]: + echo Installing new certificate container-test-run-certificates> ca # [7524795.396463] ca acme-order-renew-ca.foo-start[298]: Installing new certificate container-test-run-certificates> ca # [7524795.396509] ca acme-order-renew-ca.foo-start[298]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [7524795.397194] ca acme-order-renew-ca.foo-start[331]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [7524795.397336] ca acme-order-renew-ca.foo-start[298]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [7524795.398004] ca acme-order-renew-ca.foo-start[332]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [7524795.398131] ca acme-order-renew-ca.foo-start[298]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [7524795.398781] ca acme-order-renew-ca.foo-start[333]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [7524795.398906] ca acme-order-renew-ca.foo-start[298]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [7524795.399735] ca acme-order-renew-ca.foo-start[298]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [7524795.400542] ca acme-order-renew-ca.foo-start[298]: + for fixpath in out certificates container-test-run-certificates> ca # [7524795.400542] ca acme-order-renew-ca.foo-start[298]: + '[' -d out ']' container-test-run-certificates> ca # [7524795.400574] ca acme-order-renew-ca.foo-start[298]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [7524795.401342] ca acme-order-renew-ca.foo-start[298]: + chown -R acme:nginx out container-test-run-certificates> ca # [7524795.402906] ca acme-order-renew-ca.foo-start[298]: + for fixpath in out certificates container-test-run-certificates> ca # [7524795.402929] ca acme-order-renew-ca.foo-start[298]: + '[' -d certificates ']' container-test-run-certificates> ca # [7524795.402929] ca acme-order-renew-ca.foo-start[298]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [7524795.403714] ca acme-order-renew-ca.foo-start[298]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [7524795.404925] ca acme-order-renew-ca.foo-start[298]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [7524795.454119] ca systemd-networkd[195]: eth1: Gained IPv6LL container-test-run-certificates> ca # [7524795.501731] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [7524795.504246] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [7524795.504366] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca # [7524795.856929] ca nginx[349]: nginx: the configuration file /nix/store/740f3fnhqb0xvq046dzffrr5vswlq3w9-nginx.conf syntax is ok container-test-run-certificates> ca # [7524795.857236] ca nginx[349]: nginx: configuration file /nix/store/740f3fnhqb0xvq046dzffrr5vswlq3w9-nginx.conf test is successful container-test-run-certificates> ca # [7524796.234840] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [7524796.235052] ca systemd[1]: Startup finished in 3.458s. container-test-run-certificates> ca # [7524796.635875] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 1.66 seconds) container-test-run-certificates> ca # [7524797.013819] ca acme-order-renew-ca.foo-start[364]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [7524797.015504] ca acme-order-renew-ca.foo-start[364]: + set -euo pipefail container-test-run-certificates> ca # [7524797.015542] ca acme-order-renew-ca.foo-start[364]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [7524797.015602] ca acme-order-renew-ca.foo-start[364]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [7524797.016172] ca acme-order-renew-ca.foo-start[364]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [7524797.016206] ca acme-order-renew-ca.foo-start[364]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [7524797.016360] ca acme-order-renew-ca.foo-start[372]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [7524797.017744] ca acme-order-renew-ca.foo-start[364]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [7524797.017782] ca acme-order-renew-ca.foo-start[364]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [7524797.043931] ca step-ca[204]: time="2026-08-26T12:14:14Z" level=info duration="56.246µs" duration-ns=56246 fields.time="2026-08-26T12:14:14Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=2790ae02-611c-4722-b2b3-7aacbf120178 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7524797.044268] ca acme-order-renew-ca.foo-start[373]: 2026/08/26 12:14:14 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [7524797.044268] ca acme-order-renew-ca.foo-start[373]: 2026/08/26 12:14:14 [INFO] [ca.foo] The certificate expires at 2026-11-24T12:14:12Z, the renewal can be performed in 1439h59m37.590145744s: no renewal. container-test-run-certificates> ca # [7524797.046294] ca acme-order-renew-ca.foo-start[364]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [7524797.047593] ca acme-order-renew-ca.foo-start[364]: + touch out/acme-success container-test-run-certificates> ca # [7524797.049394] ca acme-order-renew-ca.foo-start[364]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [7524797.050487] ca acme-order-renew-ca.foo-start[364]: + for fixpath in out certificates container-test-run-certificates> ca # [7524797.050487] ca acme-order-renew-ca.foo-start[364]: + '[' -d out ']' container-test-run-certificates> ca # [7524797.050487] ca acme-order-renew-ca.foo-start[364]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [7524797.051749] ca acme-order-renew-ca.foo-start[364]: + chown -R acme:nginx out container-test-run-certificates> ca # [7524797.053965] ca acme-order-renew-ca.foo-start[364]: + for fixpath in out certificates container-test-run-certificates> ca # [7524797.053965] ca acme-order-renew-ca.foo-start[364]: + '[' -d certificates ']' container-test-run-certificates> ca # [7524797.054008] ca acme-order-renew-ca.foo-start[364]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [7524797.055603] ca acme-order-renew-ca.foo-start[364]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [7524797.057548] ca acme-order-renew-ca.foo-start[364]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [7524797.149402] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [7524797.149519] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [7524800.158920] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [7524800.159025] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [7524800.159582] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [7524800.160386] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.37 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [110 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 26 12:14:11 2026 GMT container-test-run-certificates> * expire date: Sep 25 12:14:11 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 366222 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [7524800.507294] server acme-test.foo-start[305]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7524800.508879] server acme-test.foo-start[305]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [7524800.508932] server acme-test.foo-start[305]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [7524800.513177] server acme-test.foo-start[315]: + cd test.foo container-test-run-certificates> server # [7524800.513331] server acme-test.foo-start[315]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [7524800.513932] server acme-test.foo-start[316]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [7524800.514050] server acme-test.foo-start[315]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [7524800.514668] server acme-test.foo-start[315]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [7524800.514786] server acme-test.foo-start[305]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [7524800.515620] server acme-test.foo-start[305]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [7524800.516381] server acme-test.foo-start[305]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [7524800.517152] server acme-test.foo-start[305]: + for fixpath in out certificates container-test-run-certificates> server # [7524800.517163] server acme-test.foo-start[305]: + '[' -d out ']' container-test-run-certificates> server # [7524800.517163] server acme-test.foo-start[305]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [7524800.517894] server acme-test.foo-start[305]: + chown -R acme:nginx out container-test-run-certificates> server # [7524800.519514] server acme-test.foo-start[305]: + for fixpath in out certificates container-test-run-certificates> server # [7524800.519514] server acme-test.foo-start[305]: + '[' -d certificates ']' container-test-run-certificates> server # [7524800.521147] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [7524800.522814] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [7524800.853977] server acme-order-renew-test.foo-start[323]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7524800.855850] server acme-order-renew-test.foo-start[323]: + set -euo pipefail container-test-run-certificates> server # [7524800.855932] server acme-order-renew-test.foo-start[323]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [7524800.855974] server acme-order-renew-test.foo-start[323]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [7524800.856685] server acme-order-renew-test.foo-start[323]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [7524800.878765] server acme-order-renew-test.foo-start[331]: 2026/08/26 12:14:18 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [7524800.883745] server acme-order-renew-test.foo-start[331]: !!!! HEADS UP !!!! container-test-run-certificates> server # [7524800.883745] server acme-order-renew-test.foo-start[331]: Your account credentials have been saved in your container-test-run-certificates> server # [7524800.883745] server acme-order-renew-test.foo-start[331]: configuration directory at "accounts". container-test-run-certificates> server # [7524800.883745] server acme-order-renew-test.foo-start[331]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [7524800.883745] server acme-order-renew-test.foo-start[331]: configuration directory will also contain private keys container-test-run-certificates> server # [7524800.883745] server acme-order-renew-test.foo-start[331]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [7524800.883745] server acme-order-renew-test.foo-start[331]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [7524800.883868] server acme-order-renew-test.foo-start[331]: 2026/08/26 12:14:18 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [7524800.944196] server acme-order-renew-test.foo-start[331]: 2026/08/26 12:14:18 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/UgSpES082ljNRDVHBG1MiGcKva2cW3Ep container-test-run-certificates> server # [7524800.944196] server acme-order-renew-test.foo-start[331]: 2026/08/26 12:14:18 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [7524800.944196] server acme-order-renew-test.foo-start[331]: 2026/08/26 12:14:18 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [7524800.944196] server acme-order-renew-test.foo-start[331]: 2026/08/26 12:14:18 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [7524800.946624] server acme-order-renew-test.foo-start[331]: 2026/08/26 12:14:18 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [7524800.946667] server acme-order-renew-test.foo-start[331]: 2026/08/26 12:14:18 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [7524800.951021] server acme-order-renew-test.foo-start[331]: 2026/08/26 12:14:18 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [7524800.953573] server acme-order-renew-test.foo-start[323]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [7524800.954674] server acme-order-renew-test.foo-start[323]: + touch out/acme-success container-test-run-certificates> server # [7524800.955483] server acme-order-renew-test.foo-start[323]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [7524800.956070] server acme-order-renew-test.foo-start[323]: + touch out/renewed container-test-run-certificates> server # [7524800.956821] server acme-order-renew-test.foo-start[323]: + echo Installing new certificate container-test-run-certificates> server # [7524800.956840] server acme-order-renew-test.foo-start[323]: Installing new certificate container-test-run-certificates> server # [7524800.956840] server acme-order-renew-test.foo-start[323]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [7524800.957577] server acme-order-renew-test.foo-start[352]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [7524800.957719] server acme-order-renew-test.foo-start[323]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [7524800.958451] server acme-order-renew-test.foo-start[353]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [7524800.958599] server acme-order-renew-test.foo-start[323]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [7524800.959425] server acme-order-renew-test.foo-start[354]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [7524800.959558] server acme-order-renew-test.foo-start[323]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [7524800.960420] server acme-order-renew-test.foo-start[323]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [7524800.961286] server acme-order-renew-test.foo-start[323]: + for fixpath in out certificates container-test-run-certificates> server # [7524800.961297] server acme-order-renew-test.foo-start[323]: + '[' -d out ']' container-test-run-certificates> server # [7524800.961307] server acme-order-renew-test.foo-start[323]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [7524800.962107] server acme-order-renew-test.foo-start[323]: + chown -R acme:nginx out container-test-run-certificates> server # [7524800.963398] server acme-order-renew-test.foo-start[323]: + for fixpath in out certificates container-test-run-certificates> server # [7524800.963429] server acme-order-renew-test.foo-start[323]: + '[' -d certificates ']' container-test-run-certificates> server # [7524800.963429] server acme-order-renew-test.foo-start[323]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [7524800.964188] server acme-order-renew-test.foo-start[323]: + chown -R acme:nginx certificates container-test-run-certificates> server # [7524800.965441] server acme-order-renew-test.foo-start[323]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> server # [7524801.038435] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [7524801.040327] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [7524801.040427] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> ca # [7524800.878453] ca step-ca[204]: time="2026-08-26T12:14:18Z" level=info duration="38.132µs" duration-ns=38132 fields.time="2026-08-26T12:14:18Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=3ce9330a-bf66-4fae-8c32-e2907d8c24ac response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7524800.881777] ca step-ca[204]: time="2026-08-26T12:14:18Z" level=info duration=2.180938ms duration-ns=2180938 fields.time="2026-08-26T12:14:18Z" method=HEAD name=ca nonce=S3g1a0tQdDN5V2d6QlBQdmVvNlB3MHd2Z1NHTnYwMkI path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=f28d642d-dd84-4968-81b0-71ce40d3da56 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7524800.883444] ca step-ca[204]: time="2026-08-26T12:14:18Z" level=info duration="814.134µs" duration-ns=814134 fields.time="2026-08-26T12:14:18Z" method=POST name=ca nonce=ekJINDIzcDdzOUdMNlZuTGp3aTdaSmtVV3VyWFhTMzQ path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=987107ea-7884-4ef5-a423-0574a6d90656 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/nfkzY2pVGP88ucB5GvUTv3QG3abTzRev/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7524800.885645] ca step-ca[204]: time="2026-08-26T12:14:18Z" level=info duration=1.238011ms duration-ns=1238011 fields.time="2026-08-26T12:14:18Z" method=POST name=ca nonce=bGl5enhsTWQ2MVo5YlZMNGxwdFFlWWZBbTQ3a0hxcEQ path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=f0ae348d-72ff-484f-bc51-c20b88b90e70 response="{\"id\":\"fEziVFygb8dA31wOZnuOVJqs8M5B2Ltp\",\"status\":\"pending\",\"expires\":\"2026-08-27T12:14:18Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-26T12:13:18Z\",\"notAfter\":\"2026-11-24T12:14:18Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/UgSpES082ljNRDVHBG1MiGcKva2cW3Ep\"],\"finalize\":\"https://ca.foo/acme/acme/order/fEziVFygb8dA31wOZnuOVJqs8M5B2Ltp/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7524800.943958] ca step-ca[204]: time="2026-08-26T12:14:18Z" level=info duration="568.231µs" duration-ns=568231 fields.time="2026-08-26T12:14:18Z" method=POST name=ca nonce=VGNFNVlBcmd0aE9ubG9VZFR5eWptdWxHOGs0eWxJamU path=/acme/acme/authz/UgSpES082ljNRDVHBG1MiGcKva2cW3Ep protocol=HTTP/1.1 referer= remote-address="::1" request-id=f2b0a080-dd1b-4feb-be81-35619f62e947 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"NnIXFVREI0lRFEbyAVrSgZ5qOfMTSAJr\",\"url\":\"https://ca.foo/acme/acme/challenge/UgSpES082ljNRDVHBG1MiGcKva2cW3Ep/tXXittXW6M7OrnDFvWVrA7283DesF0NC\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"NnIXFVREI0lRFEbyAVrSgZ5qOfMTSAJr\",\"url\":\"https://ca.foo/acme/acme/challenge/UgSpES082ljNRDVHBG1MiGcKva2cW3Ep/gw392YdBeTS2HIOwPdMZYIDMNYa0TEtm\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"NnIXFVREI0lRFEbyAVrSgZ5qOfMTSAJr\",\"url\":\"https://ca.foo/acme/acme/challenge/UgSpES082ljNRDVHBG1MiGcKva2cW3Ep/6GtfNVlYAQql6aLOhAt4Zig9X85DQCM9\"}],\"wildcard\":false,\"expires\":\"2026-08-27T12:14:18Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7524800.946351] ca step-ca[204]: time="2026-08-26T12:14:18Z" level=info duration=1.446264ms duration-ns=1446264 fields.time="2026-08-26T12:14:18Z" method=POST name=ca nonce=b2pjMzZIQ1p6Wkt0SHJKQjZNcVpaODRBazhVaVRsT3o path=/acme/acme/challenge/UgSpES082ljNRDVHBG1MiGcKva2cW3Ep/gw392YdBeTS2HIOwPdMZYIDMNYa0TEtm protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=8384f4bd-315d-41d1-a1ff-ec601178ba68 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"NnIXFVREI0lRFEbyAVrSgZ5qOfMTSAJr\",\"validated\":\"2026-08-26T12:14:18Z\",\"url\":\"https://ca.foo/acme/acme/challenge/UgSpES082ljNRDVHBG1MiGcKva2cW3Ep/gw392YdBeTS2HIOwPdMZYIDMNYa0TEtm\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7524800.949730] ca step-ca[204]: time="2026-08-26T12:14:18Z" level=info duration=1.818545ms duration-ns=1818545 fields.time="2026-08-26T12:14:18Z" method=POST name=ca nonce=amVjZkt5UlNWRjhaSWUxMkhWNTY0enRmSmFzSG5IWks path=/acme/acme/order/fEziVFygb8dA31wOZnuOVJqs8M5B2Ltp/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=7023d2bc-0897-4a59-be74-21a00b850c5a response="{\"id\":\"fEziVFygb8dA31wOZnuOVJqs8M5B2Ltp\",\"status\":\"valid\",\"expires\":\"2026-08-27T12:14:18Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-26T12:13:18Z\",\"notAfter\":\"2026-11-24T12:14:18Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/UgSpES082ljNRDVHBG1MiGcKva2cW3Ep\"],\"finalize\":\"https://ca.foo/acme/acme/order/fEziVFygb8dA31wOZnuOVJqs8M5B2Ltp/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/Tr1JMKguJCXIw1Fco8Fjxy8Vf92f0tDg\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7524800.950865] ca step-ca[204]: time="2026-08-26T12:14:18Z" level=info certificate="MIIB1zCCAX2gAwIBAgIQSigwkCfHgoeOxUo6O5ppvzAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MjYxMjEzMThaFw0yNjExMjQxMjE0MThaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE4a4DW9hu7tE8pD15dRpDlxIuTbWX3oB9us/Zs3xIUBxtmHPWQhfHzSFzAWBSlXyl/xgNYzXcEjnUvpxyxsbOa6OBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBQ5Camjla5hPmQA3SPnj9K7Yg6nIjAfBgNVHSMEGDAWgBQpsc9pHMYq/TytNP3+ZkbYwsqBBjATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSAAwRQIgV7CyHVVsWszBS1IkIf8VMwrK4Z2dD0GvMK9clwCvPHUCIQD8ICg1IARXD6WMHUVt8Z3d0J3+wuUpMKtjQqAPEw8eZA==" duration="376.72µs" duration-ns=376720 fields.time="2026-08-26T12:14:18Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=UEtON3cwUDV2VHc4SW9qaXRDTFB3UTZnWkZsVm9KVEc path=/acme/acme/certificate/Tr1JMKguJCXIw1Fco8Fjxy8Vf92f0tDg protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=f711bd32-989b-4695-8ca2-05c6c23b3b94 sans="map[dns:[test.foo]]" serial=98571548539252653063644607680771418559 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-08-26T12:13:18Z" valid-to="2026-11-24T12:14:18Z" container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 26 12:14:11 2026 GMT container-test-run-certificates> * expire date: Sep 25 12:14:11 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 366222 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [7524801.377420] server nginx[370]: nginx: the configuration file /nix/store/nfgk30pbmji62whlqlbylrn263ifbnzr-nginx.conf syntax is ok container-test-run-certificates> server # [7524801.377660] server nginx[370]: nginx: configuration file /nix/store/nfgk30pbmji62whlqlbylrn263ifbnzr-nginx.conf test is successful container-test-run-certificates> server # [7524801.710294] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [930 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [79 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 26 12:13:18 2026 GMT container-test-run-certificates> * expire date: Nov 24 12:14:18 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 49602 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 1820 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 2.06 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> 4a:28:30:90:27:c7:82:87:8e:c5:4a:3a:3b:9a:69:bf container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Aug 26 12:13:18 2026 GMT container-test-run-certificates> Not After : Nov 24 12:14:18 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:e1:ae:03:5b:d8:6e:ee:d1:3c:a4:3d:79:75:1a: container-test-run-certificates> 43:97:12:2e:4d:b5:97:de:80:7d:ba:cf:d9:b3:7c: container-test-run-certificates> 48:50:1c:6d:98:73:d6:42:17:c7:cd:21:73:01:60: container-test-run-certificates> 52:95:7c:a5:ff:18:0d:63:35:dc:12:39:d4:be:9c: container-test-run-certificates> 72:c6:c6:ce:6b container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> 39:09:A9:A3:95:AE:61:3E:64:00:DD:23:E7:8F:D2:BB:62:0E:A7:22 container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> 29:B1:CF:69:1C:C6:2A:FD:3C:AD:34:FD:FE:66:46:D8:C2:CA:81:06 container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:45:02:20:57:b0:b2:1d:55:6c:5a:cc:c1:4b:52:24:21:ff: container-test-run-certificates> 15:33:0a:ca:e1:9d:9d:0f:41:af:30:af:5c:97:00:af:3c:75: container-test-run-certificates> 02:21:00:fc:20:28:35:20:04:57:0f:a5:8c:1d:45:6d:f1:9d: container-test-run-certificates> dd:d0:9d:fe:c2:e5:29:30:ab:63:42:a0:0f:13:0f:1e:64 container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.02 seconds) container-test-run-certificates> (finished: run the VM test script, in 10.11 seconds) container-test-run-certificates> test script finished in 10.18s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 53) container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> kill NspawnMachine (pid 58) container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> Container server terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.29 seconds) post-build step Upload to niks3: ok time=2026-08-26T12:14:20.694Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-26T12:14:21.028Z level=INFO msg="Uploading 1 narinfos" time=2026-08-26T12:14:21.107Z level=INFO msg="Upload complete. (509ms)"