container-test-run-certificates
checks.aarch64-linux.certificates
· build #511
· raw
1Machine state will be reset. To keep it, pass --keep-machine-state2start all VLans3(finished: start all VLans, in 0.00 seconds)45Test will time out and terminate in 3600.0 seconds6run the VM test script7additionally exposed symbols:8 ca, client, server,9 vlan1,10 start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh11start all VMs12ca: systemd-nspawn running (pid 53)13server: systemd-nspawn running (pid 55)14ca: Waiting for journal at /build/vm-state-ca/var/log/journal...15client: systemd-nspawn running (pid 54)16server: Waiting for journal at /build/vm-state-server/var/log/journal...17client: Waiting for journal at /build/vm-state-client/var/log/journal...18(finished: start all VMs, in 0.00 seconds)19nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE20nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.21nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE22nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.23nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE24nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.25Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.26Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.27Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.28░ Spawning container server on /build/vm-state-server.29░ Spawning container ca on /build/vm-state-ca.30░ Spawning container client on /build/vm-state-client.31server # No journal boot entry found for the specified boot (+0).32ca # No journal boot entry found for the specified boot (+0).33client # No journal boot entry found for the specified boot (+0).34server # [6865739.928343] server systemd-journald[69]: Journal started35server # [6865739.928393] server systemd-journald[69]: Runtime Journal (/run/log/journal/3a82d7c889844eafa808a88cb169518c) is 8M, max 2.5G, 2.4G free.36server # [6865739.948962] server systemd[1]: Starting Flush Journal to Persistent Storage...37server # [6865739.950243] server systemd[1]: Starting Network Name Resolution...38server # [6865739.951122] server systemd[1]: Starting Create Static Device Nodes in /dev...39server # [6865739.959269] server systemd-journald[69]: Time spent on flushing to /var/log/journal/3a82d7c889844eafa808a88cb169518c is 1.252ms for 5 entries.40server # [6865739.959269] server systemd-journald[69]: System Journal (/var/log/journal/3a82d7c889844eafa808a88cb169518c) is 8M, max 4G, 3.9G free.41server # [6865739.966951] server systemd[1]: Finished Create Static Device Nodes in /dev.42server # [6865739.967236] server systemd[1]: Reached target Preparation for Local File Systems.43server # [6865739.967327] server systemd[1]: Reached target Local File Systems.44server # [6865739.968312] server systemd[1]: Listening on Boot Loader Control Service Socket.45server # [6865739.968360] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container46server # [6865739.969363] server systemd[1]: Starting Save Transient machine-id to Disk...47server # [6865739.969407] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys48server # [6865740.002838] server systemd[1]: Finished Flush Journal to Persistent Storage.49server # [6865740.004077] server systemd[1]: Starting Create System Files and Directories...50server # [6865740.021136] server systemd-tmpfiles[134]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted51server # [6865740.021191] server systemd[1]: Finished Save Transient machine-id to Disk.52server # [6865740.021318] server systemd-tmpfiles[134]: fchmod() of /var/log/journal failed: Operation not permitted53server # [6865740.021436] server systemd-tmpfiles[134]: fchmod() of /var/log/journal/3a82d7c889844eafa808a88cb169518c failed: Operation not permitted54server # [6865740.021616] server systemd-tmpfiles[134]: fchmod() of /run/log/journal failed: Operation not permitted55server # [6865740.023168] server systemd[1]: Finished Create System Files and Directories.56server # [6865740.024295] server systemd[1]: Starting Rebuild Journal Catalog...57server # [6865740.025036] server systemd[1]: Starting Record System Boot/Shutdown in UTMP...58server # [6865740.036409] server systemd[1]: Finished Record System Boot/Shutdown in UTMP.59server # [6865740.046188] server systemd[1]: Finished Rebuild Journal Catalog.60server # [6865740.047266] server systemd[1]: Starting Update is Completed...61server # [6865740.058025] server systemd[1]: Finished Update is Completed.62server # [6865740.076135] server systemd[1]: Finished Firewall.63server # [6865740.076802] server systemd[1]: Reached target Preparation for Network.64server # [6865740.077113] server systemd[1]: Listening on Network Management Resolve Hook Socket.65server # [6865740.078229] server systemd[1]: Starting Network Management...66server # [6865740.918751] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully.67ca # [6865739.931559] ca systemd-journald[78]: Journal started68ca # [6865739.931611] ca systemd-journald[78]: Runtime Journal (/run/log/journal/9b4d210a317740c9a60180d45bfe5f55) is 8M, max 2.5G, 2.4G free.69ca # [6865739.938754] ca systemd[1]: Finished Apply Kernel Variables.70ca # [6865739.949147] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully.71ca # [6865739.959976] ca systemd[1]: Starting Flush Journal to Persistent Storage...72ca # [6865739.960900] ca systemd[1]: Starting Network Name Resolution...73ca # [6865739.961577] ca systemd[1]: Starting Create Static Device Nodes in /dev...74ca # [6865739.971908] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/9b4d210a317740c9a60180d45bfe5f55 is 1.556ms for 7 entries.75ca # [6865739.971908] ca systemd-journald[78]: System Journal (/var/log/journal/9b4d210a317740c9a60180d45bfe5f55) is 8M, max 4G, 3.9G free.76ca # [6865739.980466] ca systemd[1]: Finished Create Static Device Nodes in /dev.77ca # [6865739.981233] ca systemd[1]: Reached target Preparation for Local File Systems.78ca # [6865739.981352] ca systemd[1]: Reached target Local File Systems.79ca # [6865739.982261] ca systemd[1]: Listening on Boot Loader Control Service Socket.80ca # [6865739.982313] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container81ca # [6865739.983272] ca systemd[1]: Starting Save Transient machine-id to Disk...82ca # [6865739.983310] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys83ca # [6865740.004516] ca systemd[1]: Finished Flush Journal to Persistent Storage.84ca # [6865740.005541] ca systemd[1]: Starting Create System Files and Directories...85ca # [6865740.019074] ca systemd[1]: Finished Save Transient machine-id to Disk.86ca # [6865740.023771] ca systemd-tmpfiles[142]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted87ca # [6865740.023973] ca systemd-tmpfiles[142]: fchmod() of /var/log/journal failed: Operation not permitted88ca # [6865740.024119] ca systemd-tmpfiles[142]: fchmod() of /var/log/journal/9b4d210a317740c9a60180d45bfe5f55 failed: Operation not permitted89ca # [6865740.024321] ca systemd-tmpfiles[142]: fchmod() of /run/log/journal failed: Operation not permitted90ca # [6865740.025774] ca systemd[1]: Finished Create System Files and Directories.91ca # [6865740.026868] ca systemd[1]: Starting Rebuild Journal Catalog...92ca # [6865740.027568] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP...93ca # [6865740.038789] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP.94ca # [6865740.045714] ca systemd[1]: Finished Rebuild Journal Catalog.95ca # [6865740.046837] ca systemd[1]: Starting Update is Completed...96ca # [6865740.058905] ca systemd[1]: Finished Update is Completed.97ca # [6865740.083062] ca systemd[1]: Finished Firewall.98ca # [6865740.083221] ca systemd[1]: Reached target Preparation for Network.99ca # [6865740.083448] ca systemd[1]: Listening on Network Management Resolve Hook Socket.100ca # [6865740.084766] ca systemd[1]: Starting Network Management...101ca # [6865740.919320] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully.102client # [6865739.927978] client systemd-journald[69]: Journal started103client # [6865739.928052] client systemd-journald[69]: Runtime Journal (/run/log/journal/a13411b16a0b46ac8bd3345b7abf90b3) is 8M, max 2.5G, 2.4G free.104client # [6865739.939071] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully.105client # [6865739.949293] client systemd[1]: Starting Flush Journal to Persistent Storage...106client # [6865739.950443] client systemd[1]: Starting Network Name Resolution...107client # [6865739.951169] client systemd[1]: Starting Create Static Device Nodes in /dev...108client # [6865739.959589] client systemd-journald[69]: Time spent on flushing to /var/log/journal/a13411b16a0b46ac8bd3345b7abf90b3 is 1.306ms for 6 entries.109client # [6865739.959589] client systemd-journald[69]: System Journal (/var/log/journal/a13411b16a0b46ac8bd3345b7abf90b3) is 8M, max 4G, 3.9G free.110client # [6865739.966944] client systemd[1]: Finished Create Static Device Nodes in /dev.111client # [6865739.967722] client systemd[1]: Reached target Preparation for Local File Systems.112client # [6865739.967828] client systemd[1]: Reached target Local File Systems.113client # [6865739.968714] client systemd[1]: Listening on Boot Loader Control Service Socket.114client # [6865739.968761] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container115client # [6865739.969727] client systemd[1]: Starting Save Transient machine-id to Disk...116client # [6865739.969768] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys117client # [6865740.003096] client systemd[1]: Finished Flush Journal to Persistent Storage.118client # [6865740.004305] client systemd[1]: Starting Create System Files and Directories...119client # [6865740.019907] client systemd[1]: Finished Save Transient machine-id to Disk.120client # [6865740.020703] client systemd-tmpfiles[137]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted121client # [6865740.020872] client systemd-tmpfiles[137]: fchmod() of /var/log/journal failed: Operation not permitted122client # [6865740.020983] client systemd-tmpfiles[137]: fchmod() of /var/log/journal/a13411b16a0b46ac8bd3345b7abf90b3 failed: Operation not permitted123client # [6865740.021154] client systemd-tmpfiles[137]: fchmod() of /run/log/journal failed: Operation not permitted124client # [6865740.022583] client systemd[1]: Finished Create System Files and Directories.125client # [6865740.023837] client systemd[1]: Starting Rebuild Journal Catalog...126client # [6865740.024766] client systemd[1]: Starting Record System Boot/Shutdown in UTMP...127client # [6865740.038249] client systemd[1]: Finished Record System Boot/Shutdown in UTMP.128client # [6865740.043604] client systemd[1]: Finished Rebuild Journal Catalog.129client # [6865740.044714] client systemd[1]: Starting Update is Completed...130client # [6865740.055132] client systemd[1]: Finished Update is Completed.131client # [6865740.066740] client systemd[1]: Finished Firewall.132client # [6865740.066897] client systemd[1]: Reached target Preparation for Network.133client # [6865740.067360] client systemd[1]: Listening on Network Management Resolve Hook Socket.134client # [6865740.068620] client systemd[1]: Starting Network Management...135client # [6865740.918815] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully.136ca # [6865741.006415] ca systemd-networkd[196]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted137ca # [6865741.006512] ca systemd-networkd[196]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted138ca # [6865741.019975] ca systemd-networkd[196]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.139ca # [6865741.020164] ca systemd-networkd[196]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.140ca # [6865741.020346] ca systemd-networkd[196]: lo: Link UP141ca # [6865741.020350] ca systemd-networkd[196]: lo: Gained carrier142ca # [6865741.020576] ca systemd-networkd[196]: eth1: Configuring with /etc/systemd/network/40-eth1.network.143ca # [6865741.020979] ca systemd[1]: Started Network Management.144ca # [6865741.021080] ca systemd-networkd[196]: eth1: Link UP145ca # [6865741.021353] ca systemd-networkd[196]: eth1: Gained carrier146ca # [6865741.022299] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd...147ca # [6865741.092587] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd.148server # [6865741.179343] server systemd-networkd[187]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted149server # [6865741.179445] server systemd-networkd[187]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted150server # [6865741.196516] server systemd-networkd[187]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.151server # [6865741.196686] server systemd-networkd[187]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.152server # [6865741.196851] server systemd-networkd[187]: lo: Link UP153server # [6865741.196855] server systemd-networkd[187]: lo: Gained carrier154server # [6865741.197030] server systemd-networkd[187]: eth1: Configuring with /etc/systemd/network/40-eth1.network.155server # [6865741.197447] server systemd[1]: Started Network Management.156server # [6865741.200824] server systemd-networkd[187]: eth1: Link UP157server # [6865741.201083] server systemd-networkd[187]: eth1: Gained carrier158server # [6865741.201506] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd...159server # [6865741.253997] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd.160client # [6865741.229805] client systemd-networkd[183]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted161client # [6865741.229905] client systemd-networkd[183]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted162client # [6865741.240141] client systemd-networkd[183]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.163client # [6865741.240309] client systemd-networkd[183]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.164client # [6865741.240481] client systemd-networkd[183]: lo: Link UP165client # [6865741.240486] client systemd-networkd[183]: lo: Gained carrier166client # [6865741.240689] client systemd-networkd[183]: eth1: Configuring with /etc/systemd/network/40-eth1.network.167client # [6865741.241056] client systemd[1]: Started Network Management.168client # [6865741.241181] client systemd-networkd[183]: eth1: Link UP169client # [6865741.241405] client systemd-networkd[183]: eth1: Gained carrier170client # [6865741.242379] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd...171client # [6865741.273588] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd.172ca # [6865741.557117] ca systemd-resolved[111]: Positive Trust Anchors:173ca # [6865741.557129] ca systemd-resolved[111]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d174ca # [6865741.557132] ca systemd-resolved[111]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16175ca # [6865741.557166] ca systemd-resolved[111]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test176ca # [6865741.580808] ca systemd-resolved[111]: Using system hostname 'ca'.177ca # [6865741.582604] ca systemd[1]: Started Network Name Resolution.178ca # [6865741.582702] ca systemd[1]: Reached target Network.179ca # [6865741.582785] ca systemd[1]: Reached target Network is Online.180ca # [6865741.582844] ca systemd[1]: Reached target System Initialization.181ca # [6865741.583141] ca systemd[1]: Started Renew ACME Certificate for ca.foo.182ca # [6865741.583197] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container183ca # [6865741.583234] ca systemd[1]: Started Daily Cleanup of Temporary Directories.184ca # [6865741.583253] ca systemd[1]: Reached target Timer Units.185ca # [6865741.583447] ca systemd[1]: Listening on D-Bus System Message Bus Socket.186ca # [6865741.583578] ca systemd[1]: Listening on Nix Daemon Socket.187ca # [6865741.583752] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.188ca # [6865741.583773] ca systemd[1]: Reached target Socket Units.189ca # [6865741.583814] ca systemd[1]: Reached target Basic System.190ca # [6865741.585316] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure...191ca # [6865741.586223] ca systemd[1]: Starting Import lastlog data into lastlog2 database...192ca # [6865741.586267] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem193ca # [6865741.587129] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)...194ca # [6865741.588100] ca systemd[1]: Starting step-ca service...195ca # [6865741.644478] ca systemd[1]: Starting D-Bus System Message Bus...196ca # [6865741.725357] ca systemd[1]: lastlog2-import.service: Failed to spawn executor: No such file or directory197ca # [6865741.725384] ca systemd[1]: lastlog2-import.service: Failed to spawn 'start-post' task: No such file or directory198ca # [6865741.725414] ca systemd[1]: lastlog2-import.service: Failed with result 'resources'.199ca # [6865741.725511] ca systemd[1]: Failed to start Import lastlog data into lastlog2 database.200ca # [6865741.828965] ca acme-setup-privileged[201]: + set -euo pipefail201ca # [6865741.828965] ca acme-setup-privileged[201]: + cd /var/lib/acme202ca # [6865741.828965] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts203client # [6865741.629991] client systemd-resolved[103]: Positive Trust Anchors:204client # [6865741.630002] client systemd-resolved[103]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d205client # [6865741.630006] client systemd-resolved[103]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16206client # [6865741.630042] client systemd-resolved[103]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test207client # [6865741.652434] client systemd-resolved[103]: Using system hostname 'client'.208client # [6865741.653830] client systemd[1]: Started Network Name Resolution.209client # [6865741.653915] client systemd[1]: Reached target Network.210client # [6865741.653982] client systemd[1]: Reached target System Initialization.211client # [6865741.654033] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container212client # [6865741.654070] client systemd[1]: Started Daily Cleanup of Temporary Directories.213client # [6865741.654089] client systemd[1]: Reached target Timer Units.214client # [6865741.654214] client systemd[1]: Listening on D-Bus System Message Bus Socket.215client # [6865741.654343] client systemd[1]: Listening on Nix Daemon Socket.216client # [6865741.654450] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.217client # [6865741.654473] client systemd[1]: Reached target Socket Units.218client # [6865741.654511] client systemd[1]: Reached target Basic System.219client # [6865741.655690] client systemd[1]: Starting Import lastlog data into lastlog2 database...220client # [6865741.656522] client systemd[1]: Starting Name Service Cache Daemon (nsncd)...221client # [6865741.657723] client systemd[1]: Starting D-Bus System Message Bus...222client # [6865741.674634] client systemd[1]: Finished Import lastlog data into lastlog2 database.223client # [6865741.861472] client nsncd[189]: Aug 27 10:32:47.914 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"224client # [6865741.861534] client systemd[1]: Started Name Service Cache Daemon (nsncd).225client # [6865741.861597] client systemd[1]: Reached target Host and Network Name Lookups.226client # [6865741.861655] client systemd[1]: Reached target User and Group Name Lookups.227client # [6865741.862855] client systemd[1]: Starting User Login Management...228client # [6865741.863645] client systemd[1]: Starting Permit User Sessions...229client # [6865741.873835] client systemd[1]: Finished Permit User Sessions.230client # [6865741.874981] client systemd[1]: Started Console Getty.231client # [6865741.875027] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0232client # [6865741.875046] client systemd[1]: Reached target Login Prompts.233ca: must succeed: systemctl restart acme-order-renew-ca.foo.service 234server # [6865741.792363] server systemd-resolved[99]: Positive Trust Anchors:235server # [6865741.792376] server systemd-resolved[99]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d236server # [6865741.792379] server systemd-resolved[99]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16237server # [6865741.792412] server systemd-resolved[99]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test238server # [6865741.815931] server systemd-resolved[99]: Using system hostname 'server'.239server # [6865741.817453] server systemd[1]: Started Network Name Resolution.240server # [6865741.817542] server systemd[1]: Reached target Network.241server # [6865741.817605] server systemd[1]: Reached target Network is Online.242server # [6865741.817645] server systemd[1]: Reached target System Initialization.243server # [6865741.817853] server systemd[1]: Started Renew ACME Certificate for test.foo.244server # [6865741.817892] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container245server # [6865741.817910] server systemd[1]: Started Daily Cleanup of Temporary Directories.246server # [6865741.817927] server systemd[1]: Reached target Timer Units.247server # [6865741.818052] server systemd[1]: Listening on D-Bus System Message Bus Socket.248server # [6865741.818155] server systemd[1]: Listening on Nix Daemon Socket.249server # [6865741.818261] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.250server # [6865741.818287] server systemd[1]: Reached target Socket Units.251server # [6865741.818320] server systemd[1]: Reached target Basic System.252server # [6865741.819588] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure...253server # [6865741.820464] server systemd[1]: Starting Import lastlog data into lastlog2 database...254server # [6865741.820501] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem255server # [6865741.821298] server systemd[1]: Starting Name Service Cache Daemon (nsncd)...256server # [6865741.822492] server systemd[1]: Starting D-Bus System Message Bus...257server # [6865741.839847] server systemd[1]: Finished Import lastlog data into lastlog2 database.258server # [6865741.938335] server acme-setup-privileged[192]: + set -euo pipefail259server # [6865741.938335] server acme-setup-privileged[192]: + cd /var/lib/acme260server # [6865741.938730] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts261server # [6865741.940075] server acme-setup-privileged[192]: + chown -R acme .lego/accounts262server # [6865741.941733] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo263server # [6865741.941760] server acme-setup-privileged[192]: + '[' -d test.foo ']'264server # [6865741.941760] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo265server # [6865741.941760] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']'266server # [6865741.972949] server nsncd[194]: Aug 27 10:32:48.026 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"267server # [6865741.973083] server systemd[1]: Started Name Service Cache Daemon (nsncd).268server # [6865741.973152] server systemd[1]: Reached target Host and Network Name Lookups.269server # [6865741.973219] server systemd[1]: Reached target User and Group Name Lookups.270server # [6865741.992575] server systemd[1]: Starting User Login Management...271server # [6865741.993756] server systemd[1]: Starting Permit User Sessions...272server # [6865742.004998] server systemd[1]: Finished Permit User Sessions.273server # [6865742.006070] server systemd[1]: Started Console Getty.274server # [6865742.006110] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0275server # [6865742.006130] server systemd[1]: Reached target Login Prompts.276server # [6865742.103774] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'...277ca # [6865741.830454] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts278ca # [6865741.831943] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo279ca # [6865741.831977] ca acme-setup-privileged[201]: + '[' -d ca.foo ']'280ca # [6865741.831977] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo281ca # [6865741.831977] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']'282ca # [6865741.871217] ca nsncd[203]: Aug 27 10:32:47.923 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"283ca # [6865741.870757] ca systemd[1]: Started Name Service Cache Daemon (nsncd).284ca # [6865741.870836] ca systemd[1]: Reached target Host and Network Name Lookups.285ca # [6865741.870898] ca systemd[1]: Reached target User and Group Name Lookups.286ca # [6865741.872645] ca systemd[1]: Starting User Login Management...287ca # [6865741.873458] ca systemd[1]: Starting Permit User Sessions...288ca # [6865741.883476] ca systemd[1]: Finished Permit User Sessions.289ca # [6865741.885453] ca systemd[1]: Started Console Getty.290ca # [6865741.885499] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0291ca # [6865741.885517] ca systemd[1]: Reached target Login Prompts.292ca # [6865742.029408] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'...293ca # [6865742.030078] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync'294ca # [6865742.030078] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/gj5k0v2rcdsvmwzrdidpx1a8s0szjk65-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"295ca # [6865742.030514] ca systemd[1]: Started D-Bus System Message Bus.296ca # [6865742.040139] ca dbus-broker-launch[205]: Ready297client # [6865741.999651] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'...298client # [6865742.000455] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync'299client # [6865742.000455] client dbus-broker-launch[190]: Invalid user-name in /nix/store/zrbrcrcf4ksfm9isn90jq44dzyd6g8f3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"300client # [6865742.000916] client systemd[1]: Started D-Bus System Message Bus.301client # [6865742.007822] client dbus-broker-launch[190]: Ready302server # [6865742.104746] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync'303server # [6865742.104746] server dbus-broker-launch[195]: Invalid user-name in /nix/store/qlm5ds27nygd7kx149cwgpvarjrvks9s-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"304server # [6865742.105159] server systemd[1]: Started D-Bus System Message Bus.305server # [6865742.112081] server dbus-broker-launch[195]: Ready306client # [6865742.304150] client systemd-networkd[183]: eth1: Gained IPv6LL307client # [6865742.543605] client systemd-logind[205]: New seat seat0.308client # [6865742.543760] client systemd[1]: Started User Login Management.309ca # [6865742.555730] ca systemd-logind[233]: New seat seat0.310ca # [6865742.556387] ca systemd[1]: Started User Login Management.311ca # [6865742.589569] ca systemd[1]: Starting linger-users.service...312ca # [6865742.595224] ca acme-setup-start[217]: + set -euo pipefail313ca # [6865742.595482] ca acme-setup-start[217]: + test -e ca/key.pem314ca # [6865742.595482] ca acme-setup-start[217]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local315ca # [6865742.603148] ca systemd[1]: linger-users.service: Deactivated successfully.316ca # [6865742.603328] ca systemd[1]: Finished linger-users.service.317ca # [6865742.614892] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure.318ca # [6865742.616374] ca systemd[1]: Starting Ensure certificate for ca.foo...319ca # [6865742.756171] ca systemd-networkd[196]: eth1: Gained IPv6LL320client # [6865742.589823] client systemd[1]: Starting linger-users.service...321client # [6865742.603512] client systemd[1]: linger-users.service: Deactivated successfully.322client # [6865742.603593] client systemd[1]: Finished linger-users.service.323client # [6865742.604022] client systemd[1]: Reached target Multi-User System.324client # [6865742.620131] client systemd[1]: Startup finished in 3.101s.325server # [6865742.624895] server systemd-logind[219]: New seat seat0.326server # [6865742.625099] server systemd[1]: Started User Login Management.327server # [6865742.626482] server systemd[1]: Starting linger-users.service...328server # [6865742.637812] server systemd[1]: linger-users.service: Deactivated successfully.329server # [6865742.638066] server systemd[1]: Finished linger-users.service.330server # [6865742.693995] server acme-setup-start[208]: + set -euo pipefail331server # [6865742.694250] server acme-setup-start[208]: + test -e ca/key.pem332server # [6865742.694250] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local333server # [6865742.731062] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure.334server # [6865742.732649] server systemd[1]: Starting Ensure certificate for test.foo...335server # [6865742.756230] server systemd-networkd[187]: eth1: Gained IPv6LL336ca # [6865742.956494] ca step-ca[204]: badger 2026/08/27 10:32:49 INFO: All 0 tables opened in 0s337ca # [6865742.966037] ca step-ca[204]: 2026/08/27 10:32:49 Building new tls configuration using step-ca x509 Signer Interface338ca # [6865742.973202] ca step-ca[204]: 2026/08/27 10:32:49 Starting Smallstep CA/0.30.2 (linux/arm64)339ca # [6865742.973202] ca step-ca[204]: 2026/08/27 10:32:49 Documentation: https://u.step.sm/docs/ca340ca # [6865742.973202] ca step-ca[204]: 2026/08/27 10:32:49 Community Discord: https://u.step.sm/discord341ca # [6865742.973202] ca step-ca[204]: 2026/08/27 10:32:49 Config file: /etc/smallstep/ca.json342ca # [6865742.973202] ca step-ca[204]: 2026/08/27 10:32:49 The primary server URL is https://ca.foo:1443343ca # [6865742.973202] ca step-ca[204]: 2026/08/27 10:32:49 Root certificates are available at https://ca.foo:1443/roots.pem344ca # [6865742.973382] ca step-ca[204]: 2026/08/27 10:32:49 X.509 Root Fingerprint: a97ce9440c81c1aac50ade6eee6049e3bf7db6ae1e5cfda05f46dcd1f4c24fa4345ca # [6865742.973687] ca systemd[1]: Started step-ca service.346ca # [6865742.974058] ca step-ca[204]: 2026/08/27 10:32:49 Serving HTTPS on 0.0.0.0:1443 ...347ca # [6865743.629758] ca acme-ca.foo-start[254]: Waiting to acquire lock in /run/acme/348ca # [6865743.632777] ca acme-ca.foo-start[254]: + '[' -e out/acme-success ']'349ca # [6865743.632820] ca acme-ca.foo-start[254]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses=350ca # [6865743.644324] ca acme-ca.foo-start[292]: + cd ca.foo351ca # [6865743.644541] ca acme-ca.foo-start[292]: + cp -vp cert.pem ../out/cert.pem352ca # [6865743.645677] ca acme-ca.foo-start[293]: 'cert.pem' -> '../out/cert.pem'353ca # [6865743.645897] ca acme-ca.foo-start[292]: + cp -vp key.pem ../out/key.pem354ca # [6865743.647314] ca acme-ca.foo-start[292]: 'key.pem' -> '../out/key.pem'355ca # [6865743.647597] ca acme-ca.foo-start[254]: + cat out/cert.pem ca/cert.pem356ca # [6865743.649133] ca acme-ca.foo-start[254]: + cp ca/cert.pem out/chain.pem357ca # [6865743.650629] ca acme-ca.foo-start[254]: + cat out/key.pem out/fullchain.pem358ca # [6865743.652103] ca acme-ca.foo-start[254]: + for fixpath in out certificates359ca # [6865743.652103] ca acme-ca.foo-start[254]: + '[' -d out ']'360ca # [6865743.652146] ca acme-ca.foo-start[254]: + chmod -R u=rwX,g=rX,o= out361ca # [6865743.654344] ca acme-ca.foo-start[254]: + chown -R acme:nginx out362ca # [6865743.657214] ca acme-ca.foo-start[254]: + for fixpath in out certificates363ca # [6865743.657239] ca acme-ca.foo-start[254]: + '[' -d certificates ']'364ca # [6865743.662718] ca systemd[1]: Finished Ensure certificate for ca.foo.365ca # [6865743.664113] ca systemd[1]: Starting Nginx Web Server...366server # [6865743.934015] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/367server # [6865743.936443] server acme-test.foo-start[245]: + '[' -e out/acme-success ']'368server # [6865743.936490] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=369server # [6865743.947792] server acme-test.foo-start[255]: + cd test.foo370server # [6865743.948191] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem371server # [6865743.949241] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem'372server # [6865743.949448] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem373server # [6865743.950555] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem'374server # [6865743.950769] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem375server # [6865743.952263] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem376server # [6865743.953653] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem377server # [6865743.955119] server acme-test.foo-start[245]: + for fixpath in out certificates378server # [6865743.955145] server acme-test.foo-start[245]: + '[' -d out ']'379server # [6865743.955145] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out380server # [6865743.956615] server acme-test.foo-start[245]: + chown -R acme:nginx out381server # [6865743.959006] server acme-test.foo-start[245]: + for fixpath in out certificates382server # [6865743.959037] server acme-test.foo-start[245]: + '[' -d certificates ']'383server # [6865744.000364] server systemd[1]: Finished Ensure certificate for test.foo.384server # [6865744.001769] server systemd[1]: Starting Nginx Web Server...385ca # [6865745.354737] ca nginx-pre-start[304]: nginx: the configuration file /nix/store/k6vn04kvvc5wrilzgx0i5sa6zfs4lfi9-nginx.conf syntax is ok386ca # [6865745.355295] ca nginx-pre-start[304]: nginx: configuration file /nix/store/k6vn04kvvc5wrilzgx0i5sa6zfs4lfi9-nginx.conf test is successful387ca # [6865745.360762] ca systemd[1]: Started Nginx Web Server.388ca # [6865745.361125] ca systemd[1]: Reached target Multi-User System.389ca # [6865745.362332] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...390server # [6865745.438118] server nginx-pre-start[267]: nginx: the configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf syntax is ok391server # [6865745.438482] server nginx-pre-start[267]: nginx: configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf test is successful392server # [6865745.442657] server systemd[1]: Started Nginx Web Server.393server # [6865745.443018] server systemd[1]: Reached target Multi-User System.394server # [6865745.444173] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...395ca # [6865746.660056] ca acme-order-renew-ca.foo-start[307]: Waiting to acquire lock in /run/acme/396ca # [6865746.662472] ca acme-order-renew-ca.foo-start[307]: + set -euo pipefail397ca # [6865746.662548] ca acme-order-renew-ca.foo-start[307]: + echo 88dc4fc401a6091a1bd9398ca # [6865746.662660] ca acme-order-renew-ca.foo-start[307]: + cmp -s domainhash.txt certificates/domainhash.txt399ca # [6865746.663800] ca acme-order-renew-ca.foo-start[307]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run400ca # [6865746.694135] ca acme-order-renew-ca.foo-start[318]: 2026/08/27 10:32:52 No key found for account none@none.tld. Generating a P256 key.401ca # [6865746.694458] ca acme-order-renew-ca.foo-start[318]: 2026/08/27 10:32:52 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key402ca # [6865746.719731] ca step-ca[204]: time="2026-08-27T10:32:52Z" level=info duration="169.722µs" duration-ns=169722 fields.time="2026-08-27T10:32:52Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=31cef6ca-31fd-44b2-a01a-dc305a838f0d response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=403ca # [6865746.720130] ca acme-order-renew-ca.foo-start[318]: 2026/08/27 10:32:52 [INFO] acme: Registering account for none@none.tld404ca # [6865746.837755] ca step-ca[204]: time="2026-08-27T10:32:52Z" level=info duration=117.416272ms duration-ns=117416272 fields.time="2026-08-27T10:32:52Z" method=HEAD name=ca nonce=YU12VWh3TFRYbXd4S3pBOUNaeUhPMVlmQlFyR2RlQk0 path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=2d9ff2ef-03f2-47a4-bbe4-5a7834b46bdc size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=405ca # [6865746.842815] ca step-ca[204]: time="2026-08-27T10:32:52Z" level=info duration=4.299061ms duration-ns=4299061 fields.time="2026-08-27T10:32:52Z" method=POST name=ca nonce=QTJyUHNZbWVOVTBrQldwa2wwS1UwdThqQTR6WXgyWTk path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=49331c9b-47f5-4fb4-a834-b944d7ecbb68 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/4z4Tr4TeIgYnnJQVdWkRhj5td5mffjEF/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=406ca # [6865746.843168] ca acme-order-renew-ca.foo-start[318]: !!!! HEADS UP !!!!407ca # [6865746.843168] ca acme-order-renew-ca.foo-start[318]: Your account credentials have been saved in your408ca # [6865746.843168] ca acme-order-renew-ca.foo-start[318]: configuration directory at "accounts".409ca # [6865746.843168] ca acme-order-renew-ca.foo-start[318]: You should make a secure backup of this folder now. This410ca # [6865746.843168] ca acme-order-renew-ca.foo-start[318]: configuration directory will also contain private keys411ca # [6865746.843168] ca acme-order-renew-ca.foo-start[318]: generated by lego and certificates obtained from the ACME412ca # [6865746.843168] ca acme-order-renew-ca.foo-start[318]: server. Making regular backups of this folder is ideal.413ca # [6865746.843302] ca acme-order-renew-ca.foo-start[318]: 2026/08/27 10:32:52 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate414ca # [6865746.846504] ca step-ca[204]: time="2026-08-27T10:32:52Z" level=info duration=2.82772ms duration-ns=2827720 fields.time="2026-08-27T10:32:52Z" method=POST name=ca nonce=NklSUDBqNWo2WlFVMUxlV2N0VW82MXFaOVFDN2hoQlo path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=908cc24e-3d52-47d1-96b2-76e625bd93aa response="{\"id\":\"bGHbcgvQCXzdaratx027u8o2LcNsjfyG\",\"status\":\"pending\",\"expires\":\"2026-08-28T10:32:52Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-27T10:31:52Z\",\"notAfter\":\"2026-11-25T10:32:52Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/wZ0DMhrOWMpSGopjfjB5BErS7mIOD0L1\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/bGHbcgvQCXzdaratx027u8o2LcNsjfyG/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=415ca # [6865746.908177] ca step-ca[204]: time="2026-08-27T10:32:52Z" level=info duration=4.813188ms duration-ns=4813188 fields.time="2026-08-27T10:32:52Z" method=POST name=ca nonce=WFB6emR6aVIwRjZ1bGp6elE4ZzFPZEVTODdnQm11YWE path=/acme/acme/authz/wZ0DMhrOWMpSGopjfjB5BErS7mIOD0L1 protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=ff870e3a-c496-4260-959f-360b1f557739 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"RwonZFaa5AE0hC6sdhzdn7IZJSjkw90A\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/wZ0DMhrOWMpSGopjfjB5BErS7mIOD0L1/kPcCi4SG9U3FRkcevo1O4R5Me4cuJimq\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"RwonZFaa5AE0hC6sdhzdn7IZJSjkw90A\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/wZ0DMhrOWMpSGopjfjB5BErS7mIOD0L1/QkhP5mzjVZEqWDuQzN66oLHlFSfrWunG\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"RwonZFaa5AE0hC6sdhzdn7IZJSjkw90A\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/wZ0DMhrOWMpSGopjfjB5BErS7mIOD0L1/Jt6wP8cdhFcWTqfhUU8ZI4Gagvaankoh\"}],\"wildcard\":false,\"expires\":\"2026-08-28T10:32:52Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=416ca # [6865746.908472] ca acme-order-renew-ca.foo-start[318]: 2026/08/27 10:32:52 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/wZ0DMhrOWMpSGopjfjB5BErS7mIOD0L1417ca # [6865746.908472] ca acme-order-renew-ca.foo-start[318]: 2026/08/27 10:32:52 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01418ca # [6865746.908472] ca acme-order-renew-ca.foo-start[318]: 2026/08/27 10:32:52 [INFO] [ca.foo] acme: use http-01 solver419ca # [6865746.908547] ca acme-order-renew-ca.foo-start[318]: 2026/08/27 10:32:52 [INFO] [ca.foo] acme: Trying to solve HTTP-01420ca # [6865746.913456] ca step-ca[204]: time="2026-08-27T10:32:52Z" level=info duration=4.455463ms duration-ns=4455463 fields.time="2026-08-27T10:32:52Z" method=POST name=ca nonce=TVdoV0g4d3E1QnNEdHlSaGpTdmVtZ2JXZDFQZGF0ZkE path=/acme/acme/challenge/wZ0DMhrOWMpSGopjfjB5BErS7mIOD0L1/QkhP5mzjVZEqWDuQzN66oLHlFSfrWunG protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=5204cc07-2981-4533-983d-afb59c2d6c08 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"RwonZFaa5AE0hC6sdhzdn7IZJSjkw90A\",\"validated\":\"2026-08-27T10:32:52Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/wZ0DMhrOWMpSGopjfjB5BErS7mIOD0L1/QkhP5mzjVZEqWDuQzN66oLHlFSfrWunG\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=421ca # [6865746.913708] ca acme-order-renew-ca.foo-start[318]: 2026/08/27 10:32:52 [INFO] [ca.foo] The server validated our request422ca # [6865746.913784] ca acme-order-renew-ca.foo-start[318]: 2026/08/27 10:32:52 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates423server # [6865746.689484] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/424server # [6865746.691915] server acme-order-renew-test.foo-start[270]: + set -euo pipefail425server # [6865746.691991] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108426server # [6865746.692123] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt427server # [6865746.693223] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run428server # [6865746.707861] server acme-order-renew-test.foo-start[282]: 2026/08/27 10:32:52 No key found for account none@none.tld. Generating a P256 key.429server # [6865746.708185] server acme-order-renew-test.foo-start[282]: 2026/08/27 10:32:52 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key430server # [6865746.736178] server acme-order-renew-test.foo-start[282]: 2026/08/27 10:32:52 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority431server # [6865746.736632] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.432server # [6865746.736632] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.433server # [6865746.736632] server acme-order-renew-test.foo-start[270]: + exit 10434server # [6865746.739802] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a435server # [6865746.739896] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'.436server # [6865746.740209] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo.437server # [6865746.740488] server systemd[1]: Startup finished in 7.250s.438ca # [6865746.919005] ca step-ca[204]: time="2026-08-27T10:32:52Z" level=info duration=4.328262ms duration-ns=4328262 fields.time="2026-08-27T10:32:52Z" method=POST name=ca nonce=dk9WZEtiWVRCbnhOdVJHQVpTQ3J0Tmc1eVhqcWRQUk8 path=/acme/acme/order/bGHbcgvQCXzdaratx027u8o2LcNsjfyG/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=d9bccd74-e7f6-44f8-afa9-dbc93e274b4e response="{\"id\":\"bGHbcgvQCXzdaratx027u8o2LcNsjfyG\",\"status\":\"valid\",\"expires\":\"2026-08-28T10:32:52Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-27T10:31:52Z\",\"notAfter\":\"2026-11-25T10:32:52Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/wZ0DMhrOWMpSGopjfjB5BErS7mIOD0L1\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/bGHbcgvQCXzdaratx027u8o2LcNsjfyG/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/W4dNYqPyYpisluyp2oJehWE8G5KorjlT\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=439ca # [6865746.920491] ca step-ca[204]: time="2026-08-27T10:32:52Z" level=info certificate="MIIB0jCCAXmgAwIBAgIQQgnIfrUyZv6PQs3eR2bT3TAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MjcxMDMxNTJaFw0yNjExMjUxMDMyNTJaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABFgwuRBqTR+0QhruZiySjPnHwd5yboJ5E4SmfIgMNGlFEHHtndD7iJSgrbyzgA0PZ6xS9NF+DEI5xS9KjBVIgi6jgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQU5AuRkk3lOSg2UWLYZKdJXC0ap8owHwYDVR0jBBgwFoAUdxIN6TH+n631IsDUCbskK/v24VowEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNHADBEAiAZ2RCfXvGB5JmxQ1jlsVFA8MAmO5dtBDrSs6Elg7MfDQIgKQN3nV0Maptep/Y0+LjEAkk9rJL++azIPiwR1kMUzP4=" duration="902.773µs" duration-ns=902773 fields.time="2026-08-27T10:32:52Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=OThFR0gwenBDMG1wTzVGeHpJNGFiUTVvT2hEUXRtejA path=/acme/acme/certificate/W4dNYqPyYpisluyp2oJehWE8G5KorjlT protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=2863ca75-c5fe-4fc7-9461-74c5b11510b9 sans="map[dns:[ca.foo]]" serial=87779844914278187637520842656670208989 size=1340 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-27T10:31:52Z" valid-to="2026-11-25T10:32:52Z"440ca # [6865746.920713] ca acme-order-renew-ca.foo-start[318]: 2026/08/27 10:32:52 [INFO] [ca.foo] Server responded with a certificate.441ca # [6865746.928212] ca acme-order-renew-ca.foo-start[307]: + mv domainhash.txt certificates/442ca # [6865746.929772] ca acme-order-renew-ca.foo-start[307]: + touch out/acme-success443ca # [6865746.931106] ca acme-order-renew-ca.foo-start[307]: + cmp -s certificates/ca.foo.crt out/fullchain.pem444ca # [6865746.932154] ca acme-order-renew-ca.foo-start[307]: + touch out/renewed445ca # [6865746.933429] ca acme-order-renew-ca.foo-start[307]: + echo Installing new certificate446ca # [6865746.933429] ca acme-order-renew-ca.foo-start[307]: Installing new certificate447ca # [6865746.933469] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.crt out/fullchain.pem448ca # [6865746.934708] ca acme-order-renew-ca.foo-start[349]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem'449ca # [6865746.934903] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.key out/key.pem450ca # [6865746.936271] ca acme-order-renew-ca.foo-start[350]: 'certificates/ca.foo.key' -> 'out/key.pem'451ca # [6865746.936478] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem452ca # [6865746.937940] ca acme-order-renew-ca.foo-start[351]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem'453ca # [6865746.938158] ca acme-order-renew-ca.foo-start[307]: + ln -sf fullchain.pem out/cert.pem454ca # [6865746.939646] ca acme-order-renew-ca.foo-start[307]: + cat out/key.pem out/fullchain.pem455ca # [6865746.941268] ca acme-order-renew-ca.foo-start[307]: + for fixpath in out certificates456ca # [6865746.941268] ca acme-order-renew-ca.foo-start[307]: + '[' -d out ']'457ca # [6865746.941320] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=rX,o= out458ca # [6865746.942739] ca acme-order-renew-ca.foo-start[307]: + chown -R acme:nginx out459ca # [6865746.944962] ca acme-order-renew-ca.foo-start[307]: + for fixpath in out certificates460ca # [6865746.944962] ca acme-order-renew-ca.foo-start[307]: + '[' -d certificates ']'461ca # [6865746.945040] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=rX,o= certificates462ca # [6865746.946346] ca acme-order-renew-ca.foo-start[307]: + chown -R acme:nginx certificates463ca # [6865746.948459] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=,o= accounts/.464ca # [6865747.071795] ca systemd[1]: Reloading Nginx Web Server...465ca # [6865747.076172] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.466ca # [6865747.076366] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.467ca # [6865747.641767] ca nginx[367]: nginx: the configuration file /nix/store/k6vn04kvvc5wrilzgx0i5sa6zfs4lfi9-nginx.conf syntax is ok468ca # [6865747.642302] ca nginx[367]: nginx: configuration file /nix/store/k6vn04kvvc5wrilzgx0i5sa6zfs4lfi9-nginx.conf test is successful469ca # [6865749.002490] ca systemd[1]: Reloaded Nginx Web Server.470ca # [6865749.002850] ca systemd[1]: Startup finished in 9.469s.471ca # [6865749.126019] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...472ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 8.36 seconds)473ca # [6865750.106064] ca acme-order-renew-ca.foo-start[382]: Waiting to acquire lock in /run/acme/474ca # [6865750.108602] ca acme-order-renew-ca.foo-start[382]: + set -euo pipefail475ca # [6865750.108681] ca acme-order-renew-ca.foo-start[382]: + echo 88dc4fc401a6091a1bd9476ca # [6865750.108798] ca acme-order-renew-ca.foo-start[382]: + cmp -s domainhash.txt certificates/domainhash.txt477ca # [6865750.109818] ca acme-order-renew-ca.foo-start[382]: + '[' -e certificates/ca.foo.key ']'478ca # [6865750.109840] ca acme-order-renew-ca.foo-start[382]: + '[' -e certificates/ca.foo.crt ']'479ca # [6865750.110745] ca acme-order-renew-ca.foo-start[390]: ++ find accounts -name none@none.tld.key480ca # [6865750.113084] ca acme-order-renew-ca.foo-start[382]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']'481ca # [6865750.113138] ca acme-order-renew-ca.foo-start[382]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic482ca # [6865750.153854] ca step-ca[204]: time="2026-08-27T10:32:56Z" level=info duration="48.44µs" duration-ns=48440 fields.time="2026-08-27T10:32:56Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=16420740-05ec-4111-90e7-057e6effe25f response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=483ca # [6865750.154217] ca acme-order-renew-ca.foo-start[391]: 2026/08/27 10:32:56 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint484ca # [6865750.154217] ca acme-order-renew-ca.foo-start[391]: 2026/08/27 10:32:56 [INFO] [ca.foo] The certificate expires at 2026-11-25T10:32:52Z, the renewal can be performed in 1439h59m35.792630615s: no renewal.485ca # [6865750.154692] ca acme-order-renew-ca.foo-start[382]: + mv domainhash.txt certificates/486ca # [6865750.156345] ca acme-order-renew-ca.foo-start[382]: + touch out/acme-success487ca # [6865750.157730] ca acme-order-renew-ca.foo-start[382]: + cmp -s certificates/ca.foo.crt out/fullchain.pem488ca # [6865750.158771] ca acme-order-renew-ca.foo-start[382]: + for fixpath in out certificates489ca # [6865750.159039] ca acme-order-renew-ca.foo-start[382]: + '[' -d out ']'490ca # [6865750.159039] ca acme-order-renew-ca.foo-start[382]: + chmod -R u=rwX,g=rX,o= out491ca # [6865750.161733] ca acme-order-renew-ca.foo-start[382]: + chown -R acme:nginx out492ca # [6865750.164315] ca acme-order-renew-ca.foo-start[382]: + for fixpath in out certificates493ca # [6865750.164346] ca acme-order-renew-ca.foo-start[382]: + '[' -d certificates ']'494ca # [6865750.164346] ca acme-order-renew-ca.foo-start[382]: + chmod -R u=rwX,g=rX,o= certificates495ca # [6865750.165706] ca acme-order-renew-ca.foo-start[382]: + chown -R acme:nginx certificates496ca # [6865750.168334] ca acme-order-renew-ca.foo-start[382]: + chmod -R u=rwX,g=,o= accounts/.497ca # [6865750.325591] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.498ca # [6865750.325919] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.499server: must succeed: systemctl restart acme-test.foo.service500server # [6865753.349360] server systemd[1]: acme-test.foo.service: Deactivated successfully.501server # [6865753.349529] server systemd[1]: Stopped Ensure certificate for test.foo.502server # [6865753.350558] server systemd[1]: Stopping Ensure certificate for test.foo...503server # [6865753.353477] server systemd[1]: Starting Ensure certificate for test.foo...504server: (finished: must succeed: systemctl restart acme-test.foo.service, in 1.02 seconds)505client: waiting for success: curl -v https://test.foo506* Host test.foo:443 was resolved.507* IPv6: 2001:db8:1::3508* IPv4: 192.168.1.3509* Trying [2001:db8:1::3]:443...510* ALPN: curl offers h2,http/1.1511} [5 bytes data]512* TLSv1.3 (OUT), TLS handshake, Client hello (1):513} [1552 bytes data]514* SSL Trust Anchors:515* OpenSSL default paths (fallback)516{ [5 bytes data]517* TLSv1.3 (IN), TLS handshake, Server hello (2):518{ [1210 bytes data]519* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):520{ [1 bytes data]521* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):522{ [19 bytes data]523* TLSv1.3 (IN), TLS handshake, Certificate (11):524{ [1009 bytes data]525* TLSv1.3 (IN), TLS handshake, CERT verify (15):526{ [112 bytes data]527* TLSv1.3 (IN), TLS handshake, Finished (20):528{ [52 bytes data]529* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):530} [1 bytes data]531* TLSv1.3 (OUT), TLS handshake, Finished (20):532} [52 bytes data]533* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey534* ALPN: server accepted h2535* Server certificate:536* subject: CN=test.foo537* start date: Aug 27 10:32:49 2026 GMT538* expire date: Sep 26 10:32:49 2028 GMT539* issuer: CN=minica root ca 73a0fa540* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384541* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384542* subjectAltName: "test.foo" matches cert's "test.foo"543* OpenSSL verify result: 13544* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)545* closing connection #0546curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)547More details here: https://curl.se/docs/sslcerts.html548549curl failed to verify the legitimacy of the server and therefore could not550establish a secure connection to it. To learn more about this situation and551how to fix it, please visit the webpage mentioned above.552server # [6865754.327047] server acme-test.foo-start[315]: Waiting to acquire lock in /run/acme/553server # [6865754.329676] server acme-test.foo-start[315]: + '[' -e out/acme-success ']'554server # [6865754.329722] server acme-test.foo-start[315]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=555server # [6865754.340481] server acme-test.foo-start[325]: + cd test.foo556server # [6865754.340839] server acme-test.foo-start[325]: + cp -vp cert.pem ../out/cert.pem557server # [6865754.342010] server acme-test.foo-start[326]: 'cert.pem' -> '../out/cert.pem'558server # [6865754.342278] server acme-test.foo-start[325]: + cp -vp key.pem ../out/key.pem559server # [6865754.343508] server acme-test.foo-start[325]: 'key.pem' -> '../out/key.pem'560server # [6865754.343794] server acme-test.foo-start[315]: + cat out/cert.pem ca/cert.pem561server # [6865754.345470] server acme-test.foo-start[315]: + cp ca/cert.pem out/chain.pem562server # [6865754.347022] server acme-test.foo-start[315]: + cat out/key.pem out/fullchain.pem563server # [6865754.348787] server acme-test.foo-start[315]: + for fixpath in out certificates564server # [6865754.348808] server acme-test.foo-start[315]: + '[' -d out ']'565server # [6865754.348824] server acme-test.foo-start[315]: + chmod -R u=rwX,g=rX,o= out566server # [6865754.350426] server acme-test.foo-start[315]: + chown -R acme:nginx out567server # [6865754.354385] server acme-test.foo-start[315]: + for fixpath in out certificates568server # [6865754.354424] server acme-test.foo-start[315]: + '[' -d certificates ']'569server # [6865754.358059] server systemd[1]: Finished Ensure certificate for test.foo.570server # [6865754.361107] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...571* Host test.foo:443 was resolved.572* IPv6: 2001:db8:1::3573* IPv4: 192.168.1.3574* Trying [2001:db8:1::3]:443...575* ALPN: curl offers h2,http/1.1576} [5 bytes data]577* TLSv1.3 (OUT), TLS handshake, Client hello (1):578} [1552 bytes data]579* SSL Trust Anchors:580* OpenSSL default paths (fallback)581{ [5 bytes data]582* TLSv1.3 (IN), TLS handshake, Server hello (2):583{ [1210 bytes data]584* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):585{ [1 bytes data]586* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):587{ [19 bytes data]588* TLSv1.3 (IN), TLS handshake, Certificate (11):589{ [1009 bytes data]590* TLSv1.3 (IN), TLS handshake, CERT verify (15):591{ [111 bytes data]592* TLSv1.3 (IN), TLS handshake, Finished (20):593{ [52 bytes data]594* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):595} [1 bytes data]596* TLSv1.3 (OUT), TLS handshake, Finished (20):597} [52 bytes data]598* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey599* ALPN: server accepted h2600* Server certificate:601* subject: CN=test.foo602* start date: Aug 27 10:32:49 2026 GMT603* expire date: Sep 26 10:32:49 2028 GMT604* issuer: CN=minica root ca 73a0fa605* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384606* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384607* subjectAltName: "test.foo" matches cert's "test.foo"608* OpenSSL verify result: 13609* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)610* closing connection #0611curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)612More details here: https://curl.se/docs/sslcerts.html613614curl failed to verify the legitimacy of the server and therefore could not615establish a secure connection to it. To learn more about this situation and616how to fix it, please visit the webpage mentioned above.617server # [6865755.436312] server acme-order-renew-test.foo-start[333]: Waiting to acquire lock in /run/acme/618server # [6865755.439034] server acme-order-renew-test.foo-start[333]: + set -euo pipefail619server # [6865755.439113] server acme-order-renew-test.foo-start[333]: + echo ad12aa6741ce4bd2c108620server # [6865755.439231] server acme-order-renew-test.foo-start[333]: + cmp -s domainhash.txt certificates/domainhash.txt621server # [6865755.440333] server acme-order-renew-test.foo-start[333]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run622server # [6865755.480646] server acme-order-renew-test.foo-start[341]: 2026/08/27 10:33:01 [INFO] acme: Registering account for none@none.tld623server # [6865755.529557] server acme-order-renew-test.foo-start[341]: !!!! HEADS UP !!!!624server # [6865755.529557] server acme-order-renew-test.foo-start[341]: Your account credentials have been saved in your625server # [6865755.529557] server acme-order-renew-test.foo-start[341]: configuration directory at "accounts".626server # [6865755.529557] server acme-order-renew-test.foo-start[341]: You should make a secure backup of this folder now. This627server # [6865755.529557] server acme-order-renew-test.foo-start[341]: configuration directory will also contain private keys628server # [6865755.529557] server acme-order-renew-test.foo-start[341]: generated by lego and certificates obtained from the ACME629server # [6865755.529557] server acme-order-renew-test.foo-start[341]: server. Making regular backups of this folder is ideal.630server # [6865755.529759] server acme-order-renew-test.foo-start[341]: 2026/08/27 10:33:01 [INFO] [test.foo] acme: Obtaining bundled SAN certificate631server # [6865755.602046] server acme-order-renew-test.foo-start[341]: 2026/08/27 10:33:01 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/uf3sKu7DMRA1vydCHwXLbJgfH6PKl6nb632server # [6865755.602046] server acme-order-renew-test.foo-start[341]: 2026/08/27 10:33:01 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01633server # [6865755.602046] server acme-order-renew-test.foo-start[341]: 2026/08/27 10:33:01 [INFO] [test.foo] acme: use http-01 solver634server # [6865755.602046] server acme-order-renew-test.foo-start[341]: 2026/08/27 10:33:01 [INFO] [test.foo] acme: Trying to solve HTTP-01635server # [6865755.610878] server acme-order-renew-test.foo-start[341]: 2026/08/27 10:33:01 [INFO] [test.foo] The server validated our request636server # [6865755.610951] server acme-order-renew-test.foo-start[341]: 2026/08/27 10:33:01 [INFO] [test.foo] acme: Validations succeeded; requesting certificates637server # [6865755.632225] server acme-order-renew-test.foo-start[341]: 2026/08/27 10:33:01 [INFO] [test.foo] Server responded with a certificate.638server # [6865755.640716] server acme-order-renew-test.foo-start[333]: + mv domainhash.txt certificates/639server # [6865755.642429] server acme-order-renew-test.foo-start[333]: + touch out/acme-success640server # [6865755.644108] server acme-order-renew-test.foo-start[333]: + cmp -s certificates/test.foo.crt out/fullchain.pem641server # [6865755.645151] server acme-order-renew-test.foo-start[333]: + touch out/renewed642server # [6865755.646603] server acme-order-renew-test.foo-start[333]: + echo Installing new certificate643server # [6865755.646603] server acme-order-renew-test.foo-start[333]: Installing new certificate644server # [6865755.646646] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.crt out/fullchain.pem645server # [6865755.648143] server acme-order-renew-test.foo-start[371]: 'certificates/test.foo.crt' -> 'out/fullchain.pem'646server # [6865755.648390] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.key out/key.pem647server # [6865755.649786] server acme-order-renew-test.foo-start[372]: 'certificates/test.foo.key' -> 'out/key.pem'648server # [6865755.650024] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem649server # [6865755.651443] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem'650server # [6865755.651655] server acme-order-renew-test.foo-start[333]: + ln -sf fullchain.pem out/cert.pem651server # [6865755.653168] server acme-order-renew-test.foo-start[333]: + cat out/key.pem out/fullchain.pem652server # [6865755.654694] server acme-order-renew-test.foo-start[333]: + for fixpath in out certificates653server # [6865755.654717] server acme-order-renew-test.foo-start[333]: + '[' -d out ']'654server # [6865755.654717] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=rX,o= out655server # [6865755.656078] server acme-order-renew-test.foo-start[333]: + chown -R acme:nginx out656server # [6865755.658520] server acme-order-renew-test.foo-start[333]: + for fixpath in out certificates657server # [6865755.658566] server acme-order-renew-test.foo-start[333]: + '[' -d certificates ']'658server # [6865755.658566] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=rX,o= certificates659server # [6865755.659997] server acme-order-renew-test.foo-start[333]: + chown -R acme:nginx certificates660server # [6865755.663195] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=,o= accounts/.661ca # [6865755.480265] ca step-ca[204]: time="2026-08-27T10:33:01Z" level=info duration="43.721µs" duration-ns=43721 fields.time="2026-08-27T10:33:01Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=6e05be50-7680-4085-b7fd-a57783e1d0f4 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=662ca # [6865755.521704] ca step-ca[204]: time="2026-08-27T10:33:01Z" level=info duration=38.885994ms duration-ns=38885994 fields.time="2026-08-27T10:33:01Z" method=HEAD name=ca nonce=VHRPME5BRTdKYmJGblRyMFVzUkFia0l5bmx0VUhEU3c path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=deeb5965-6b42-4be3-bcad-f5aa64cc203f size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=663ca # [6865755.529038] ca step-ca[204]: time="2026-08-27T10:33:01Z" level=info duration=5.110193ms duration-ns=5110193 fields.time="2026-08-27T10:33:01Z" method=POST name=ca nonce=ajV3dW82bFhVeUFnWk5ySWJCT1BzQXpIZ0lzd1lVbDI path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=65de9596-b7cf-4b90-a7b9-ab829722911f response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/wOCwhb3E1W1w5JJ3ed6nne0Q2phPgpzo/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=664ca # [6865755.537101] ca step-ca[204]: time="2026-08-27T10:33:01Z" level=info duration=4.547865ms duration-ns=4547865 fields.time="2026-08-27T10:33:01Z" method=POST name=ca nonce=cUE4c0VuR0F0VlM5WTJsTDV2TkRVdVlFWGZpZ1Q2SG0 path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=eb2b2186-dfab-4894-ba96-a38851099852 response="{\"id\":\"6U1024JYhDg12DHetAGQZd7jqiu2uKvB\",\"status\":\"pending\",\"expires\":\"2026-08-28T10:33:01Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-27T10:32:01Z\",\"notAfter\":\"2026-11-25T10:33:01Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/uf3sKu7DMRA1vydCHwXLbJgfH6PKl6nb\"],\"finalize\":\"https://ca.foo/acme/acme/order/6U1024JYhDg12DHetAGQZd7jqiu2uKvB/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=665ca # [6865755.601502] ca step-ca[204]: time="2026-08-27T10:33:01Z" level=info duration=4.805668ms duration-ns=4805668 fields.time="2026-08-27T10:33:01Z" method=POST name=ca nonce=ZnJuSHFaRlpQYUFBRXJ1ZU1RV2F4SWxxN1FlVXZ3ZWs path=/acme/acme/authz/uf3sKu7DMRA1vydCHwXLbJgfH6PKl6nb protocol=HTTP/1.1 referer= remote-address="::1" request-id=07b33a8e-0948-41b8-864c-b51dbcdefbd0 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"nzVX4SxfejFF3RT2ynseBk3HYUepspcT\",\"url\":\"https://ca.foo/acme/acme/challenge/uf3sKu7DMRA1vydCHwXLbJgfH6PKl6nb/pqM0ZMKvlC0ePMaLAg1UMK8nbGIYMa8r\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"nzVX4SxfejFF3RT2ynseBk3HYUepspcT\",\"url\":\"https://ca.foo/acme/acme/challenge/uf3sKu7DMRA1vydCHwXLbJgfH6PKl6nb/4F92IYz6zjUiC65RZQBXcOBXM2radd3N\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"nzVX4SxfejFF3RT2ynseBk3HYUepspcT\",\"url\":\"https://ca.foo/acme/acme/challenge/uf3sKu7DMRA1vydCHwXLbJgfH6PKl6nb/71F41CynYO5umgrdHW37ZzyqTkiKxIiG\"}],\"wildcard\":false,\"expires\":\"2026-08-28T10:33:01Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=666ca # [6865755.610400] ca step-ca[204]: time="2026-08-27T10:33:01Z" level=info duration=5.358156ms duration-ns=5358156 fields.time="2026-08-27T10:33:01Z" method=POST name=ca nonce=UUZRNWNKVFY0V24yQ2tFVW1uMFlEclhtVFdiaDl6QUM path=/acme/acme/challenge/uf3sKu7DMRA1vydCHwXLbJgfH6PKl6nb/4F92IYz6zjUiC65RZQBXcOBXM2radd3N protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=41398a7e-016d-459a-bc10-3310ed6a11f5 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"nzVX4SxfejFF3RT2ynseBk3HYUepspcT\",\"validated\":\"2026-08-27T10:33:01Z\",\"url\":\"https://ca.foo/acme/acme/challenge/uf3sKu7DMRA1vydCHwXLbJgfH6PKl6nb/4F92IYz6zjUiC65RZQBXcOBXM2radd3N\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=667ca # [6865755.622136] ca step-ca[204]: time="2026-08-27T10:33:01Z" level=info duration=8.818205ms duration-ns=8818205 fields.time="2026-08-27T10:33:01Z" method=POST name=ca nonce=T1MxQzNEeW9oWkdRT0FNS2xOQTBSU21IRDdEWnROeHQ path=/acme/acme/order/6U1024JYhDg12DHetAGQZd7jqiu2uKvB/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=83147eeb-5676-4d9e-8f4a-402f50a61df4 response="{\"id\":\"6U1024JYhDg12DHetAGQZd7jqiu2uKvB\",\"status\":\"valid\",\"expires\":\"2026-08-28T10:33:01Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-27T10:32:01Z\",\"notAfter\":\"2026-11-25T10:33:01Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/uf3sKu7DMRA1vydCHwXLbJgfH6PKl6nb\"],\"finalize\":\"https://ca.foo/acme/acme/order/6U1024JYhDg12DHetAGQZd7jqiu2uKvB/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/8tlzKRRxAvKWTaLXAjnSocxnhEpLxf9X\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=668ca # [6865755.631502] ca step-ca[204]: time="2026-08-27T10:33:01Z" level=info certificate="MIIB2DCCAX2gAwIBAgIQNHNlSu0etGgBKEc8AiPjDTAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MjcxMDMyMDFaFw0yNjExMjUxMDMzMDFaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEq6X66uCky28wl0hC8egQkpAr/4Q5klC/CLkK3+nXhGM3u+TFxItdf14NlTx2yKzqqdot7YFUNYH/Q+N0w3twCaOBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBTNqn2+Hq78HAIuvYAd6Kd0L9kPcDAfBgNVHSMEGDAWgBR3Eg3pMf6frfUiwNQJuyQr+/bhWjATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSQAwRgIhAKrBsDEw77HbRh+sYi9Q1ocnSnwjx4B/UhDQZs2fDrGEAiEAp6LoUJFTH+9OUVOXuUWoZZEafPEA2AZNjLSSmRxdC/0=" duration=4.363982ms duration-ns=4363982 fields.time="2026-08-27T10:33:01Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=Z1BNVm10YkVaUndtQlRFMW83T0psaUtZYXNIUVJqbHI path=/acme/acme/certificate/8tlzKRRxAvKWTaLXAjnSocxnhEpLxf9X protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=5e8b4e5a-934a-4247-8d37-3c866179b907 sans="map[dns:[test.foo]]" serial=69719024379186192489311690088182440717 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-27T10:32:01Z" valid-to="2026-11-25T10:33:01Z"669server # [6865755.818458] server systemd[1]: Reloading Nginx Web Server...670server # [6865755.823292] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully.671server # [6865755.823483] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo.672* Host test.foo:443 was resolved.673* IPv6: 2001:db8:1::3674* IPv4: 192.168.1.3675* Trying [2001:db8:1::3]:443...676* ALPN: curl offers h2,http/1.1677} [5 bytes data]678* TLSv1.3 (OUT), TLS handshake, Client hello (1):679} [1552 bytes data]680* SSL Trust Anchors:681* OpenSSL default paths (fallback)682{ [5 bytes data]683* TLSv1.3 (IN), TLS handshake, Server hello (2):684{ [1210 bytes data]685* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):686{ [1 bytes data]687* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):688{ [19 bytes data]689* TLSv1.3 (IN), TLS handshake, Certificate (11):690{ [1009 bytes data]691* TLSv1.3 (IN), TLS handshake, CERT verify (15):692{ [111 bytes data]693* TLSv1.3 (IN), TLS handshake, Finished (20):694{ [52 bytes data]695* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):696} [1 bytes data]697* TLSv1.3 (OUT), TLS handshake, Finished (20):698} [52 bytes data]699* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey700* ALPN: server accepted h2701* Server certificate:702* subject: CN=test.foo703* start date: Aug 27 10:32:49 2026 GMT704* expire date: Sep 26 10:32:49 2028 GMT705* issuer: CN=minica root ca 73a0fa706* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384707* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384708* subjectAltName: "test.foo" matches cert's "test.foo"709* OpenSSL verify result: 13710* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)711* closing connection #0712curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)713More details here: https://curl.se/docs/sslcerts.html714715curl failed to verify the legitimacy of the server and therefore could not716establish a secure connection to it. To learn more about this situation and717how to fix it, please visit the webpage mentioned above.718server # [6865756.549434] server nginx[389]: nginx: the configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf syntax is ok719server # [6865756.549820] server nginx[389]: nginx: configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf test is successful720* Host test.foo:443 was resolved.721* IPv6: 2001:db8:1::3722* IPv4: 192.168.1.3723* Trying [2001:db8:1::3]:443...724* ALPN: curl offers h2,http/1.1725} [5 bytes data]726* TLSv1.3 (OUT), TLS handshake, Client hello (1):727} [1552 bytes data]728* SSL Trust Anchors:729* OpenSSL default paths (fallback)730{ [5 bytes data]731* TLSv1.3 (IN), TLS handshake, Server hello (2):732{ [1210 bytes data]733* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):734{ [1 bytes data]735* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):736{ [19 bytes data]737* TLSv1.3 (IN), TLS handshake, Certificate (11):738{ [1009 bytes data]739* TLSv1.3 (IN), TLS handshake, CERT verify (15):740{ [111 bytes data]741* TLSv1.3 (IN), TLS handshake, Finished (20):742{ [52 bytes data]743* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):744} [1 bytes data]745* TLSv1.3 (OUT), TLS handshake, Finished (20):746} [52 bytes data]747* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey748* ALPN: server accepted h2749* Server certificate:750* subject: CN=test.foo751* start date: Aug 27 10:32:49 2026 GMT752* expire date: Sep 26 10:32:49 2028 GMT753* issuer: CN=minica root ca 73a0fa754* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384755* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384756* subjectAltName: "test.foo" matches cert's "test.foo"757* OpenSSL verify result: 13758* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)759* closing connection #0760curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)761More details here: https://curl.se/docs/sslcerts.html762763curl failed to verify the legitimacy of the server and therefore could not764establish a secure connection to it. To learn more about this situation and765how to fix it, please visit the webpage mentioned above.766server # [6865757.454404] server systemd[1]: Reloaded Nginx Web Server.767* Host test.foo:443 was resolved.768* IPv6: 2001:db8:1::3769* IPv4: 192.168.1.3770* Trying [2001:db8:1::3]:443...771* ALPN: curl offers h2,http/1.1772} [5 bytes data]773* TLSv1.3 (OUT), TLS handshake, Client hello (1):774} [1552 bytes data]775* SSL Trust Anchors:776* OpenSSL default paths (fallback)777{ [5 bytes data]778* TLSv1.3 (IN), TLS handshake, Server hello (2):779{ [1210 bytes data]780* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):781{ [1 bytes data]782* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):783{ [19 bytes data]784* TLSv1.3 (IN), TLS handshake, Certificate (11):785{ [931 bytes data]786* TLSv1.3 (IN), TLS handshake, CERT verify (15):787{ [80 bytes data]788* TLSv1.3 (IN), TLS handshake, Finished (20):789{ [52 bytes data]790* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):791} [1 bytes data]792* TLSv1.3 (OUT), TLS handshake, Finished (20):793} [52 bytes data]794* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey795* ALPN: server accepted h2796* Server certificate:797* subject: CN=test.foo798* start date: Aug 27 10:32:01 2026 GMT799* expire date: Nov 25 10:33:01 2026 GMT800* issuer: CN=Clan Intermediate CA801* Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256802* Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256803* Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256804* subjectAltName: "test.foo" matches cert's "test.foo"805* OpenSSL verify result: 0806* SSL certificate verified via OpenSSL.807* Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 56622 808 % Total % Received % Xferd Average Speed Time Time Time Current809 Dload Upload Total Spent Left Speed810 0 0 0 0 0 0 0 0 0* using HTTP/2811* [HTTP/2] [1] OPENED stream for https://test.foo/812* [HTTP/2] [1] [:method: GET]813* [HTTP/2] [1] [:scheme: https]814* [HTTP/2] [1] [:authority: test.foo]815* [HTTP/2] [1] [:path: /]816* [HTTP/2] [1] [user-agent: curl/8.21.0]817* [HTTP/2] [1] [accept: */*]818} [5 bytes data]819820821822823824* Request completely sent off825{ [5 bytes data]826* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):827{ [265 bytes data]828* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):829{ [265 bytes data]830831832833834835836837{ [5 bytes data]838100 20 100 20 0 0 815 0 0839* Connection #0 to host test.foo:443 left intact840client: (finished: waiting for success: curl -v https://test.foo, in 4.21 seconds)841client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2842Certificate:843 Data:844 Version: 3 (0x2)845 Serial Number:846 34:73:65:4a:ed:1e:b4:68:01:28:47:3c:02:23:e3:0d847 Signature Algorithm: ecdsa-with-SHA256848 Issuer: CN=Clan Intermediate CA849 Validity850 Not Before: Aug 27 10:32:01 2026 GMT851 Not After : Nov 25 10:33:01 2026 GMT852 Subject: CN=test.foo853 Subject Public Key Info:854 Public Key Algorithm: id-ecPublicKey855 Public-Key: (256 bit)856 pub:857 04:ab:a5:fa:ea:e0:a4:cb:6f:30:97:48:42:f1:e8:858 10:92:90:2b:ff:84:39:92:50:bf:08:b9:0a:df:e9:859 d7:84:63:37:bb:e4:c5:c4:8b:5d:7f:5e:0d:95:3c:860 76:c8:ac:ea:a9:da:2d:ed:81:54:35:81:ff:43:e3:861 74:c3:7b:70:09862 ASN1 OID: prime256v1863 NIST CURVE: P-256864 X509v3 extensions:865 X509v3 Key Usage: critical866 Digital Signature867 X509v3 Extended Key Usage: 868 TLS Web Server Authentication, TLS Web Client Authentication869 X509v3 Subject Key Identifier: 870 CD:AA:7D:BE:1E:AE:FC:1C:02:2E:BD:80:1D:E8:A7:74:2F:D9:0F:70871 X509v3 Authority Key Identifier: 872 77:12:0D:E9:31:FE:9F:AD:F5:22:C0:D4:09:BB:24:2B:FB:F6:E1:5A873 X509v3 Subject Alternative Name: 874 DNS:test.foo875 1.3.6.1.4.1.37476.9000.64.1: 876 0......acme..877 Signature Algorithm: ecdsa-with-SHA256878 Signature Value:879 30:46:02:21:00:aa:c1:b0:31:30:ef:b1:db:46:1f:ac:62:2f:880 50:d6:87:27:4a:7c:23:c7:80:7f:52:10:d0:66:cd:9f:0e:b1:881 84:02:21:00:a7:a2:e8:50:91:53:1f:ef:4e:51:53:97:b9:45:882 a8:65:91:1a:7c:f1:00:d8:06:4d:8c:b4:92:99:1c:5d:0b:fd883client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2, in 0.04 seconds)884(finished: run the VM test script, in 19.64 seconds)885test script finished in 19.69s886cleanup887kill NspawnMachine (pid 53)888kill NspawnMachine (pid 54)889Container ca terminated by signal KILL.890kill NspawnMachine (pid 55)891Container client terminated by signal KILL.892(finished: cleanup, in 0.49 seconds)893Container server terminated by signal KILL.