these 129 derivations will be built: /nix/store/0aznxyzb6x331csg7gjn8cw5xl2605pi-system-path.drv /nix/store/36093jr86bnmgl2w5hi8pb61ly2bfymc-unit-suid-sgid-wrappers.service-disabled.drv /nix/store/50m6cfa5x1dxaslnp49g6lxj4p7np9bp-unit-systemd-networkd.service.drv /nix/store/863zw10ii54bs6wmi9c48cjaihd3ln1p-unit-resolvconf.service-disabled.drv /nix/store/jbshx5qyrvn9cpssjwl13flglklg15sj-unit-script-nix-gc-start.drv /nix/store/90yard373v99f02ghjm179dw0jyra3jq-unit-nix-gc.service.drv /nix/store/9wq3xd2sy586pzs7rnpcsl1857hf2a4x-unit-systemd-journald-.service.drv /nix/store/fa3m94n9x9h6rvcvv1b7xmbvzxxndg04-system-path.drv /nix/store/h8wqiaffc333h4n15l9fq1wrz4849l51-dbus-1.drv /nix/store/m5iwi6jigzhhka4fg48a5vdkd9b03dh5-X-Restart-Triggers-dbus-broker.drv /nix/store/c5ddj5j6j88aw15558234rxzaq62jifn-unit-dbus-broker.service.drv /nix/store/55r3xbviq6l3zgziig53rhs351x7xj6l-cacert-extra-certificates-bundle.crt.drv /nix/store/x52vjn5rprsx9n1jd5m287f9yhs1ffqn-cacert-blocklist.txt.drv /nix/store/7l2xgzni77jwd11cz3z5iw69vhnlqdji-nss-cacert-3.126.drv /nix/store/lxkn1msxrap3j472dyw6hq1lk55dml8p-X-Restart-Triggers-nix-daemon.drv /nix/store/d79nmaybjgffcypr4zfhnp7p3vrgijly-unit-nix-daemon.service.drv /nix/store/dc4gn73n2m072ck0rm5jx5npg9winm6c-unit-serial-getty-hvc0.service-disabled.drv /nix/store/p32ifkb9jkjlhm1m1m17jg1nbmqc4zbl-X-Restart-Triggers-systemd-sysctl.drv /nix/store/g2gpd27y6vw63m3l59xsfrqf44l31igf-unit-systemd-sysctl.service.drv /nix/store/g9bfvl6h2n1ags2vhzcymd11bzbp5vsc-unit-systemd-journald.service.drv /nix/store/wk7m48i09fl5440y04scqvbjjx6v5blg-firewall-reload.drv /nix/store/i8g688x99787cjd8jvlsmddvhq71rcv2-unit-firewall.service.drv /nix/store/iwak2s8vxh0gknl39krmkycm8k27lbyw-unit-serial-getty-ttyAMA0.service-disabled.drv /nix/store/prkpxrpnbg00wkvx2dnkna3y29skgvjg-X-Reload-Triggers-systemd-resolved.drv /nix/store/v0clim1zszqklxri4dwhf4gr45rx79ja-unit-systemd-resolved.service.drv /nix/store/611br14m45zhx3dfhz4q47a5y9248n9n-shutdown-ramfs-contents.json.drv /nix/store/v75n6iibh1hdrjkqg7cig45jy07dhyfa-unit-generate-shutdown-ramfs.service.drv /nix/store/r8fhz27xd0l66xr72gkaka9navxlsqg9-tmpfiles.d.drv /nix/store/sl5znvf0apy7ym92giyfbi95qqf7z9in-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/vkpiaym4725622gh4zq7x9vzcay622dk-unit-systemd-tmpfiles-resetup.service.drv /nix/store/wsyfklsm3q5s0r921ifrnvrf8vpa818w-unit-systemd-timedated.service.drv /nix/store/y09qxnkg7kkpr443p6k4smg9pspqdbih-unit-serial-getty-.service.drv /nix/store/zysgb31jhg6syi6xkv3ap6lrd4pb7yhm-unit-systemd-makefs-.service.drv /nix/store/0d1mj0bmx5g8050fds6va1rirgqsi2q9-system-units.drv /nix/store/6855qyfnz0gs4rb5b4vjlakqwsx0c0pl-system-path.drv /nix/store/fic80krmpyc0vdr46jg8vn3n1f0g2j73-dbus-1.drv /nix/store/mrnpn8dw7zhx50b8swf2sk27a7pj7fa5-X-Restart-Triggers-dbus-broker.drv /nix/store/rkdgv9ib3kg999rh445ciz27785ymvsz-unit-dbus-broker.service.drv /nix/store/0ksihnydzfrkng1zyj3i8a7lx7djrxf7-user-units.drv /nix/store/bychh595fc590mv3gxmri156qz332kig-ca.json.drv /nix/store/piyiw6gkn670gpm11q7i0cyh9a5idrrz-X-Restart-Triggers-step-ca.drv /nix/store/0lyj566nvprnn3xrr18aha9hjqwh4n3i-unit-step-ca.service.drv /nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv /nix/store/6z5jc0sp4vjkgzd37icya2gy22sk8q70-nixos-tmpfiles.d.drv /nix/store/79kfpjcg65c0rrnp43qfppivwzfx8yvi-10-acme.conf.drv /nix/store/3rxxn6h88dq0dw8c0jb09b175y7dx7ys-tmpfiles.d.drv /nix/store/4d11adikk9i02khvknlf61i542avljxa-nginx.conf.drv /nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv /nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv /nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv /nix/store/v3r6klh4wv9zb6hmz7fwb1gyzyil9a5n-unit-40-eth1.network.drv /nix/store/ycl6gbj04ywcaxa7ad5ms35wranp5b1r-X-Reload-Triggers-systemd-networkd.drv /nix/store/2y5dcvasfw9vhxcmcgzy70r1w1bd6jg9-unit-systemd-networkd.service.drv /nix/store/j3lmyghsa4g7nacl7gf67lvx5m91k2br-unit-script-acme-setup-start.drv /nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv /nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv /nix/store/kjql7xf5v2jlgmmrdnz87nan6jmlgyaj-unit-script-nginx-pre-start.drv /nix/store/ihcyabx8107x0z51x1p00ss738m1by4z-unit-nginx.service.drv /nix/store/ma7d068wl7r81dsprwq8db0ccvml111w-unit-dbus-broker.service.drv /nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv /nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv /nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv /nix/store/pz8cs4lg35mq4mi7ck3am5chl70g70yx-firewall-start.drv /nix/store/1h3016b7n1wag10qh4dax4mdvk4hiydh-firewall-reload.drv /nix/store/ra9f6mzgpig8bxfp26sd4f4dhdymamc3-unit-firewall.service.drv /nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv /nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv /nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv /nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv /nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv /nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/sg6xid8vdr82bvgaxxp97z15ijj6xlyh-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/wdrjpapm3vz3asakl6v1mj7l3ps5ri5r-unit-systemd-tmpfiles-resetup.service.drv /nix/store/w39mwlz7rkmh9b9n5r45nnmha2dzrd05-system-units.drv /nix/store/0y05rvglr3ir1qdwfqfhdag7sw0qipkb-etc.drv /nix/store/7bm5w0wpz1gk6ma416c9i77kslkzgm9m-decrypt-age-secrets.drv /nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv /nix/store/dchyhwqv07i7klnvd0xqr9dk47fvwd5q-activate.drv /nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv /nix/store/3m8xb51m5wqvmzmc0996sgckkjammya0-nixos-system-server-test.drv /nix/store/i6p39l619i0sz52sspw93wikd5xyj9rd-run-server-nspawn.drv /nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv /nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv /nix/store/jxm6hpbyi9ja04zj89z6qzrwjy2pk16q-unit-dbus-broker.service.drv /nix/store/ya9vnsc16n65kc9lhqmjnniq63dvccgk-user-units.drv /nix/store/6zglsqk8kybhfqkr3s4wd5ch622lb0in-etc.drv /nix/store/5mrdkkv0rkyrgkwxwdj3gbwks10c6i55-users-groups.json.drv /nix/store/hvpdgppc2ph0w7r40a0nla0cl5zy2x1k-dry-activate.drv /nix/store/icv2xfwy742yz0k6abs6jrlpyq3knp71-activate.drv /nix/store/sipyzq1idf290a3gymyv0vz3bmsm4zs8-nixos-system-client-test.drv /nix/store/nvgip3jazl7x6cj7vmlrkajr24lnd403-run-client-nspawn.drv /nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv /nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv /nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv /nix/store/gml8r4jzrx8pxi8kgp8dskjbyaw0a0fs-dbus-1.drv /nix/store/zaygn692fzw3y7hvi0y2nspp3vxdf4zf-X-Restart-Triggers-dbus-broker.drv /nix/store/k7p5hmpmjprhf8avpip5hqgwal6ynyar-unit-dbus-broker.service.drv /nix/store/5byjaqq8fvvhkpibph0xvk5464lnadf5-user-units.drv /nix/store/p58gpq8dlbza3dklkqrzwj7blz2knydv-nginx-recommended-proxy_set_header-headers.conf.drv /nix/store/757sc0s15h5d4i5y78ywmzdiimbsgys7-nginx.conf.drv /nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv /nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv /nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv /nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv /nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv /nix/store/fx7ik3vx6rfz50jgfpv7iqc1npfpfzn6-unit-systemd-networkd.service.drv /nix/store/if2dfikfrcj1g6phg8p3i4r8h3bh1h2i-unit-dbus-broker.service.drv /nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/g74w0jngpc4wya00k4q2k9k64pvcvfn7-unit-script-nginx-pre-start.drv /nix/store/pfj1fkxgbai6b3cqfacgddq0cc1dd76x-unit-nginx.service.drv /nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv /nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv /nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv /nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv /nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv /nix/store/azfpzvqsbpcvzn90kld3s3ncbbb98akx-system-units.drv /nix/store/c2pygc22m06f5j91981i00smr1dw9d9f-user-generators.drv /nix/store/ikk469l2wssyvzhq1n3iyvza3f30jvc5-system-shutdown.drv /nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv /nix/store/kv244kzjv2wsq4aj781mgqyi03rkwppz-system-generators.drv /nix/store/p2jzgg84l6m667s243pxvh4g45rj25px-etc.drv /nix/store/km7ql53mknxxbf4wdl8hxgk852s8mzyy-activate.drv /nix/store/cizg7vmw57wicgkr8m15sz4qjsz0mjbi-nixos-system-ca-test.drv /nix/store/ylkssa7h2lwmqffi9c3ava0nbnzsa9h8-run-ca-nspawn.drv /nix/store/11ildvvba5fx8n6q5gi52rlj375qxvkh-driverConfiguration.json.drv /nix/store/qx487647kjd397w9k1mkny11pxxsd7bq-nixos-test-driver-1.1.drv /nix/store/ylgjjxb2hdqff1b5bycn5x9cjgqshir4-nixos-test-driver-certificates.drv /nix/store/19ikf78pfn230xifcrjzwax5r1pybgij-container-test-run-certificates.drv these 16 paths will be fetched (45.5 MiB download, 148.8 MiB unpacked): /nix/store/3japwvq6a40ykrmxjjjvm695q2z6c66c-flock-0.4.0 /nix/store/6nr0a4775j5z9nr71ciasfd9pzz076zs-gixy-0.1.21 /nix/store/p12aczsxidgl3m4jkpc4dl4y7kzf8vck-lego-4.35.2 /nix/store/fqcqw4nlcg6q6n77z3gnxhgg3ll6gjvy-minica-1.1.0 /nix/store/pjqhdi88bpspx4a01qlsw96jn2isl11k-nginx-1.30.4 /nix/store/g59y871mjn55fgjswdn72g51qc62j6wa-nginx-config-formatter-1.4.0 /nix/store/n0hdbypqp52bcmm1b5bhxgha5yl8hjs1-nginx-mod-moreheaders-0.40 /nix/store/zzhdyl8d6l7z4jfl5i36ijwqz2vpja7i-nginx-mod-rtmp-1.2.2 /nix/store/1psq003v8r8611bv7bk74xdwz9z6dgaj-openssl-3.6.3-man /nix/store/06pcrb4pj0c0sk6pa39hgmfddprslv4k-openssl-4.0.1 /nix/store/fkylsp720lag8s97n9cbxcafx78clj31-python3.14-buildcatrust-0.5.1 /nix/store/kjz0wmk9imvcj2nrm6ls5yd4mw8awajj-python3.14-cached-property-2.0.1 /nix/store/pfxx0s91wb2bhph7m1hdmzik1d8r9jn9-python3.14-configargparse-1.7.5 /nix/store/fdr01jdc50hn18dn90hx7q9p2jhkaw6m-python3.14-pyparsing-2.4.7 /nix/store/9zffz42v1gbfs8dwi61v4m09skszgl9x-step-ca-0.30.2 /nix/store/j345y5z7axzdpxivknd0swxi5yccyxq4-zlib-ng-2.3.3 building '/nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v3r6klh4wv9zb6hmz7fwb1gyzyil9a5n-unit-40-eth1.network.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/79kfpjcg65c0rrnp43qfppivwzfx8yvi-10-acme.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p58gpq8dlbza3dklkqrzwj7blz2knydv-nginx-recommended-proxy_set_header-headers.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6z5jc0sp4vjkgzd37icya2gy22sk8q70-nixos-tmpfiles.d.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kv244kzjv2wsq4aj781mgqyi03rkwppz-system-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv' building '/nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv' building '/nix/store/v3r6klh4wv9zb6hmz7fwb1gyzyil9a5n-unit-40-eth1.network.drv' unit-40-eth1.network> structuredAttrs is enabled building '/nix/store/79kfpjcg65c0rrnp43qfppivwzfx8yvi-10-acme.conf.drv' building '/nix/store/ycl6gbj04ywcaxa7ad5ms35wranp5b1r-X-Reload-Triggers-systemd-networkd.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv' building '/nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bychh595fc590mv3gxmri156qz332kig-ca.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/x52vjn5rprsx9n1jd5m287f9yhs1ffqn-cacert-blocklist.txt.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/55r3xbviq6l3zgziig53rhs351x7xj6l-cacert-extra-certificates-bundle.crt.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/pz8cs4lg35mq4mi7ck3am5chl70g70yx-firewall-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/4d11adikk9i02khvknlf61i542avljxa-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0aznxyzb6x331csg7gjn8cw5xl2605pi-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6855qyfnz0gs4rb5b4vjlakqwsx0c0pl-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/fa3m94n9x9h6rvcvv1b7xmbvzxxndg04-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ikk469l2wssyvzhq1n3iyvza3f30jvc5-system-shutdown.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/j3lmyghsa4g7nacl7gf67lvx5m91k2br-unit-script-acme-setup-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/c2pygc22m06f5j91981i00smr1dw9d9f-user-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p58gpq8dlbza3dklkqrzwj7blz2knydv-nginx-recommended-proxy_set_header-headers.conf.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/6z5jc0sp4vjkgzd37icya2gy22sk8q70-nixos-tmpfiles.d.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv' building '/nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv' building '/nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv' building '/nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv' building '/nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv' building '/nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv' unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled building '/nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv' unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled building '/nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv' unit-acme-renew-ca.foo.timer> structuredAttrs is enabled building '/nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv' unit-acme-renew-test.foo.timer> structuredAttrs is enabled building '/nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/757sc0s15h5d4i5y78ywmzdiimbsgys7-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/3rxxn6h88dq0dw8c0jb09b175y7dx7ys-tmpfiles.d.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kv244kzjv2wsq4aj781mgqyi03rkwppz-system-generators.drv' building '/nix/store/ycl6gbj04ywcaxa7ad5ms35wranp5b1r-X-Reload-Triggers-systemd-networkd.drv' building '/nix/store/2y5dcvasfw9vhxcmcgzy70r1w1bd6jg9-unit-systemd-networkd.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/x52vjn5rprsx9n1jd5m287f9yhs1ffqn-cacert-blocklist.txt.drv' building '/nix/store/bychh595fc590mv3gxmri156qz332kig-ca.json.drv' ca.json> structuredAttrs is enabled building '/nix/store/piyiw6gkn670gpm11q7i0cyh9a5idrrz-X-Restart-Triggers-step-ca.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/55r3xbviq6l3zgziig53rhs351x7xj6l-cacert-extra-certificates-bundle.crt.drv' building '/nix/store/pz8cs4lg35mq4mi7ck3am5chl70g70yx-firewall-start.drv' building '/nix/store/7l2xgzni77jwd11cz3z5iw69vhnlqdji-nss-cacert-3.126.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv' building '/nix/store/4d11adikk9i02khvknlf61i542avljxa-nginx.conf.drv' nginx.conf> structuredAttrs is enabled nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/kjql7xf5v2jlgmmrdnz87nan6jmlgyaj-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0aznxyzb6x331csg7gjn8cw5xl2605pi-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/ikk469l2wssyvzhq1n3iyvza3f30jvc5-system-shutdown.drv' building '/nix/store/fa3m94n9x9h6rvcvv1b7xmbvzxxndg04-system-path.drv' system-path> structuredAttrs is enabled building '/nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv' building '/nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv' system-path> created 1718 symlinks in user environment building '/nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv' building '/nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv' building '/nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv' building '/nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv' building '/nix/store/3rxxn6h88dq0dw8c0jb09b175y7dx7ys-tmpfiles.d.drv' building '/nix/store/757sc0s15h5d4i5y78ywmzdiimbsgys7-nginx.conf.drv' nginx.conf> structuredAttrs is enabled building '/nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/j3lmyghsa4g7nacl7gf67lvx5m91k2br-unit-script-acme-setup-start.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/g74w0jngpc4wya00k4q2k9k64pvcvfn7-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/sg6xid8vdr82bvgaxxp97z15ijj6xlyh-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/1h3016b7n1wag10qh4dax4mdvk4hiydh-firewall-reload.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/piyiw6gkn670gpm11q7i0cyh9a5idrrz-X-Restart-Triggers-step-ca.drv' building '/nix/store/7l2xgzni77jwd11cz3z5iw69vhnlqdji-nss-cacert-3.126.drv' nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase building '/nix/store/h8wqiaffc333h4n15l9fq1wrz4849l51-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase building '/nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/c2pygc22m06f5j91981i00smr1dw9d9f-user-generators.drv' building '/nix/store/2y5dcvasfw9vhxcmcgzy70r1w1bd6jg9-unit-systemd-networkd.service.drv' unit-systemd-networkd.service> structuredAttrs is enabled nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/fynh3gb6fqxplyn6gxx02a773s8l69d6-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/fynh3gb6fqxplyn6gxx02a773s8l69d6-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/fynh3gb6fqxplyn6gxx02a773s8l69d6-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/czllyk25hb5mfc035i9pap5j5fv5yhlv-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/czllyk25hb5mfc035i9pap5j5fv5yhlv-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/czllyk25hb5mfc035i9pap5j5fv5yhlv-nss-cacert-3.126-unbundled building '/nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/ajx7ddrqjy8brksdvx7s0vqqi0jrh623-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/ajx7ddrqjy8brksdvx7s0vqqi0jrh623-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/ajx7ddrqjy8brksdvx7s0vqqi0jrh623-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/78gs1xgr6xak6pw2sf4dnji7ny094mf7-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/78gs1xgr6xak6pw2sf4dnji7ny094mf7-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/78gs1xgr6xak6pw2sf4dnji7ny094mf7-nss-cacert-3.126-hashed building '/nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/kjql7xf5v2jlgmmrdnz87nan6jmlgyaj-unit-script-nginx-pre-start.drv' building '/nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0lyj566nvprnn3xrr18aha9hjqwh4n3i-unit-step-ca.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv' building '/nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ihcyabx8107x0z51x1p00ss738m1by4z-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6855qyfnz0gs4rb5b4vjlakqwsx0c0pl-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/d79nmaybjgffcypr4zfhnp7p3vrgijly-unit-nix-daemon.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/gml8r4jzrx8pxi8kgp8dskjbyaw0a0fs-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled building '/nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv' unit-acme-order-renew-test.foo.service> structuredAttrs is enabled building '/nix/store/fic80krmpyc0vdr46jg8vn3n1f0g2j73-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/g74w0jngpc4wya00k4q2k9k64pvcvfn7-unit-script-nginx-pre-start.drv' building '/nix/store/pfj1fkxgbai6b3cqfacgddq0cc1dd76x-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/sg6xid8vdr82bvgaxxp97z15ijj6xlyh-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' building '/nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv' building '/nix/store/gml8r4jzrx8pxi8kgp8dskjbyaw0a0fs-dbus-1.drv' building '/nix/store/1h3016b7n1wag10qh4dax4mdvk4hiydh-firewall-reload.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/fic80krmpyc0vdr46jg8vn3n1f0g2j73-dbus-1.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/ra9f6mzgpig8bxfp26sd4f4dhdymamc3-unit-firewall.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/h8wqiaffc333h4n15l9fq1wrz4849l51-dbus-1.drv' building '/nix/store/zaygn692fzw3y7hvi0y2nspp3vxdf4zf-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/mrnpn8dw7zhx50b8swf2sk27a7pj7fa5-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv' unit-acme-test.foo.service> structuredAttrs is enabled building '/nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv' unit-acme-ca.foo.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ihcyabx8107x0z51x1p00ss738m1by4z-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/pfj1fkxgbai6b3cqfacgddq0cc1dd76x-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/d79nmaybjgffcypr4zfhnp7p3vrgijly-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/0lyj566nvprnn3xrr18aha9hjqwh4n3i-unit-step-ca.service.drv' unit-step-ca.service> structuredAttrs is enabled building '/nix/store/zaygn692fzw3y7hvi0y2nspp3vxdf4zf-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/mrnpn8dw7zhx50b8swf2sk27a7pj7fa5-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/ma7d068wl7r81dsprwq8db0ccvml111w-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rkdgv9ib3kg999rh445ciz27785ymvsz-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ra9f6mzgpig8bxfp26sd4f4dhdymamc3-unit-firewall.service.drv' unit-firewall.service> structuredAttrs is enabled building '/nix/store/wdrjpapm3vz3asakl6v1mj7l3ps5ri5r-unit-systemd-tmpfiles-resetup.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/if2dfikfrcj1g6phg8p3i4r8h3bh1h2i-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/k7p5hmpmjprhf8avpip5hqgwal6ynyar-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv' building '/nix/store/rkdgv9ib3kg999rh445ciz27785ymvsz-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/ma7d068wl7r81dsprwq8db0ccvml111w-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/m5iwi6jigzhhka4fg48a5vdkd9b03dh5-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/if2dfikfrcj1g6phg8p3i4r8h3bh1h2i-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/k7p5hmpmjprhf8avpip5hqgwal6ynyar-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/0ksihnydzfrkng1zyj3i8a7lx7djrxf7-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5byjaqq8fvvhkpibph0xvk5464lnadf5-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wdrjpapm3vz3asakl6v1mj7l3ps5ri5r-unit-systemd-tmpfiles-resetup.service.drv' unit-systemd-tmpfiles-resetup.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/m5iwi6jigzhhka4fg48a5vdkd9b03dh5-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/c5ddj5j6j88aw15558234rxzaq62jifn-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jxm6hpbyi9ja04zj89z6qzrwjy2pk16q-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/0ksihnydzfrkng1zyj3i8a7lx7djrxf7-user-units.drv' building '/nix/store/5byjaqq8fvvhkpibph0xvk5464lnadf5-user-units.drv' building '/nix/store/azfpzvqsbpcvzn90kld3s3ncbbb98akx-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/w39mwlz7rkmh9b9n5r45nnmha2dzrd05-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/c5ddj5j6j88aw15558234rxzaq62jifn-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/jxm6hpbyi9ja04zj89z6qzrwjy2pk16q-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/ya9vnsc16n65kc9lhqmjnniq63dvccgk-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0d1mj0bmx5g8050fds6va1rirgqsi2q9-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/azfpzvqsbpcvzn90kld3s3ncbbb98akx-system-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/w39mwlz7rkmh9b9n5r45nnmha2dzrd05-system-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/p2jzgg84l6m667s243pxvh4g45rj25px-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0y05rvglr3ir1qdwfqfhdag7sw0qipkb-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ya9vnsc16n65kc9lhqmjnniq63dvccgk-user-units.drv' building '/nix/store/0d1mj0bmx5g8050fds6va1rirgqsi2q9-system-units.drv' building '/nix/store/6zglsqk8kybhfqkr3s4wd5ch622lb0in-etc.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/6zglsqk8kybhfqkr3s4wd5ch622lb0in-etc.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/icv2xfwy742yz0k6abs6jrlpyq3knp71-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0y05rvglr3ir1qdwfqfhdag7sw0qipkb-etc.drv' building '/nix/store/dchyhwqv07i7klnvd0xqr9dk47fvwd5q-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p2jzgg84l6m667s243pxvh4g45rj25px-etc.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/dchyhwqv07i7klnvd0xqr9dk47fvwd5q-activate.drv' building '/nix/store/km7ql53mknxxbf4wdl8hxgk852s8mzyy-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3m8xb51m5wqvmzmc0996sgckkjammya0-nixos-system-server-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/icv2xfwy742yz0k6abs6jrlpyq3knp71-activate.drv' building '/nix/store/sipyzq1idf290a3gymyv0vz3bmsm4zs8-nixos-system-client-test.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/sipyzq1idf290a3gymyv0vz3bmsm4zs8-nixos-system-client-test.drv' nixos-system-client-test> structuredAttrs is enabled building '/nix/store/km7ql53mknxxbf4wdl8hxgk852s8mzyy-activate.drv' building '/nix/store/cizg7vmw57wicgkr8m15sz4qjsz0mjbi-nixos-system-ca-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3m8xb51m5wqvmzmc0996sgckkjammya0-nixos-system-server-test.drv' nixos-system-server-test> structuredAttrs is enabled building '/nix/store/nvgip3jazl7x6cj7vmlrkajr24lnd403-run-client-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/i6p39l619i0sz52sspw93wikd5xyj9rd-run-server-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/nvgip3jazl7x6cj7vmlrkajr24lnd403-run-client-nspawn.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/i6p39l619i0sz52sspw93wikd5xyj9rd-run-server-nspawn.drv' building '/nix/store/cizg7vmw57wicgkr8m15sz4qjsz0mjbi-nixos-system-ca-test.drv' nixos-system-ca-test> structuredAttrs is enabled building '/nix/store/ylkssa7h2lwmqffi9c3ava0nbnzsa9h8-run-ca-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ylkssa7h2lwmqffi9c3ava0nbnzsa9h8-run-ca-nspawn.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/11ildvvba5fx8n6q5gi52rlj375qxvkh-driverConfiguration.json.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/11ildvvba5fx8n6q5gi52rlj375qxvkh-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/ylgjjxb2hdqff1b5bycn5x9cjgqshir4-nixos-test-driver-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ylgjjxb2hdqff1b5bycn5x9cjgqshir4-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! building '/nix/store/19ikf78pfn230xifcrjzwax5r1pybgij-container-test-run-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/19ikf78pfn230xifcrjzwax5r1pybgij-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> ca: systemd-nspawn running (pid 53) container-test-run-certificates> server: systemd-nspawn running (pid 55) container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> client: systemd-nspawn running (pid 54) container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> server # No journal boot entry found for the specified boot (+0). container-test-run-certificates> ca # No journal boot entry found for the specified boot (+0). container-test-run-certificates> client # No journal boot entry found for the specified boot (+0). container-test-run-certificates> server # [6865739.928343] server systemd-journald[69]: Journal started container-test-run-certificates> server # [6865739.928393] server systemd-journald[69]: Runtime Journal (/run/log/journal/3a82d7c889844eafa808a88cb169518c) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> server # [6865739.948962] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> server # [6865739.950243] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> server # [6865739.951122] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> server # [6865739.959269] server systemd-journald[69]: Time spent on flushing to /var/log/journal/3a82d7c889844eafa808a88cb169518c is 1.252ms for 5 entries. container-test-run-certificates> server # [6865739.959269] server systemd-journald[69]: System Journal (/var/log/journal/3a82d7c889844eafa808a88cb169518c) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [6865739.966951] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [6865739.967236] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [6865739.967327] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [6865739.968312] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [6865739.968360] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6865739.969363] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [6865739.969407] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [6865740.002838] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [6865740.004077] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [6865740.021136] server systemd-tmpfiles[134]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [6865740.021191] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [6865740.021318] server systemd-tmpfiles[134]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [6865740.021436] server systemd-tmpfiles[134]: fchmod() of /var/log/journal/3a82d7c889844eafa808a88cb169518c failed: Operation not permitted container-test-run-certificates> server # [6865740.021616] server systemd-tmpfiles[134]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [6865740.023168] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [6865740.024295] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [6865740.025036] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [6865740.036409] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [6865740.046188] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [6865740.047266] server systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [6865740.058025] server systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [6865740.076135] server systemd[1]: Finished Firewall. container-test-run-certificates> server # [6865740.076802] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [6865740.077113] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [6865740.078229] server systemd[1]: Starting Network Management... container-test-run-certificates> server # [6865740.918751] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [6865739.931559] ca systemd-journald[78]: Journal started container-test-run-certificates> ca # [6865739.931611] ca systemd-journald[78]: Runtime Journal (/run/log/journal/9b4d210a317740c9a60180d45bfe5f55) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> ca # [6865739.938754] ca systemd[1]: Finished Apply Kernel Variables. container-test-run-certificates> ca # [6865739.949147] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [6865739.959976] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [6865739.960900] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [6865739.961577] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [6865739.971908] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/9b4d210a317740c9a60180d45bfe5f55 is 1.556ms for 7 entries. container-test-run-certificates> ca # [6865739.971908] ca systemd-journald[78]: System Journal (/var/log/journal/9b4d210a317740c9a60180d45bfe5f55) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [6865739.980466] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [6865739.981233] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [6865739.981352] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [6865739.982261] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [6865739.982313] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6865739.983272] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [6865739.983310] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [6865740.004516] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [6865740.005541] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [6865740.019074] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [6865740.023771] ca systemd-tmpfiles[142]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [6865740.023973] ca systemd-tmpfiles[142]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [6865740.024119] ca systemd-tmpfiles[142]: fchmod() of /var/log/journal/9b4d210a317740c9a60180d45bfe5f55 failed: Operation not permitted container-test-run-certificates> ca # [6865740.024321] ca systemd-tmpfiles[142]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [6865740.025774] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [6865740.026868] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [6865740.027568] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [6865740.038789] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [6865740.045714] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [6865740.046837] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [6865740.058905] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [6865740.083062] ca systemd[1]: Finished Firewall. container-test-run-certificates> ca # [6865740.083221] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [6865740.083448] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [6865740.084766] ca systemd[1]: Starting Network Management... container-test-run-certificates> ca # [6865740.919320] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> client # [6865739.927978] client systemd-journald[69]: Journal started container-test-run-certificates> client # [6865739.928052] client systemd-journald[69]: Runtime Journal (/run/log/journal/a13411b16a0b46ac8bd3345b7abf90b3) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> client # [6865739.939071] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [6865739.949293] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [6865739.950443] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [6865739.951169] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [6865739.959589] client systemd-journald[69]: Time spent on flushing to /var/log/journal/a13411b16a0b46ac8bd3345b7abf90b3 is 1.306ms for 6 entries. container-test-run-certificates> client # [6865739.959589] client systemd-journald[69]: System Journal (/var/log/journal/a13411b16a0b46ac8bd3345b7abf90b3) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [6865739.966944] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [6865739.967722] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [6865739.967828] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [6865739.968714] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [6865739.968761] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6865739.969727] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [6865739.969768] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [6865740.003096] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [6865740.004305] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [6865740.019907] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [6865740.020703] client systemd-tmpfiles[137]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [6865740.020872] client systemd-tmpfiles[137]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [6865740.020983] client systemd-tmpfiles[137]: fchmod() of /var/log/journal/a13411b16a0b46ac8bd3345b7abf90b3 failed: Operation not permitted container-test-run-certificates> client # [6865740.021154] client systemd-tmpfiles[137]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [6865740.022583] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [6865740.023837] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [6865740.024766] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> client # [6865740.038249] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [6865740.043604] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [6865740.044714] client systemd[1]: Starting Update is Completed... container-test-run-certificates> client # [6865740.055132] client systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [6865740.066740] client systemd[1]: Finished Firewall. container-test-run-certificates> client # [6865740.066897] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [6865740.067360] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [6865740.068620] client systemd[1]: Starting Network Management... container-test-run-certificates> client # [6865740.918815] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [6865741.006415] ca systemd-networkd[196]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6865741.006512] ca systemd-networkd[196]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6865741.019975] ca systemd-networkd[196]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6865741.020164] ca systemd-networkd[196]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6865741.020346] ca systemd-networkd[196]: lo: Link UP container-test-run-certificates> ca # [6865741.020350] ca systemd-networkd[196]: lo: Gained carrier container-test-run-certificates> ca # [6865741.020576] ca systemd-networkd[196]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [6865741.020979] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [6865741.021080] ca systemd-networkd[196]: eth1: Link UP container-test-run-certificates> ca # [6865741.021353] ca systemd-networkd[196]: eth1: Gained carrier container-test-run-certificates> ca # [6865741.022299] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [6865741.092587] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [6865741.179343] server systemd-networkd[187]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6865741.179445] server systemd-networkd[187]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6865741.196516] server systemd-networkd[187]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6865741.196686] server systemd-networkd[187]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6865741.196851] server systemd-networkd[187]: lo: Link UP container-test-run-certificates> server # [6865741.196855] server systemd-networkd[187]: lo: Gained carrier container-test-run-certificates> server # [6865741.197030] server systemd-networkd[187]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [6865741.197447] server systemd[1]: Started Network Management. container-test-run-certificates> server # [6865741.200824] server systemd-networkd[187]: eth1: Link UP container-test-run-certificates> server # [6865741.201083] server systemd-networkd[187]: eth1: Gained carrier container-test-run-certificates> server # [6865741.201506] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [6865741.253997] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [6865741.229805] client systemd-networkd[183]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6865741.229905] client systemd-networkd[183]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6865741.240141] client systemd-networkd[183]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6865741.240309] client systemd-networkd[183]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6865741.240481] client systemd-networkd[183]: lo: Link UP container-test-run-certificates> client # [6865741.240486] client systemd-networkd[183]: lo: Gained carrier container-test-run-certificates> client # [6865741.240689] client systemd-networkd[183]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [6865741.241056] client systemd[1]: Started Network Management. container-test-run-certificates> client # [6865741.241181] client systemd-networkd[183]: eth1: Link UP container-test-run-certificates> client # [6865741.241405] client systemd-networkd[183]: eth1: Gained carrier container-test-run-certificates> client # [6865741.242379] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [6865741.273588] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [6865741.557117] ca systemd-resolved[111]: Positive Trust Anchors: container-test-run-certificates> ca # [6865741.557129] ca systemd-resolved[111]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [6865741.557132] ca systemd-resolved[111]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [6865741.557166] ca systemd-resolved[111]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [6865741.580808] ca systemd-resolved[111]: Using system hostname 'ca'. container-test-run-certificates> ca # [6865741.582604] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [6865741.582702] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [6865741.582785] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [6865741.582844] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [6865741.583141] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [6865741.583197] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6865741.583234] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [6865741.583253] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [6865741.583447] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [6865741.583578] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [6865741.583752] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [6865741.583773] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [6865741.583814] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [6865741.585316] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [6865741.586223] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [6865741.586267] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [6865741.587129] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [6865741.588100] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [6865741.644478] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [6865741.725357] ca systemd[1]: lastlog2-import.service: Failed to spawn executor: No such file or directory container-test-run-certificates> ca # [6865741.725384] ca systemd[1]: lastlog2-import.service: Failed to spawn 'start-post' task: No such file or directory container-test-run-certificates> ca # [6865741.725414] ca systemd[1]: lastlog2-import.service: Failed with result 'resources'. container-test-run-certificates> ca # [6865741.725511] ca systemd[1]: Failed to start Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [6865741.828965] ca acme-setup-privileged[201]: + set -euo pipefail container-test-run-certificates> ca # [6865741.828965] ca acme-setup-privileged[201]: + cd /var/lib/acme container-test-run-certificates> ca # [6865741.828965] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> client # [6865741.629991] client systemd-resolved[103]: Positive Trust Anchors: container-test-run-certificates> client # [6865741.630002] client systemd-resolved[103]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [6865741.630006] client systemd-resolved[103]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [6865741.630042] client systemd-resolved[103]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [6865741.652434] client systemd-resolved[103]: Using system hostname 'client'. container-test-run-certificates> client # [6865741.653830] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [6865741.653915] client systemd[1]: Reached target Network. container-test-run-certificates> client # [6865741.653982] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [6865741.654033] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6865741.654070] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [6865741.654089] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [6865741.654214] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [6865741.654343] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [6865741.654450] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [6865741.654473] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [6865741.654511] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [6865741.655690] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [6865741.656522] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [6865741.657723] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [6865741.674634] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [6865741.861472] client nsncd[189]: Aug 27 10:32:47.914 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [6865741.861534] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [6865741.861597] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [6865741.861655] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [6865741.862855] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [6865741.863645] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [6865741.873835] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [6865741.874981] client systemd[1]: Started Console Getty. container-test-run-certificates> client # [6865741.875027] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [6865741.875046] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> server # [6865741.792363] server systemd-resolved[99]: Positive Trust Anchors: container-test-run-certificates> server # [6865741.792376] server systemd-resolved[99]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [6865741.792379] server systemd-resolved[99]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [6865741.792412] server systemd-resolved[99]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [6865741.815931] server systemd-resolved[99]: Using system hostname 'server'. container-test-run-certificates> server # [6865741.817453] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [6865741.817542] server systemd[1]: Reached target Network. container-test-run-certificates> server # [6865741.817605] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [6865741.817645] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [6865741.817853] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [6865741.817892] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6865741.817910] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [6865741.817927] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [6865741.818052] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [6865741.818155] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [6865741.818261] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [6865741.818287] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [6865741.818320] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [6865741.819588] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [6865741.820464] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [6865741.820501] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [6865741.821298] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [6865741.822492] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [6865741.839847] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [6865741.938335] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> server # [6865741.938335] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [6865741.938730] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> server # [6865741.940075] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> server # [6865741.941733] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [6865741.941760] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> server # [6865741.941760] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [6865741.941760] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> server # [6865741.972949] server nsncd[194]: Aug 27 10:32:48.026 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [6865741.973083] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [6865741.973152] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [6865741.973219] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [6865741.992575] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [6865741.993756] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [6865742.004998] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [6865742.006070] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [6865742.006110] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [6865742.006130] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [6865742.103774] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [6865741.830454] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [6865741.831943] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6865741.831977] ca acme-setup-privileged[201]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [6865741.831977] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6865741.831977] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [6865741.871217] ca nsncd[203]: Aug 27 10:32:47.923 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [6865741.870757] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [6865741.870836] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [6865741.870898] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [6865741.872645] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [6865741.873458] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [6865741.883476] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [6865741.885453] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [6865741.885499] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [6865741.885517] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [6865742.029408] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [6865742.030078] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [6865742.030078] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/gj5k0v2rcdsvmwzrdidpx1a8s0szjk65-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [6865742.030514] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [6865742.040139] ca dbus-broker-launch[205]: Ready container-test-run-certificates> client # [6865741.999651] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [6865742.000455] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [6865742.000455] client dbus-broker-launch[190]: Invalid user-name in /nix/store/zrbrcrcf4ksfm9isn90jq44dzyd6g8f3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [6865742.000916] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [6865742.007822] client dbus-broker-launch[190]: Ready container-test-run-certificates> server # [6865742.104746] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [6865742.104746] server dbus-broker-launch[195]: Invalid user-name in /nix/store/qlm5ds27nygd7kx149cwgpvarjrvks9s-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [6865742.105159] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [6865742.112081] server dbus-broker-launch[195]: Ready container-test-run-certificates> client # [6865742.304150] client systemd-networkd[183]: eth1: Gained IPv6LL container-test-run-certificates> client # [6865742.543605] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [6865742.543760] client systemd[1]: Started User Login Management. container-test-run-certificates> ca # [6865742.555730] ca systemd-logind[233]: New seat seat0. container-test-run-certificates> ca # [6865742.556387] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [6865742.589569] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [6865742.595224] ca acme-setup-start[217]: + set -euo pipefail container-test-run-certificates> ca # [6865742.595482] ca acme-setup-start[217]: + test -e ca/key.pem container-test-run-certificates> ca # [6865742.595482] ca acme-setup-start[217]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [6865742.603148] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [6865742.603328] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [6865742.614892] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [6865742.616374] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> ca # [6865742.756171] ca systemd-networkd[196]: eth1: Gained IPv6LL container-test-run-certificates> client # [6865742.589823] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [6865742.603512] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [6865742.603593] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [6865742.604022] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [6865742.620131] client systemd[1]: Startup finished in 3.101s. container-test-run-certificates> server # [6865742.624895] server systemd-logind[219]: New seat seat0. container-test-run-certificates> server # [6865742.625099] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [6865742.626482] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [6865742.637812] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [6865742.638066] server systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [6865742.693995] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> server # [6865742.694250] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> server # [6865742.694250] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [6865742.731062] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [6865742.732649] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server # [6865742.756230] server systemd-networkd[187]: eth1: Gained IPv6LL container-test-run-certificates> ca # [6865742.956494] ca step-ca[204]: badger 2026/08/27 10:32:49 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [6865742.966037] ca step-ca[204]: 2026/08/27 10:32:49 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [6865742.973202] ca step-ca[204]: 2026/08/27 10:32:49 Starting Smallstep CA/0.30.2 (linux/arm64) container-test-run-certificates> ca # [6865742.973202] ca step-ca[204]: 2026/08/27 10:32:49 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [6865742.973202] ca step-ca[204]: 2026/08/27 10:32:49 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [6865742.973202] ca step-ca[204]: 2026/08/27 10:32:49 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [6865742.973202] ca step-ca[204]: 2026/08/27 10:32:49 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [6865742.973202] ca step-ca[204]: 2026/08/27 10:32:49 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [6865742.973382] ca step-ca[204]: 2026/08/27 10:32:49 X.509 Root Fingerprint: a97ce9440c81c1aac50ade6eee6049e3bf7db6ae1e5cfda05f46dcd1f4c24fa4 container-test-run-certificates> ca # [6865742.973687] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [6865742.974058] ca step-ca[204]: 2026/08/27 10:32:49 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> ca # [6865743.629758] ca acme-ca.foo-start[254]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6865743.632777] ca acme-ca.foo-start[254]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [6865743.632820] ca acme-ca.foo-start[254]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [6865743.644324] ca acme-ca.foo-start[292]: + cd ca.foo container-test-run-certificates> ca # [6865743.644541] ca acme-ca.foo-start[292]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [6865743.645677] ca acme-ca.foo-start[293]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [6865743.645897] ca acme-ca.foo-start[292]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [6865743.647314] ca acme-ca.foo-start[292]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [6865743.647597] ca acme-ca.foo-start[254]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [6865743.649133] ca acme-ca.foo-start[254]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [6865743.650629] ca acme-ca.foo-start[254]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6865743.652103] ca acme-ca.foo-start[254]: + for fixpath in out certificates container-test-run-certificates> ca # [6865743.652103] ca acme-ca.foo-start[254]: + '[' -d out ']' container-test-run-certificates> ca # [6865743.652146] ca acme-ca.foo-start[254]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6865743.654344] ca acme-ca.foo-start[254]: + chown -R acme:nginx out container-test-run-certificates> ca # [6865743.657214] ca acme-ca.foo-start[254]: + for fixpath in out certificates container-test-run-certificates> ca # [6865743.657239] ca acme-ca.foo-start[254]: + '[' -d certificates ']' container-test-run-certificates> ca # [6865743.662718] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [6865743.664113] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> server # [6865743.934015] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6865743.936443] server acme-test.foo-start[245]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6865743.936490] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6865743.947792] server acme-test.foo-start[255]: + cd test.foo container-test-run-certificates> server # [6865743.948191] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6865743.949241] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6865743.949448] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6865743.950555] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6865743.950769] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6865743.952263] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6865743.953653] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6865743.955119] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [6865743.955145] server acme-test.foo-start[245]: + '[' -d out ']' container-test-run-certificates> server # [6865743.955145] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6865743.956615] server acme-test.foo-start[245]: + chown -R acme:nginx out container-test-run-certificates> server # [6865743.959006] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [6865743.959037] server acme-test.foo-start[245]: + '[' -d certificates ']' container-test-run-certificates> server # [6865744.000364] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6865744.001769] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [6865745.354737] ca nginx-pre-start[304]: nginx: the configuration file /nix/store/k6vn04kvvc5wrilzgx0i5sa6zfs4lfi9-nginx.conf syntax is ok container-test-run-certificates> ca # [6865745.355295] ca nginx-pre-start[304]: nginx: configuration file /nix/store/k6vn04kvvc5wrilzgx0i5sa6zfs4lfi9-nginx.conf test is successful container-test-run-certificates> ca # [6865745.360762] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [6865745.361125] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [6865745.362332] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> server # [6865745.438118] server nginx-pre-start[267]: nginx: the configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf syntax is ok container-test-run-certificates> server # [6865745.438482] server nginx-pre-start[267]: nginx: configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf test is successful container-test-run-certificates> server # [6865745.442657] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [6865745.443018] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [6865745.444173] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [6865746.660056] ca acme-order-renew-ca.foo-start[307]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6865746.662472] ca acme-order-renew-ca.foo-start[307]: + set -euo pipefail container-test-run-certificates> ca # [6865746.662548] ca acme-order-renew-ca.foo-start[307]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6865746.662660] ca acme-order-renew-ca.foo-start[307]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6865746.663800] ca acme-order-renew-ca.foo-start[307]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [6865746.694135] ca acme-order-renew-ca.foo-start[318]: 2026/08/27 10:32:52 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [6865746.694458] ca acme-order-renew-ca.foo-start[318]: 2026/08/27 10:32:52 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [6865746.719731] ca step-ca[204]: time="2026-08-27T10:32:52Z" level=info duration="169.722µs" duration-ns=169722 fields.time="2026-08-27T10:32:52Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=31cef6ca-31fd-44b2-a01a-dc305a838f0d response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6865746.720130] ca acme-order-renew-ca.foo-start[318]: 2026/08/27 10:32:52 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [6865746.837755] ca step-ca[204]: time="2026-08-27T10:32:52Z" level=info duration=117.416272ms duration-ns=117416272 fields.time="2026-08-27T10:32:52Z" method=HEAD name=ca nonce=YU12VWh3TFRYbXd4S3pBOUNaeUhPMVlmQlFyR2RlQk0 path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=2d9ff2ef-03f2-47a4-bbe4-5a7834b46bdc size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6865746.842815] ca step-ca[204]: time="2026-08-27T10:32:52Z" level=info duration=4.299061ms duration-ns=4299061 fields.time="2026-08-27T10:32:52Z" method=POST name=ca nonce=QTJyUHNZbWVOVTBrQldwa2wwS1UwdThqQTR6WXgyWTk path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=49331c9b-47f5-4fb4-a834-b944d7ecbb68 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/4z4Tr4TeIgYnnJQVdWkRhj5td5mffjEF/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6865746.843168] ca acme-order-renew-ca.foo-start[318]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [6865746.843168] ca acme-order-renew-ca.foo-start[318]: Your account credentials have been saved in your container-test-run-certificates> ca # [6865746.843168] ca acme-order-renew-ca.foo-start[318]: configuration directory at "accounts". container-test-run-certificates> ca # [6865746.843168] ca acme-order-renew-ca.foo-start[318]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [6865746.843168] ca acme-order-renew-ca.foo-start[318]: configuration directory will also contain private keys container-test-run-certificates> ca # [6865746.843168] ca acme-order-renew-ca.foo-start[318]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [6865746.843168] ca acme-order-renew-ca.foo-start[318]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [6865746.843302] ca acme-order-renew-ca.foo-start[318]: 2026/08/27 10:32:52 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [6865746.846504] ca step-ca[204]: time="2026-08-27T10:32:52Z" level=info duration=2.82772ms duration-ns=2827720 fields.time="2026-08-27T10:32:52Z" method=POST name=ca nonce=NklSUDBqNWo2WlFVMUxlV2N0VW82MXFaOVFDN2hoQlo path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=908cc24e-3d52-47d1-96b2-76e625bd93aa response="{\"id\":\"bGHbcgvQCXzdaratx027u8o2LcNsjfyG\",\"status\":\"pending\",\"expires\":\"2026-08-28T10:32:52Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-27T10:31:52Z\",\"notAfter\":\"2026-11-25T10:32:52Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/wZ0DMhrOWMpSGopjfjB5BErS7mIOD0L1\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/bGHbcgvQCXzdaratx027u8o2LcNsjfyG/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6865746.908177] ca step-ca[204]: time="2026-08-27T10:32:52Z" level=info duration=4.813188ms duration-ns=4813188 fields.time="2026-08-27T10:32:52Z" method=POST name=ca nonce=WFB6emR6aVIwRjZ1bGp6elE4ZzFPZEVTODdnQm11YWE path=/acme/acme/authz/wZ0DMhrOWMpSGopjfjB5BErS7mIOD0L1 protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=ff870e3a-c496-4260-959f-360b1f557739 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"RwonZFaa5AE0hC6sdhzdn7IZJSjkw90A\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/wZ0DMhrOWMpSGopjfjB5BErS7mIOD0L1/kPcCi4SG9U3FRkcevo1O4R5Me4cuJimq\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"RwonZFaa5AE0hC6sdhzdn7IZJSjkw90A\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/wZ0DMhrOWMpSGopjfjB5BErS7mIOD0L1/QkhP5mzjVZEqWDuQzN66oLHlFSfrWunG\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"RwonZFaa5AE0hC6sdhzdn7IZJSjkw90A\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/wZ0DMhrOWMpSGopjfjB5BErS7mIOD0L1/Jt6wP8cdhFcWTqfhUU8ZI4Gagvaankoh\"}],\"wildcard\":false,\"expires\":\"2026-08-28T10:32:52Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6865746.908472] ca acme-order-renew-ca.foo-start[318]: 2026/08/27 10:32:52 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/wZ0DMhrOWMpSGopjfjB5BErS7mIOD0L1 container-test-run-certificates> ca # [6865746.908472] ca acme-order-renew-ca.foo-start[318]: 2026/08/27 10:32:52 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [6865746.908472] ca acme-order-renew-ca.foo-start[318]: 2026/08/27 10:32:52 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [6865746.908547] ca acme-order-renew-ca.foo-start[318]: 2026/08/27 10:32:52 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [6865746.913456] ca step-ca[204]: time="2026-08-27T10:32:52Z" level=info duration=4.455463ms duration-ns=4455463 fields.time="2026-08-27T10:32:52Z" method=POST name=ca nonce=TVdoV0g4d3E1QnNEdHlSaGpTdmVtZ2JXZDFQZGF0ZkE path=/acme/acme/challenge/wZ0DMhrOWMpSGopjfjB5BErS7mIOD0L1/QkhP5mzjVZEqWDuQzN66oLHlFSfrWunG protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=5204cc07-2981-4533-983d-afb59c2d6c08 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"RwonZFaa5AE0hC6sdhzdn7IZJSjkw90A\",\"validated\":\"2026-08-27T10:32:52Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/wZ0DMhrOWMpSGopjfjB5BErS7mIOD0L1/QkhP5mzjVZEqWDuQzN66oLHlFSfrWunG\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6865746.913708] ca acme-order-renew-ca.foo-start[318]: 2026/08/27 10:32:52 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [6865746.913784] ca acme-order-renew-ca.foo-start[318]: 2026/08/27 10:32:52 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [6865746.689484] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6865746.691915] server acme-order-renew-test.foo-start[270]: + set -euo pipefail container-test-run-certificates> server # [6865746.691991] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6865746.692123] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6865746.693223] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6865746.707861] server acme-order-renew-test.foo-start[282]: 2026/08/27 10:32:52 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [6865746.708185] server acme-order-renew-test.foo-start[282]: 2026/08/27 10:32:52 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> server # [6865746.736178] server acme-order-renew-test.foo-start[282]: 2026/08/27 10:32:52 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [6865746.736632] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6865746.736632] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6865746.736632] server acme-order-renew-test.foo-start[270]: + exit 10 container-test-run-certificates> server # [6865746.739802] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [6865746.739896] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [6865746.740209] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [6865746.740488] server systemd[1]: Startup finished in 7.250s. container-test-run-certificates> ca # [6865746.919005] ca step-ca[204]: time="2026-08-27T10:32:52Z" level=info duration=4.328262ms duration-ns=4328262 fields.time="2026-08-27T10:32:52Z" method=POST name=ca nonce=dk9WZEtiWVRCbnhOdVJHQVpTQ3J0Tmc1eVhqcWRQUk8 path=/acme/acme/order/bGHbcgvQCXzdaratx027u8o2LcNsjfyG/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=d9bccd74-e7f6-44f8-afa9-dbc93e274b4e response="{\"id\":\"bGHbcgvQCXzdaratx027u8o2LcNsjfyG\",\"status\":\"valid\",\"expires\":\"2026-08-28T10:32:52Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-27T10:31:52Z\",\"notAfter\":\"2026-11-25T10:32:52Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/wZ0DMhrOWMpSGopjfjB5BErS7mIOD0L1\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/bGHbcgvQCXzdaratx027u8o2LcNsjfyG/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/W4dNYqPyYpisluyp2oJehWE8G5KorjlT\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6865746.920491] ca step-ca[204]: time="2026-08-27T10:32:52Z" level=info certificate="MIIB0jCCAXmgAwIBAgIQQgnIfrUyZv6PQs3eR2bT3TAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MjcxMDMxNTJaFw0yNjExMjUxMDMyNTJaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABFgwuRBqTR+0QhruZiySjPnHwd5yboJ5E4SmfIgMNGlFEHHtndD7iJSgrbyzgA0PZ6xS9NF+DEI5xS9KjBVIgi6jgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQU5AuRkk3lOSg2UWLYZKdJXC0ap8owHwYDVR0jBBgwFoAUdxIN6TH+n631IsDUCbskK/v24VowEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNHADBEAiAZ2RCfXvGB5JmxQ1jlsVFA8MAmO5dtBDrSs6Elg7MfDQIgKQN3nV0Maptep/Y0+LjEAkk9rJL++azIPiwR1kMUzP4=" duration="902.773µs" duration-ns=902773 fields.time="2026-08-27T10:32:52Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=OThFR0gwenBDMG1wTzVGeHpJNGFiUTVvT2hEUXRtejA path=/acme/acme/certificate/W4dNYqPyYpisluyp2oJehWE8G5KorjlT protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=2863ca75-c5fe-4fc7-9461-74c5b11510b9 sans="map[dns:[ca.foo]]" serial=87779844914278187637520842656670208989 size=1340 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-27T10:31:52Z" valid-to="2026-11-25T10:32:52Z" container-test-run-certificates> ca # [6865746.920713] ca acme-order-renew-ca.foo-start[318]: 2026/08/27 10:32:52 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [6865746.928212] ca acme-order-renew-ca.foo-start[307]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6865746.929772] ca acme-order-renew-ca.foo-start[307]: + touch out/acme-success container-test-run-certificates> ca # [6865746.931106] ca acme-order-renew-ca.foo-start[307]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6865746.932154] ca acme-order-renew-ca.foo-start[307]: + touch out/renewed container-test-run-certificates> ca # [6865746.933429] ca acme-order-renew-ca.foo-start[307]: + echo Installing new certificate container-test-run-certificates> ca # [6865746.933429] ca acme-order-renew-ca.foo-start[307]: Installing new certificate container-test-run-certificates> ca # [6865746.933469] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6865746.934708] ca acme-order-renew-ca.foo-start[349]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [6865746.934903] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [6865746.936271] ca acme-order-renew-ca.foo-start[350]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [6865746.936478] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [6865746.937940] ca acme-order-renew-ca.foo-start[351]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [6865746.938158] ca acme-order-renew-ca.foo-start[307]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [6865746.939646] ca acme-order-renew-ca.foo-start[307]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6865746.941268] ca acme-order-renew-ca.foo-start[307]: + for fixpath in out certificates container-test-run-certificates> ca # [6865746.941268] ca acme-order-renew-ca.foo-start[307]: + '[' -d out ']' container-test-run-certificates> ca # [6865746.941320] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6865746.942739] ca acme-order-renew-ca.foo-start[307]: + chown -R acme:nginx out container-test-run-certificates> ca # [6865746.944962] ca acme-order-renew-ca.foo-start[307]: + for fixpath in out certificates container-test-run-certificates> ca # [6865746.944962] ca acme-order-renew-ca.foo-start[307]: + '[' -d certificates ']' container-test-run-certificates> ca # [6865746.945040] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6865746.946346] ca acme-order-renew-ca.foo-start[307]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6865746.948459] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6865747.071795] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [6865747.076172] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6865747.076366] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca # [6865747.641767] ca nginx[367]: nginx: the configuration file /nix/store/k6vn04kvvc5wrilzgx0i5sa6zfs4lfi9-nginx.conf syntax is ok container-test-run-certificates> ca # [6865747.642302] ca nginx[367]: nginx: configuration file /nix/store/k6vn04kvvc5wrilzgx0i5sa6zfs4lfi9-nginx.conf test is successful container-test-run-certificates> ca # [6865749.002490] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [6865749.002850] ca systemd[1]: Startup finished in 9.469s. container-test-run-certificates> ca # [6865749.126019] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 8.36 seconds) container-test-run-certificates> ca # [6865750.106064] ca acme-order-renew-ca.foo-start[382]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6865750.108602] ca acme-order-renew-ca.foo-start[382]: + set -euo pipefail container-test-run-certificates> ca # [6865750.108681] ca acme-order-renew-ca.foo-start[382]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6865750.108798] ca acme-order-renew-ca.foo-start[382]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6865750.109818] ca acme-order-renew-ca.foo-start[382]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [6865750.109840] ca acme-order-renew-ca.foo-start[382]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [6865750.110745] ca acme-order-renew-ca.foo-start[390]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [6865750.113084] ca acme-order-renew-ca.foo-start[382]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [6865750.113138] ca acme-order-renew-ca.foo-start[382]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [6865750.153854] ca step-ca[204]: time="2026-08-27T10:32:56Z" level=info duration="48.44µs" duration-ns=48440 fields.time="2026-08-27T10:32:56Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=16420740-05ec-4111-90e7-057e6effe25f response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6865750.154217] ca acme-order-renew-ca.foo-start[391]: 2026/08/27 10:32:56 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [6865750.154217] ca acme-order-renew-ca.foo-start[391]: 2026/08/27 10:32:56 [INFO] [ca.foo] The certificate expires at 2026-11-25T10:32:52Z, the renewal can be performed in 1439h59m35.792630615s: no renewal. container-test-run-certificates> ca # [6865750.154692] ca acme-order-renew-ca.foo-start[382]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6865750.156345] ca acme-order-renew-ca.foo-start[382]: + touch out/acme-success container-test-run-certificates> ca # [6865750.157730] ca acme-order-renew-ca.foo-start[382]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6865750.158771] ca acme-order-renew-ca.foo-start[382]: + for fixpath in out certificates container-test-run-certificates> ca # [6865750.159039] ca acme-order-renew-ca.foo-start[382]: + '[' -d out ']' container-test-run-certificates> ca # [6865750.159039] ca acme-order-renew-ca.foo-start[382]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6865750.161733] ca acme-order-renew-ca.foo-start[382]: + chown -R acme:nginx out container-test-run-certificates> ca # [6865750.164315] ca acme-order-renew-ca.foo-start[382]: + for fixpath in out certificates container-test-run-certificates> ca # [6865750.164346] ca acme-order-renew-ca.foo-start[382]: + '[' -d certificates ']' container-test-run-certificates> ca # [6865750.164346] ca acme-order-renew-ca.foo-start[382]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6865750.165706] ca acme-order-renew-ca.foo-start[382]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6865750.168334] ca acme-order-renew-ca.foo-start[382]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6865750.325591] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6865750.325919] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [6865753.349360] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6865753.349529] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [6865753.350558] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [6865753.353477] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 1.02 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [112 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 27 10:32:49 2026 GMT container-test-run-certificates> * expire date: Sep 26 10:32:49 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 73a0fa container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6865754.327047] server acme-test.foo-start[315]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6865754.329676] server acme-test.foo-start[315]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6865754.329722] server acme-test.foo-start[315]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6865754.340481] server acme-test.foo-start[325]: + cd test.foo container-test-run-certificates> server # [6865754.340839] server acme-test.foo-start[325]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6865754.342010] server acme-test.foo-start[326]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6865754.342278] server acme-test.foo-start[325]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6865754.343508] server acme-test.foo-start[325]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6865754.343794] server acme-test.foo-start[315]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6865754.345470] server acme-test.foo-start[315]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6865754.347022] server acme-test.foo-start[315]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6865754.348787] server acme-test.foo-start[315]: + for fixpath in out certificates container-test-run-certificates> server # [6865754.348808] server acme-test.foo-start[315]: + '[' -d out ']' container-test-run-certificates> server # [6865754.348824] server acme-test.foo-start[315]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6865754.350426] server acme-test.foo-start[315]: + chown -R acme:nginx out container-test-run-certificates> server # [6865754.354385] server acme-test.foo-start[315]: + for fixpath in out certificates container-test-run-certificates> server # [6865754.354424] server acme-test.foo-start[315]: + '[' -d certificates ']' container-test-run-certificates> server # [6865754.358059] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6865754.361107] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 27 10:32:49 2026 GMT container-test-run-certificates> * expire date: Sep 26 10:32:49 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 73a0fa container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6865755.436312] server acme-order-renew-test.foo-start[333]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6865755.439034] server acme-order-renew-test.foo-start[333]: + set -euo pipefail container-test-run-certificates> server # [6865755.439113] server acme-order-renew-test.foo-start[333]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6865755.439231] server acme-order-renew-test.foo-start[333]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6865755.440333] server acme-order-renew-test.foo-start[333]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6865755.480646] server acme-order-renew-test.foo-start[341]: 2026/08/27 10:33:01 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [6865755.529557] server acme-order-renew-test.foo-start[341]: !!!! HEADS UP !!!! container-test-run-certificates> server # [6865755.529557] server acme-order-renew-test.foo-start[341]: Your account credentials have been saved in your container-test-run-certificates> server # [6865755.529557] server acme-order-renew-test.foo-start[341]: configuration directory at "accounts". container-test-run-certificates> server # [6865755.529557] server acme-order-renew-test.foo-start[341]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [6865755.529557] server acme-order-renew-test.foo-start[341]: configuration directory will also contain private keys container-test-run-certificates> server # [6865755.529557] server acme-order-renew-test.foo-start[341]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [6865755.529557] server acme-order-renew-test.foo-start[341]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [6865755.529759] server acme-order-renew-test.foo-start[341]: 2026/08/27 10:33:01 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [6865755.602046] server acme-order-renew-test.foo-start[341]: 2026/08/27 10:33:01 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/uf3sKu7DMRA1vydCHwXLbJgfH6PKl6nb container-test-run-certificates> server # [6865755.602046] server acme-order-renew-test.foo-start[341]: 2026/08/27 10:33:01 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [6865755.602046] server acme-order-renew-test.foo-start[341]: 2026/08/27 10:33:01 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [6865755.602046] server acme-order-renew-test.foo-start[341]: 2026/08/27 10:33:01 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [6865755.610878] server acme-order-renew-test.foo-start[341]: 2026/08/27 10:33:01 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [6865755.610951] server acme-order-renew-test.foo-start[341]: 2026/08/27 10:33:01 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [6865755.632225] server acme-order-renew-test.foo-start[341]: 2026/08/27 10:33:01 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [6865755.640716] server acme-order-renew-test.foo-start[333]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [6865755.642429] server acme-order-renew-test.foo-start[333]: + touch out/acme-success container-test-run-certificates> server # [6865755.644108] server acme-order-renew-test.foo-start[333]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6865755.645151] server acme-order-renew-test.foo-start[333]: + touch out/renewed container-test-run-certificates> server # [6865755.646603] server acme-order-renew-test.foo-start[333]: + echo Installing new certificate container-test-run-certificates> server # [6865755.646603] server acme-order-renew-test.foo-start[333]: Installing new certificate container-test-run-certificates> server # [6865755.646646] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6865755.648143] server acme-order-renew-test.foo-start[371]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [6865755.648390] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [6865755.649786] server acme-order-renew-test.foo-start[372]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [6865755.650024] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [6865755.651443] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [6865755.651655] server acme-order-renew-test.foo-start[333]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [6865755.653168] server acme-order-renew-test.foo-start[333]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6865755.654694] server acme-order-renew-test.foo-start[333]: + for fixpath in out certificates container-test-run-certificates> server # [6865755.654717] server acme-order-renew-test.foo-start[333]: + '[' -d out ']' container-test-run-certificates> server # [6865755.654717] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6865755.656078] server acme-order-renew-test.foo-start[333]: + chown -R acme:nginx out container-test-run-certificates> server # [6865755.658520] server acme-order-renew-test.foo-start[333]: + for fixpath in out certificates container-test-run-certificates> server # [6865755.658566] server acme-order-renew-test.foo-start[333]: + '[' -d certificates ']' container-test-run-certificates> server # [6865755.658566] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [6865755.659997] server acme-order-renew-test.foo-start[333]: + chown -R acme:nginx certificates container-test-run-certificates> server # [6865755.663195] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6865755.480265] ca step-ca[204]: time="2026-08-27T10:33:01Z" level=info duration="43.721µs" duration-ns=43721 fields.time="2026-08-27T10:33:01Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=6e05be50-7680-4085-b7fd-a57783e1d0f4 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6865755.521704] ca step-ca[204]: time="2026-08-27T10:33:01Z" level=info duration=38.885994ms duration-ns=38885994 fields.time="2026-08-27T10:33:01Z" method=HEAD name=ca nonce=VHRPME5BRTdKYmJGblRyMFVzUkFia0l5bmx0VUhEU3c path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=deeb5965-6b42-4be3-bcad-f5aa64cc203f size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6865755.529038] ca step-ca[204]: time="2026-08-27T10:33:01Z" level=info duration=5.110193ms duration-ns=5110193 fields.time="2026-08-27T10:33:01Z" method=POST name=ca nonce=ajV3dW82bFhVeUFnWk5ySWJCT1BzQXpIZ0lzd1lVbDI path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=65de9596-b7cf-4b90-a7b9-ab829722911f response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/wOCwhb3E1W1w5JJ3ed6nne0Q2phPgpzo/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6865755.537101] ca step-ca[204]: time="2026-08-27T10:33:01Z" level=info duration=4.547865ms duration-ns=4547865 fields.time="2026-08-27T10:33:01Z" method=POST name=ca nonce=cUE4c0VuR0F0VlM5WTJsTDV2TkRVdVlFWGZpZ1Q2SG0 path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=eb2b2186-dfab-4894-ba96-a38851099852 response="{\"id\":\"6U1024JYhDg12DHetAGQZd7jqiu2uKvB\",\"status\":\"pending\",\"expires\":\"2026-08-28T10:33:01Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-27T10:32:01Z\",\"notAfter\":\"2026-11-25T10:33:01Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/uf3sKu7DMRA1vydCHwXLbJgfH6PKl6nb\"],\"finalize\":\"https://ca.foo/acme/acme/order/6U1024JYhDg12DHetAGQZd7jqiu2uKvB/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6865755.601502] ca step-ca[204]: time="2026-08-27T10:33:01Z" level=info duration=4.805668ms duration-ns=4805668 fields.time="2026-08-27T10:33:01Z" method=POST name=ca nonce=ZnJuSHFaRlpQYUFBRXJ1ZU1RV2F4SWxxN1FlVXZ3ZWs path=/acme/acme/authz/uf3sKu7DMRA1vydCHwXLbJgfH6PKl6nb protocol=HTTP/1.1 referer= remote-address="::1" request-id=07b33a8e-0948-41b8-864c-b51dbcdefbd0 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"nzVX4SxfejFF3RT2ynseBk3HYUepspcT\",\"url\":\"https://ca.foo/acme/acme/challenge/uf3sKu7DMRA1vydCHwXLbJgfH6PKl6nb/pqM0ZMKvlC0ePMaLAg1UMK8nbGIYMa8r\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"nzVX4SxfejFF3RT2ynseBk3HYUepspcT\",\"url\":\"https://ca.foo/acme/acme/challenge/uf3sKu7DMRA1vydCHwXLbJgfH6PKl6nb/4F92IYz6zjUiC65RZQBXcOBXM2radd3N\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"nzVX4SxfejFF3RT2ynseBk3HYUepspcT\",\"url\":\"https://ca.foo/acme/acme/challenge/uf3sKu7DMRA1vydCHwXLbJgfH6PKl6nb/71F41CynYO5umgrdHW37ZzyqTkiKxIiG\"}],\"wildcard\":false,\"expires\":\"2026-08-28T10:33:01Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6865755.610400] ca step-ca[204]: time="2026-08-27T10:33:01Z" level=info duration=5.358156ms duration-ns=5358156 fields.time="2026-08-27T10:33:01Z" method=POST name=ca nonce=UUZRNWNKVFY0V24yQ2tFVW1uMFlEclhtVFdiaDl6QUM path=/acme/acme/challenge/uf3sKu7DMRA1vydCHwXLbJgfH6PKl6nb/4F92IYz6zjUiC65RZQBXcOBXM2radd3N protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=41398a7e-016d-459a-bc10-3310ed6a11f5 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"nzVX4SxfejFF3RT2ynseBk3HYUepspcT\",\"validated\":\"2026-08-27T10:33:01Z\",\"url\":\"https://ca.foo/acme/acme/challenge/uf3sKu7DMRA1vydCHwXLbJgfH6PKl6nb/4F92IYz6zjUiC65RZQBXcOBXM2radd3N\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6865755.622136] ca step-ca[204]: time="2026-08-27T10:33:01Z" level=info duration=8.818205ms duration-ns=8818205 fields.time="2026-08-27T10:33:01Z" method=POST name=ca nonce=T1MxQzNEeW9oWkdRT0FNS2xOQTBSU21IRDdEWnROeHQ path=/acme/acme/order/6U1024JYhDg12DHetAGQZd7jqiu2uKvB/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=83147eeb-5676-4d9e-8f4a-402f50a61df4 response="{\"id\":\"6U1024JYhDg12DHetAGQZd7jqiu2uKvB\",\"status\":\"valid\",\"expires\":\"2026-08-28T10:33:01Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-27T10:32:01Z\",\"notAfter\":\"2026-11-25T10:33:01Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/uf3sKu7DMRA1vydCHwXLbJgfH6PKl6nb\"],\"finalize\":\"https://ca.foo/acme/acme/order/6U1024JYhDg12DHetAGQZd7jqiu2uKvB/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/8tlzKRRxAvKWTaLXAjnSocxnhEpLxf9X\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6865755.631502] ca step-ca[204]: time="2026-08-27T10:33:01Z" level=info certificate="MIIB2DCCAX2gAwIBAgIQNHNlSu0etGgBKEc8AiPjDTAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MjcxMDMyMDFaFw0yNjExMjUxMDMzMDFaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEq6X66uCky28wl0hC8egQkpAr/4Q5klC/CLkK3+nXhGM3u+TFxItdf14NlTx2yKzqqdot7YFUNYH/Q+N0w3twCaOBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBTNqn2+Hq78HAIuvYAd6Kd0L9kPcDAfBgNVHSMEGDAWgBR3Eg3pMf6frfUiwNQJuyQr+/bhWjATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSQAwRgIhAKrBsDEw77HbRh+sYi9Q1ocnSnwjx4B/UhDQZs2fDrGEAiEAp6LoUJFTH+9OUVOXuUWoZZEafPEA2AZNjLSSmRxdC/0=" duration=4.363982ms duration-ns=4363982 fields.time="2026-08-27T10:33:01Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=Z1BNVm10YkVaUndtQlRFMW83T0psaUtZYXNIUVJqbHI path=/acme/acme/certificate/8tlzKRRxAvKWTaLXAjnSocxnhEpLxf9X protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=5e8b4e5a-934a-4247-8d37-3c866179b907 sans="map[dns:[test.foo]]" serial=69719024379186192489311690088182440717 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-27T10:32:01Z" valid-to="2026-11-25T10:33:01Z" container-test-run-certificates> server # [6865755.818458] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [6865755.823292] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6865755.823483] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 27 10:32:49 2026 GMT container-test-run-certificates> * expire date: Sep 26 10:32:49 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 73a0fa container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6865756.549434] server nginx[389]: nginx: the configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf syntax is ok container-test-run-certificates> server # [6865756.549820] server nginx[389]: nginx: configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf test is successful container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 27 10:32:49 2026 GMT container-test-run-certificates> * expire date: Sep 26 10:32:49 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 73a0fa container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6865757.454404] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [931 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [80 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 27 10:32:01 2026 GMT container-test-run-certificates> * expire date: Nov 25 10:33:01 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 56622 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 815 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 4.21 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> 34:73:65:4a:ed:1e:b4:68:01:28:47:3c:02:23:e3:0d container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Aug 27 10:32:01 2026 GMT container-test-run-certificates> Not After : Nov 25 10:33:01 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:ab:a5:fa:ea:e0:a4:cb:6f:30:97:48:42:f1:e8: container-test-run-certificates> 10:92:90:2b:ff:84:39:92:50:bf:08:b9:0a:df:e9: container-test-run-certificates> d7:84:63:37:bb:e4:c5:c4:8b:5d:7f:5e:0d:95:3c: container-test-run-certificates> 76:c8:ac:ea:a9:da:2d:ed:81:54:35:81:ff:43:e3: container-test-run-certificates> 74:c3:7b:70:09 container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> CD:AA:7D:BE:1E:AE:FC:1C:02:2E:BD:80:1D:E8:A7:74:2F:D9:0F:70 container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> 77:12:0D:E9:31:FE:9F:AD:F5:22:C0:D4:09:BB:24:2B:FB:F6:E1:5A container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:46:02:21:00:aa:c1:b0:31:30:ef:b1:db:46:1f:ac:62:2f: container-test-run-certificates> 50:d6:87:27:4a:7c:23:c7:80:7f:52:10:d0:66:cd:9f:0e:b1: container-test-run-certificates> 84:02:21:00:a7:a2:e8:50:91:53:1f:ef:4e:51:53:97:b9:45: container-test-run-certificates> a8:65:91:1a:7c:f1:00:d8:06:4d:8c:b4:92:99:1c:5d:0b:fd container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.04 seconds) container-test-run-certificates> (finished: run the VM test script, in 19.64 seconds) container-test-run-certificates> test script finished in 19.69s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 53) container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> kill NspawnMachine (pid 55) container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.49 seconds) container-test-run-certificates> Container server terminated by signal KILL. post-build step Upload to niks3: ok time=2026-08-27T10:33:05.745Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-27T10:33:06.119Z level=INFO msg="Uploading 1 narinfos" time=2026-08-27T10:33:06.334Z level=INFO msg="Upload complete. (648ms)"