these 97 derivations will be built: /nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv /nix/store/05gw6yyrzlhj5mg2zfdp7m6ng902jxsr-cacert-blocklist.txt.drv /nix/store/a0fjq2lmggzgmdqmw61ppvcrk0ns78lv-firewall-start.drv /nix/store/05l61ybxsccw6az5wkv1yr6i1znk7973-firewall-reload.drv /nix/store/5l0dhhj9lqdgym7sdhqkn96v42fsrm6j-cacert-extra-certificates-bundle.crt.drv /nix/store/07ymllsf1g692gqgjw43jm91gzrrg5c1-nss-cacert-3.126.drv /nix/store/0dazh70qwhpgsvnf5ws7zfdbrmzlhg6l-users-groups.json.drv /nix/store/p2rvqr10dlfk1iandnvbfs18rm4b6qnv-ca.json.drv /nix/store/5zbn6y0g7by9nds3xvc1mb5lqcm69nf6-X-Restart-Triggers-step-ca.drv /nix/store/0j80qag3hfmw2hdfz2jbx6zczxdjyzxf-unit-step-ca.service.drv /nix/store/nizw79x2jpmvbgjpxlk3igyhh8vakhbw-nginx.conf.drv /nix/store/0v9pkxmlzs6bwbhd56wbhlj22wpgnw2p-unit-script-nginx-pre-start.drv /nix/store/1d3j7hsfkvw9p8lljs95cndmilri60h0-unit-40-eth1.network.drv /nix/store/i9dp3pxhd8i3wwisb7p3hyb99pazmsf8-system-path.drv /nix/store/7rfsbl4zr4jzakgvvbz6aqcgka7wmk3j-dbus-1.drv /nix/store/jblkhwl4fxs92xx6s3wc0mf8fhzq7rzy-unit-nix-daemon.service.drv /nix/store/frqjymwgfg7lwzcla6s2c5d36jj3zsnn-X-Restart-Triggers-dbus-broker.drv /nix/store/wbjwlajk0a2j6c39hgmd5g319ljv0wn9-unit-dbus-broker.service.drv /nix/store/f3iwwyk5n7r9pzfgsfpa9dgnlp77zcwm-system-units.drv /nix/store/lylvrr8cbsf0k9h5jlbg5h2n5bhljsq8-extra-hosts.drv /nix/store/i24rhm6bgwms3ib5b4b2cqgl5sxm2n6c-hosts.drv /nix/store/g3pbjwbabwkr9akggrlfgxyx1fyfz5lf-unit-dbus-broker.service.drv /nix/store/qgciair8g6hxi7i3lispy9i41fycaqgq-user-units.drv /nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv /nix/store/6v4pv35n2p6nf77sib090l1kax5ywl1f-etc.drv /nix/store/7g5l5glbw2nngbk2v3z6l5zdjxjfxhn2-activate.drv /nix/store/1wksn04vwq41m6k9s4m50amz27hhrgg6-nixos-system-client-test.drv /nix/store/nmwkd9rbaz11m00amisn6fc8kqzzmf95-system-path.drv /nix/store/pg4s5a7kkvw6djddjxlfmcsn2ya7laab-dbus-1.drv /nix/store/yl0v25cmi7rhvhlfavl9h9ix619h8xq4-X-Restart-Triggers-dbus-broker.drv /nix/store/2b20aiq8sa50pk3pm5zdzywvmx360iv9-unit-dbus-broker.service.drv /nix/store/2sqmhrmpwn7w72hinzmc459md2d72ddv-run-client-nspawn.drv /nix/store/33ysc61mi11kshcq09hc1x9hpw72sbi0-X-Restart-Triggers-acme-test.foo.drv /nix/store/jxb6x753fqh9qsdfr6kd1dd06snj68sb-unit-script-acme-test.foo-start.drv /nix/store/300lzbbn313vjl4xwmbp5fij40zhv6w6-unit-acme-test.foo.service.drv /nix/store/3cdmcd9isw2rag9rhnb76hi2wgz276m7-acme-postrun.drv /nix/store/jrln6ldic7lf2wk4m78mymqw3g9ikjl8-nginx.conf.drv /nix/store/3sx1ynm5g6cjrl5y260pg0ppp0v4d4wa-unit-script-nginx-pre-start.drv /nix/store/qq6ms440xlly2q027kys1f9j2bh6yy0i-test-script.drv /nix/store/4npi5hfjyzgqr0fgxwpcaif1ll5qvl6l-user-units.drv /nix/store/c6028b7d6mzlxrwdh9hvwz3fnc81n86b-hosts.drv /nix/store/krkpg8k1xmxf1p29pi6qrni0bnq088ka-nixos-tmpfiles.d.drv /nix/store/hx1vv9x2bvhhvsgxz8wbknybbsvqp4f0-tmpfiles.d.drv /nix/store/7irk03vanc5xlvca6i17vaq7j2pk794x-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/bfnbi0ivq2qlkdya7mfcyrgal3l75f72-unit-acme-renew-test.foo.timer.drv /nix/store/s7iyb8q0dvr6dgpffrcyslvjnwlzkh7x-acme-postrun.drv /nix/store/xk1djxalc44cx697ca7p2vaj698dpczg-unit-script-acme-order-renew-test.foo-start.drv /nix/store/cg3qqfszqzzbmw4dm4jxz0c07i07blyy-unit-acme-order-renew-test.foo.service.drv /nix/store/fw9zzn8p2819xmxzbwjbp5b5nng9h5sj-unit-nginx-config-reload.service.drv /nix/store/kp8dljswwwkqk7w5ngkh88cqwvv8vfmw-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/h92cs5q4q590p6vvaxjf9f83ashdimxp-unit-systemd-tmpfiles-resetup.service.drv /nix/store/hxjsdq5h221qjz2yv66s48292zr5572v-acme-setup-privileged.drv /nix/store/iw0qimh0h18z57rx7946jnvg2z4y6wmh-unit-acme-setup.service.drv /nix/store/n0i5fnzbsb0zkkiw16301r4q69pzkdmc-unit-nginx.service.drv /nix/store/n5lgd8kjn863127n3hw4a4m51iiqdncz-unit-dbus-broker.service.drv /nix/store/yw288val3xcd0lvrg7fj24317b904nz9-unit-firewall.service.drv /nix/store/56w04cclrff8fgm0b3hj9vycva9dq9r6-X-Reload-Triggers-systemd-networkd.drv /nix/store/zszxpq2xinis7dknnwymdyaiy7yyah6j-unit-systemd-networkd.service.drv /nix/store/w55r1rknf1p1mgr8n0n1alzis7sp9zmn-system-units.drv /nix/store/p6dnwa9clvgbdkfw95cfkwf6i4gb6vkj-etc.drv /nix/store/lamcl7ylbxmxlvb9i3mzsvfx1hxla754-activate.drv /nix/store/p665x5g4cf75qyf0riiwhgjzp3qzi5c6-dry-activate.drv /nix/store/z0zk39vicy9dhaka75szvjh5gdq4q9q3-nixos-system-server-test.drv /nix/store/jny5ck393x4sgxmn8nl0w7gnmfra4wl3-run-server-nspawn.drv /nix/store/53hnawxj96bx7praki7i4v57slvk3nl8-system-path.drv /nix/store/9s6z42mqv300c0zqsy258gi9lpdmq6my-users-groups.json.drv /nix/store/fwdgn1p9i71a2z91qy80lx5m46vnj148-etc-hostname.drv /nix/store/hd50zk417rykvdbbfgngqwkgwfp7m6d9-system-shutdown.drv /nix/store/i30rzaj5iwfdzlrlxm0rhlar4xp6k7n7-system-generators.drv /nix/store/ivblry47xynlrmn3f7xplcdykhz54kb5-user-generators.drv /nix/store/x3i9qpwy7sx46p4fzrsrjc4pjkh6idgf-dbus-1.drv /nix/store/kjmkg96s7i10bkdcw918a5qfjz4yscmd-X-Restart-Triggers-dbus-broker.drv /nix/store/yr14jpn42fdik55sz046ycmpk4myrss7-unit-dbus-broker.service.drv /nix/store/k3wap5inj84acy6l6jh9112p23whxx0x-user-units.drv /nix/store/vnvlniy3jw707y5758y6vkgmxgja643k-acme-setup-privileged.drv /nix/store/c32hn00sk7i5n3iwl5dwlg87kqv8hgm5-unit-acme-setup.service.drv /nix/store/d2avhjb4s4fnivfvc5m03l7w0paydb6b-unit-acme-renew-ca.foo.timer.drv /nix/store/kdk3xsk8lxb7926i0yb82cykk7b9vyj2-unit-nginx.service.drv /nix/store/mjcag0kvnj4h286hg3rvrgwgz6kwa4w9-unit-dbus-broker.service.drv /nix/store/mbmq2fnjrl6rjd4f5chjqn21h72n6g51-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/n132wcg6ip1grxd37ychp1006wkzhcza-unit-acme-order-renew-ca.foo.service.drv /nix/store/qxpp164gsfgzyas2kmd8wg3qyakqzavi-unit-nginx-config-reload.service.drv /nix/store/x7d0nslv3qznin20gmhr0c5qnwnavwp2-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/4sfz05hhn9cnswrfbqhr9r41zizqd315-unit-script-acme-ca.foo-start.drv /nix/store/ab41sxhfkmh965c1b96j4zmzrjccdw2x-X-Restart-Triggers-acme-ca.foo.drv /nix/store/yj1akmznrbkvc723n3iypygm9ahzqsak-unit-acme-ca.foo.service.drv /nix/store/nyvksy007jxaqbsyix4af9jprfb07pcb-system-units.drv /nix/store/qfsrvg58wd78nr87mq8fs9vjav0bx7h7-string-hosts.drv /nix/store/p5f8qdav49r8y6hj0x3nbp79b23vrx5j-hosts.drv /nix/store/qbxx5cfkcv4par7v5mln1sa5pdswjx9a-etc.drv /nix/store/nv0xmklh96zsnzin4nwkdcmw8blyb5gg-activate.drv /nix/store/varyvj2bd1w0xikmym53l2lbay5pcz6z-dry-activate.drv /nix/store/nr3zw508gn9wrphlcqsxy2yhs392wb4k-nixos-system-ca-test.drv /nix/store/prvnyc7s8h3slr1k1hpyql6n4763bz7g-run-ca-nspawn.drv /nix/store/rd0kdzz6824d335agl6zwcjj7wm3kw6j-driverConfiguration.json.drv /nix/store/3zzqbidnni1p4p7dlkrhigy9kpsmly6p-nixos-test-driver-certificates.drv /nix/store/lnfiwj9i50a3nld3w1hdgsbjgivahn9z-container-test-run-certificates.drv these 3 paths will be fetched (24.4 MiB download, 75.8 MiB unpacked): /nix/store/qfjhplgaj6zn71pd29p28wxngj5l4bys-openssl-3.6.3-man /nix/store/fwwgviqhlwxaigb610fvpiciz2di7wjg-python3.14-buildcatrust-0.5.1 /nix/store/dlpj6bc50h35a0glvslc6vnrq4xgp93j-step-ca-0.30.2 building '/nix/store/qq6ms440xlly2q027kys1f9j2bh6yy0i-test-script.drv' building '/nix/store/fwdgn1p9i71a2z91qy80lx5m46vnj148-etc-hostname.drv' building '/nix/store/jrln6ldic7lf2wk4m78mymqw3g9ikjl8-nginx.conf.drv' building '/nix/store/nizw79x2jpmvbgjpxlk3igyhh8vakhbw-nginx.conf.drv' building '/nix/store/1d3j7hsfkvw9p8lljs95cndmilri60h0-unit-40-eth1.network.drv' building '/nix/store/lylvrr8cbsf0k9h5jlbg5h2n5bhljsq8-extra-hosts.drv' building '/nix/store/krkpg8k1xmxf1p29pi6qrni0bnq088ka-nixos-tmpfiles.d.drv' building '/nix/store/qfsrvg58wd78nr87mq8fs9vjav0bx7h7-string-hosts.drv' building '/nix/store/7irk03vanc5xlvca6i17vaq7j2pk794x-unit-acme-account-2c44cb477b4787b2cf13.target.drv' building '/nix/store/x7d0nslv3qznin20gmhr0c5qnwnavwp2-unit-acme-account-d22a46d9459bf683a338.target.drv' nginx.conf> structuredAttrs is enabled nginx.conf> structuredAttrs is enabled unit-40-eth1.network> structuredAttrs is enabled unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled building '/nix/store/a0fjq2lmggzgmdqmw61ppvcrk0ns78lv-firewall-start.drv' building '/nix/store/qxpp164gsfgzyas2kmd8wg3qyakqzavi-unit-nginx-config-reload.service.drv' building '/nix/store/4sfz05hhn9cnswrfbqhr9r41zizqd315-unit-script-acme-ca.foo-start.drv' building '/nix/store/mbmq2fnjrl6rjd4f5chjqn21h72n6g51-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/xk1djxalc44cx697ca7p2vaj698dpczg-unit-script-acme-order-renew-test.foo-start.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/c6028b7d6mzlxrwdh9hvwz3fnc81n86b-hosts.drv' building '/nix/store/i24rhm6bgwms3ib5b4b2cqgl5sxm2n6c-hosts.drv' building '/nix/store/p5f8qdav49r8y6hj0x3nbp79b23vrx5j-hosts.drv' building '/nix/store/hx1vv9x2bvhhvsgxz8wbknybbsvqp4f0-tmpfiles.d.drv' building '/nix/store/fw9zzn8p2819xmxzbwjbp5b5nng9h5sj-unit-nginx-config-reload.service.drv' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/56w04cclrff8fgm0b3hj9vycva9dq9r6-X-Reload-Triggers-systemd-networkd.drv' building '/nix/store/hxjsdq5h221qjz2yv66s48292zr5572v-acme-setup-privileged.drv' building '/nix/store/vnvlniy3jw707y5758y6vkgmxgja643k-acme-setup-privileged.drv' building '/nix/store/05l61ybxsccw6az5wkv1yr6i1znk7973-firewall-reload.drv' building '/nix/store/d2avhjb4s4fnivfvc5m03l7w0paydb6b-unit-acme-renew-ca.foo.timer.drv' building '/nix/store/bfnbi0ivq2qlkdya7mfcyrgal3l75f72-unit-acme-renew-test.foo.timer.drv' building '/nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' unit-acme-renew-ca.foo.timer> structuredAttrs is enabled unit-acme-renew-test.foo.timer> structuredAttrs is enabled building '/nix/store/ab41sxhfkmh965c1b96j4zmzrjccdw2x-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/33ysc61mi11kshcq09hc1x9hpw72sbi0-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/3cdmcd9isw2rag9rhnb76hi2wgz276m7-acme-postrun.drv' building '/nix/store/s7iyb8q0dvr6dgpffrcyslvjnwlzkh7x-acme-postrun.drv' building '/nix/store/05gw6yyrzlhj5mg2zfdp7m6ng902jxsr-cacert-blocklist.txt.drv' building '/nix/store/5l0dhhj9lqdgym7sdhqkn96v42fsrm6j-cacert-extra-certificates-bundle.crt.drv' building '/nix/store/jxb6x753fqh9qsdfr6kd1dd06snj68sb-unit-script-acme-test.foo-start.drv' building '/nix/store/0dazh70qwhpgsvnf5ws7zfdbrmzlhg6l-users-groups.json.drv' building '/nix/store/kp8dljswwwkqk7w5ngkh88cqwvv8vfmw-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' building '/nix/store/p2rvqr10dlfk1iandnvbfs18rm4b6qnv-ca.json.drv' building '/nix/store/53hnawxj96bx7praki7i4v57slvk3nl8-system-path.drv' building '/nix/store/i9dp3pxhd8i3wwisb7p3hyb99pazmsf8-system-path.drv' building '/nix/store/nmwkd9rbaz11m00amisn6fc8kqzzmf95-system-path.drv' building '/nix/store/c32hn00sk7i5n3iwl5dwlg87kqv8hgm5-unit-acme-setup.service.drv' building '/nix/store/iw0qimh0h18z57rx7946jnvg2z4y6wmh-unit-acme-setup.service.drv' building '/nix/store/yw288val3xcd0lvrg7fj24317b904nz9-unit-firewall.service.drv' building '/nix/store/0v9pkxmlzs6bwbhd56wbhlj22wpgnw2p-unit-script-nginx-pre-start.drv' building '/nix/store/9s6z42mqv300c0zqsy258gi9lpdmq6my-users-groups.json.drv' ca.json> structuredAttrs is enabled system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment unit-acme-setup.service> structuredAttrs is enabled unit-acme-setup.service> structuredAttrs is enabled unit-firewall.service> structuredAttrs is enabled building '/nix/store/cg3qqfszqzzbmw4dm4jxz0c07i07blyy-unit-acme-order-renew-test.foo.service.drv' building '/nix/store/07ymllsf1g692gqgjw43jm91gzrrg5c1-nss-cacert-3.126.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' unit-acme-order-renew-test.foo.service> structuredAttrs is enabled building '/nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/p665x5g4cf75qyf0riiwhgjzp3qzi5c6-dry-activate.drv' building '/nix/store/i30rzaj5iwfdzlrlxm0rhlar4xp6k7n7-system-generators.drv' building '/nix/store/hd50zk417rykvdbbfgngqwkgwfp7m6d9-system-shutdown.drv' building '/nix/store/yj1akmznrbkvc723n3iypygm9ahzqsak-unit-acme-ca.foo.service.drv' building '/nix/store/n132wcg6ip1grxd37ychp1006wkzhcza-unit-acme-order-renew-ca.foo.service.drv' building '/nix/store/300lzbbn313vjl4xwmbp5fij40zhv6w6-unit-acme-test.foo.service.drv' building '/nix/store/3sx1ynm5g6cjrl5y260pg0ppp0v4d4wa-unit-script-nginx-pre-start.drv' building '/nix/store/zszxpq2xinis7dknnwymdyaiy7yyah6j-unit-systemd-networkd.service.drv' building '/nix/store/h92cs5q4q590p6vvaxjf9f83ashdimxp-unit-systemd-tmpfiles-resetup.service.drv' unit-acme-ca.foo.service> structuredAttrs is enabled unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled unit-acme-test.foo.service> structuredAttrs is enabled unit-systemd-networkd.service> structuredAttrs is enabled unit-systemd-tmpfiles-resetup.service> structuredAttrs is enabled building '/nix/store/5zbn6y0g7by9nds3xvc1mb5lqcm69nf6-X-Restart-Triggers-step-ca.drv' building '/nix/store/pg4s5a7kkvw6djddjxlfmcsn2ya7laab-dbus-1.drv' building '/nix/store/x3i9qpwy7sx46p4fzrsrjc4pjkh6idgf-dbus-1.drv' building '/nix/store/kdk3xsk8lxb7926i0yb82cykk7b9vyj2-unit-nginx.service.drv' building '/nix/store/ivblry47xynlrmn3f7xplcdykhz54kb5-user-generators.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/7rfsbl4zr4jzakgvvbz6aqcgka7wmk3j-dbus-1.drv' building '/nix/store/n0i5fnzbsb0zkkiw16301r4q69pzkdmc-unit-nginx.service.drv' building '/nix/store/yl0v25cmi7rhvhlfavl9h9ix619h8xq4-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/0j80qag3hfmw2hdfz2jbx6zczxdjyzxf-unit-step-ca.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/frqjymwgfg7lwzcla6s2c5d36jj3zsnn-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/kjmkg96s7i10bkdcw918a5qfjz4yscmd-X-Restart-Triggers-dbus-broker.drv' unit-step-ca.service> structuredAttrs is enabled building '/nix/store/2b20aiq8sa50pk3pm5zdzywvmx360iv9-unit-dbus-broker.service.drv' building '/nix/store/n5lgd8kjn863127n3hw4a4m51iiqdncz-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/g3pbjwbabwkr9akggrlfgxyx1fyfz5lf-unit-dbus-broker.service.drv' building '/nix/store/mjcag0kvnj4h286hg3rvrgwgz6kwa4w9-unit-dbus-broker.service.drv' building '/nix/store/wbjwlajk0a2j6c39hgmd5g319ljv0wn9-unit-dbus-broker.service.drv' building '/nix/store/yr14jpn42fdik55sz046ycmpk4myrss7-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/4npi5hfjyzgqr0fgxwpcaif1ll5qvl6l-user-units.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/qgciair8g6hxi7i3lispy9i41fycaqgq-user-units.drv' building '/nix/store/k3wap5inj84acy6l6jh9112p23whxx0x-user-units.drv' building '/nix/store/07ymllsf1g692gqgjw43jm91gzrrg5c1-nss-cacert-3.126.drv' nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase building '/nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv' nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/a398snyy077ajlww7lhanvjrbbpasvam-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/a398snyy077ajlww7lhanvjrbbpasvam-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/a398snyy077ajlww7lhanvjrbbpasvam-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/wcv96jizp2k0nw5ibcywgar2lnd2dqcg-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/wcv96jizp2k0nw5ibcywgar2lnd2dqcg-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/wcv96jizp2k0nw5ibcywgar2lnd2dqcg-nss-cacert-3.126-unbundled nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/ypd15ipc46367j5q4rpvk2zydp9zbj37-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/ypd15ipc46367j5q4rpvk2zydp9zbj37-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/ypd15ipc46367j5q4rpvk2zydp9zbj37-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/60d8lj3snn7k4xji8kyq05r4dgjrcpj6-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/60d8lj3snn7k4xji8kyq05r4dgjrcpj6-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/60d8lj3snn7k4xji8kyq05r4dgjrcpj6-nss-cacert-3.126-hashed building '/nix/store/varyvj2bd1w0xikmym53l2lbay5pcz6z-dry-activate.drv' building '/nix/store/jblkhwl4fxs92xx6s3wc0mf8fhzq7rzy-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled building '/nix/store/f3iwwyk5n7r9pzfgsfpa9dgnlp77zcwm-system-units.drv' building '/nix/store/nyvksy007jxaqbsyix4af9jprfb07pcb-system-units.drv' building '/nix/store/w55r1rknf1p1mgr8n0n1alzis7sp9zmn-system-units.drv' building '/nix/store/6v4pv35n2p6nf77sib090l1kax5ywl1f-etc.drv' building '/nix/store/p6dnwa9clvgbdkfw95cfkwf6i4gb6vkj-etc.drv' building '/nix/store/qbxx5cfkcv4par7v5mln1sa5pdswjx9a-etc.drv' building '/nix/store/7g5l5glbw2nngbk2v3z6l5zdjxjfxhn2-activate.drv' building '/nix/store/1wksn04vwq41m6k9s4m50amz27hhrgg6-nixos-system-client-test.drv' building '/nix/store/lamcl7ylbxmxlvb9i3mzsvfx1hxla754-activate.drv' nixos-system-client-test> structuredAttrs is enabled building '/nix/store/nv0xmklh96zsnzin4nwkdcmw8blyb5gg-activate.drv' building '/nix/store/z0zk39vicy9dhaka75szvjh5gdq4q9q3-nixos-system-server-test.drv' building '/nix/store/2sqmhrmpwn7w72hinzmc459md2d72ddv-run-client-nspawn.drv' nixos-system-server-test> structuredAttrs is enabled building '/nix/store/nr3zw508gn9wrphlcqsxy2yhs392wb4k-nixos-system-ca-test.drv' building '/nix/store/jny5ck393x4sgxmn8nl0w7gnmfra4wl3-run-server-nspawn.drv' nixos-system-ca-test> structuredAttrs is enabled building '/nix/store/prvnyc7s8h3slr1k1hpyql6n4763bz7g-run-ca-nspawn.drv' building '/nix/store/rd0kdzz6824d335agl6zwcjj7wm3kw6j-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/3zzqbidnni1p4p7dlkrhigy9kpsmly6p-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! building '/nix/store/lnfiwj9i50a3nld3w1hdgsbjgivahn9z-container-test-run-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/lnfiwj9i50a3nld3w1hdgsbjgivahn9z-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> client: systemd-nspawn running (pid 53) container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> ca: systemd-nspawn running (pid 54) container-test-run-certificates> server: systemd-nspawn running (pid 55) container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> client # [7605051.738965] client systemd-journald[69]: Journal started container-test-run-certificates> client # [7605051.738995] client systemd-journald[69]: Runtime Journal (/run/log/journal/236f7a3e98704770bf71fab68acbed6d) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> client # [7605051.740678] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [7605051.745172] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [7605051.745515] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [7605051.745809] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [7605051.749757] client systemd-journald[69]: Time spent on flushing to /var/log/journal/236f7a3e98704770bf71fab68acbed6d is 1.353ms for 6 entries. container-test-run-certificates> client # [7605051.749757] client systemd-journald[69]: System Journal (/var/log/journal/236f7a3e98704770bf71fab68acbed6d) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [7605051.754147] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [7605051.754472] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [7605051.754520] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [7605051.754975] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [7605051.755027] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [7605051.755392] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [7605051.745277] ca systemd-journald[78]: Journal started container-test-run-certificates> client # [7605051.755408] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [7605051.745304] ca systemd-journald[78]: Runtime Journal (/run/log/journal/25cee0fdeda448ec814afa4dad0e44d3) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> client # [7605051.759422] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [7605051.750183] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [7605051.760455] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [7605051.750512] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [7605051.773949] client systemd-tmpfiles[111]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [7605051.774095] client systemd-tmpfiles[111]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [7605051.774199] client systemd-tmpfiles[111]: fchmod() of /var/log/journal/236f7a3e98704770bf71fab68acbed6d failed: Operation not permitted container-test-run-certificates> client # [7605051.774354] client systemd-tmpfiles[111]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [7605051.775247] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [7605051.775654] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [7605051.776009] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> client # [7605051.782829] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [7605051.788828] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [7605051.789259] client systemd[1]: Starting Update is Completed... container-test-run-certificates> client # [7605051.794218] client systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [7605051.823812] client systemd[1]: Finished Firewall. container-test-run-certificates> client # [7605051.823891] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [7605051.824015] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [7605051.824456] client systemd[1]: Starting Network Management... container-test-run-certificates> client # [7605051.876210] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [7605052.090923] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [7605052.090990] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [7605052.096095] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [7605052.096236] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [7605052.096302] client systemd-networkd[182]: lo: Link UP container-test-run-certificates> client # [7605052.096306] client systemd-networkd[182]: lo: Gained carrier container-test-run-certificates> client # [7605052.096428] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [7605052.096664] client systemd[1]: Started Network Management. container-test-run-certificates> client # [7605052.096715] client systemd-networkd[182]: eth1: Link UP container-test-run-certificates> client # [7605052.096865] client systemd-networkd[182]: eth1: Gained carrier container-test-run-certificates> client # [7605052.097246] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [7605052.116505] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [7605052.246578] client systemd-resolved[90]: Positive Trust Anchors: container-test-run-certificates> client # [7605052.246584] client systemd-resolved[90]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [7605052.246588] client systemd-resolved[90]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [7605052.246603] client systemd-resolved[90]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [7605051.745245] server systemd-journald[69]: Journal started container-test-run-certificates> server # [7605051.745276] server systemd-journald[69]: Runtime Journal (/run/log/journal/e5f562050f354a888fe540ef9a8e291a) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> server # [7605051.746064] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> server # [7605051.750768] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> server # [7605051.751177] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> server # [7605051.751464] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> server # [7605051.756051] server systemd-journald[69]: Time spent on flushing to /var/log/journal/e5f562050f354a888fe540ef9a8e291a is 1.141ms for 6 entries. container-test-run-certificates> server # [7605051.756051] server systemd-journald[69]: System Journal (/var/log/journal/e5f562050f354a888fe540ef9a8e291a) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [7605051.772422] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [7605051.772517] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [7605051.773365] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [7605051.773419] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [7605051.773834] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [7605051.773862] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [7605051.774305] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [7605051.774611] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [7605051.774627] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [7605051.784736] server systemd-tmpfiles[120]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [7605051.784934] server systemd-tmpfiles[120]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [7605051.785069] server systemd-tmpfiles[120]: fchmod() of /var/log/journal/e5f562050f354a888fe540ef9a8e291a failed: Operation not permitted container-test-run-certificates> server # [7605051.785228] server systemd-tmpfiles[120]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [7605051.786259] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [7605051.786821] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [7605051.787192] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [7605051.794473] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [7605051.799383] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [7605051.800058] server systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [7605051.804737] server systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [7605051.832217] server systemd[1]: Finished Firewall. container-test-run-certificates> server # [7605051.832303] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [7605051.832426] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [7605051.832898] server systemd[1]: Starting Network Management... container-test-run-certificates> server # [7605051.876073] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [7605052.095085] server systemd-networkd[186]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [7605052.095150] server systemd-networkd[186]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [7605052.100341] server systemd-networkd[186]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [7605052.100481] server systemd-networkd[186]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [7605052.100533] server systemd-networkd[186]: lo: Link UP container-test-run-certificates> server # [7605052.100535] server systemd-networkd[186]: lo: Gained carrier container-test-run-certificates> server # [7605052.100660] server systemd-networkd[186]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [7605052.100910] server systemd[1]: Started Network Management. container-test-run-certificates> server # [7605052.112156] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [7605052.112217] server systemd-networkd[186]: eth1: Link UP container-test-run-certificates> server # [7605052.112334] server systemd-networkd[186]: eth1: Gained carrier container-test-run-certificates> server # [7605052.126182] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [7605052.232573] server systemd-resolved[91]: Positive Trust Anchors: container-test-run-certificates> server # [7605052.232580] server systemd-resolved[91]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [7605052.232583] server systemd-resolved[91]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [7605052.232600] server systemd-resolved[91]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [7605052.242792] server systemd-resolved[91]: Using system hostname 'server'. container-test-run-certificates> server # [7605052.243668] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [7605052.243725] server systemd[1]: Reached target Network. container-test-run-certificates> server # [7605052.243756] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [7605052.243778] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [7605052.243911] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [7605052.243929] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [7605052.243942] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [7605052.243953] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [7605052.244033] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [7605052.244094] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [7605052.244162] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [7605052.244174] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [7605052.244194] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [7605052.244895] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [7605052.245350] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [7605052.245370] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [7605052.245737] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [7605052.246362] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [7605051.750819] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [7605051.755496] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/25cee0fdeda448ec814afa4dad0e44d3 is 1.072ms for 5 entries. container-test-run-certificates> ca # [7605051.755496] ca systemd-journald[78]: System Journal (/var/log/journal/25cee0fdeda448ec814afa4dad0e44d3) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [7605051.759857] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [7605051.759972] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [7605051.760021] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [7605051.760418] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [7605051.760440] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [7605051.760751] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [7605051.760764] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [7605051.766811] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [7605051.767265] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [7605051.777416] ca systemd-tmpfiles[123]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [7605051.777578] ca systemd-tmpfiles[123]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [7605051.777682] ca systemd-tmpfiles[123]: fchmod() of /var/log/journal/25cee0fdeda448ec814afa4dad0e44d3 failed: Operation not permitted container-test-run-certificates> ca # [7605051.777835] ca systemd-tmpfiles[123]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [7605051.778752] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [7605051.779351] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [7605051.779647] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [7605051.787304] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [7605051.791424] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [7605051.791966] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [7605051.797746] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [7605051.831180] ca systemd[1]: Finished Firewall. container-test-run-certificates> ca # [7605051.831654] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [7605051.831855] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [7605051.832500] ca systemd[1]: Starting Network Management... container-test-run-certificates> ca # [7605051.876672] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [7605052.094399] ca systemd-networkd[195]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [7605052.094472] ca systemd-networkd[195]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [7605052.099512] ca systemd-networkd[195]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [7605052.099653] ca systemd-networkd[195]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [7605052.099705] ca systemd-networkd[195]: lo: Link UP container-test-run-certificates> ca # [7605052.099708] ca systemd-networkd[195]: lo: Gained carrier container-test-run-certificates> ca # [7605052.099824] ca systemd-networkd[195]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [7605052.100068] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [7605052.112115] ca systemd-networkd[195]: eth1: Link UP container-test-run-certificates> ca # [7605052.112165] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [7605052.112247] ca systemd-networkd[195]: eth1: Gained carrier container-test-run-certificates> ca # [7605052.126110] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [7605052.256879] client systemd-resolved[90]: Using system hostname 'client'. container-test-run-certificates> client # [7605052.257680] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [7605052.257717] client systemd[1]: Reached target Network. container-test-run-certificates> client # [7605052.257747] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [7605052.257775] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [7605052.257791] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [7605052.257801] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [7605052.257870] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [7605052.257939] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [7605052.258024] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [7605052.258034] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [7605052.258056] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [7605052.265196] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [7605052.265734] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [7605052.266389] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [7605052.276164] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [7605052.251609] ca systemd-resolved[101]: Positive Trust Anchors: container-test-run-certificates> ca # [7605052.251614] ca systemd-resolved[101]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [7605052.251618] ca systemd-resolved[101]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [7605052.251634] ca systemd-resolved[101]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [7605052.261624] ca systemd-resolved[101]: Using system hostname 'ca'. container-test-run-certificates> ca # [7605052.262601] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [7605052.262657] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [7605052.262698] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [7605052.262734] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [7605052.262905] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [7605052.262927] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [7605052.262944] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [7605052.262959] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [7605052.263057] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [7605052.263119] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [7605052.263184] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [7605052.263193] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [7605052.263212] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [7605052.265198] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [7605052.265500] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [7605052.265518] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [7605052.265868] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [7605052.266287] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [7605052.266888] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [7605052.276106] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [7605052.331627] ca acme-setup-privileged[201]: + set -euo pipefail container-test-run-certificates> ca # [7605052.331627] ca acme-setup-privileged[201]: + cd /var/lib/acme container-test-run-certificates> ca # [7605052.331894] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [7605052.332356] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [7605052.333130] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [7605052.333156] ca acme-setup-privileged[201]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [7605052.333156] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [7605052.333156] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [7605052.341206] ca nsncd[203]: Aug 27 10:31:49.706 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [7605052.273814] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [7605052.322886] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> server # [7605052.322886] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [7605052.323126] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> server # [7605052.323765] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> server # [7605052.324700] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [7605052.324727] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> server # [7605052.324727] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [7605052.324727] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> client # [7605052.346980] client nsncd[189]: Aug 27 10:31:49.712 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [7605052.347079] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [7605052.347106] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [7605052.347132] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [7605052.350757] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [7605052.351061] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [7605052.356219] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [7605052.356667] client systemd[1]: Started Console Getty. container-test-run-certificates> client # [7605052.356690] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [7605052.356701] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [7605052.400718] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [7605052.401239] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [7605052.401239] client dbus-broker-launch[190]: Invalid user-name in /nix/store/n25qs0cxdhj6rld8wlnm0r6dhj2cw2r3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [7605052.401568] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [7605052.404969] client dbus-broker-launch[190]: Ready container-test-run-certificates> server # [7605052.349696] server nsncd[194]: Aug 27 10:31:49.715 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [7605052.349722] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [7605052.349753] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [7605052.349780] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [7605052.350734] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [7605052.351056] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [7605052.356215] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [7605052.356647] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [7605052.356670] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [7605052.356682] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [7605052.400702] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [7605052.401171] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [7605052.401171] server dbus-broker-launch[195]: Invalid user-name in /nix/store/3998vwjgq9b8mfq8zd315f0dx0zdhk3x-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [7605052.401485] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [7605052.404828] server dbus-broker-launch[195]: Ready container-test-run-certificates> ca # [7605052.350218] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [7605052.350299] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [7605052.350329] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [7605052.350951] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [7605052.351333] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [7605052.356964] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [7605052.357729] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [7605052.357751] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [7605052.357767] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [7605052.406333] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [7605052.406641] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [7605052.406641] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/dyyq5fj9d2iyrp213l8wpy3imn4cyazg-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [7605052.406912] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [7605052.410810] ca dbus-broker-launch[205]: Ready container-test-run-certificates> client # [7605052.653047] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [7605052.653135] client systemd[1]: Started User Login Management. container-test-run-certificates> client # [7605052.653623] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [7605052.677205] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [7605052.677280] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [7605052.677483] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [7605052.677563] client systemd[1]: Startup finished in 1.179s. container-test-run-certificates> client # [7605052.733051] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [7605052.655523] server systemd-logind[221]: New seat seat0. container-test-run-certificates> server # [7605052.655631] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [7605052.673205] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [7605052.678680] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [7605052.678715] server systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [7605052.689846] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> server # [7605052.689995] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> server # [7605052.689995] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [7605052.696454] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [7605052.697244] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server # [7605052.738208] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [7605052.657300] ca systemd-logind[230]: New seat seat0. container-test-run-certificates> ca # [7605052.657387] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [7605052.673174] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [7605052.678502] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [7605052.678534] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [7605052.692531] ca acme-setup-start[219]: + set -euo pipefail container-test-run-certificates> ca # [7605052.692666] ca acme-setup-start[219]: + test -e ca/key.pem container-test-run-certificates> ca # [7605052.692666] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [7605052.698856] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [7605052.699645] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> ca # [7605052.738125] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [7605052.803997] ca step-ca[204]: badger 2026/08/27 10:31:50 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [7605052.807075] ca step-ca[204]: 2026/08/27 10:31:50 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [7605052.809602] ca step-ca[204]: 2026/08/27 10:31:50 Starting Smallstep CA/0.30.2 (linux/amd64) container-test-run-certificates> ca # [7605052.809602] ca step-ca[204]: 2026/08/27 10:31:50 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [7605052.809602] ca step-ca[204]: 2026/08/27 10:31:50 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [7605052.809602] ca step-ca[204]: 2026/08/27 10:31:50 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [7605052.809602] ca step-ca[204]: 2026/08/27 10:31:50 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [7605052.809602] ca step-ca[204]: 2026/08/27 10:31:50 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [7605052.809680] ca step-ca[204]: 2026/08/27 10:31:50 X.509 Root Fingerprint: 5389b914b2ee04bdcb137b5ae5a7e121e8735e596b53bf58866e505ea3da76d6 container-test-run-certificates> ca # [7605052.809688] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [7605052.809809] ca step-ca[204]: 2026/08/27 10:31:50 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> server # [7605053.011380] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7605053.013212] server acme-test.foo-start[245]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [7605053.013245] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [7605053.017477] server acme-test.foo-start[255]: + cd test.foo container-test-run-certificates> server # [7605053.017625] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [7605053.018276] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [7605053.018387] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [7605053.018989] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [7605053.019129] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [7605053.019976] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [7605053.020790] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [7605053.021768] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [7605053.021781] server acme-test.foo-start[245]: + '[' -d out ']' container-test-run-certificates> server # [7605053.021781] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [7605053.022507] server acme-test.foo-start[245]: + chown -R acme:nginx out container-test-run-certificates> server # [7605053.023897] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [7605053.023897] server acme-test.foo-start[245]: + '[' -d certificates ']' container-test-run-certificates> server # [7605053.025481] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [7605053.026303] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [7605053.016576] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [7605053.018227] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [7605053.018227] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [7605053.022886] ca acme-ca.foo-start[283]: + cd ca.foo container-test-run-certificates> ca # [7605053.022886] ca acme-ca.foo-start[283]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [7605053.023828] ca acme-ca.foo-start[284]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [7605053.023994] ca acme-ca.foo-start[283]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [7605053.024821] ca acme-ca.foo-start[283]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [7605053.024945] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [7605053.025804] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [7605053.026618] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [7605053.027428] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [7605053.027439] ca acme-ca.foo-start[256]: + '[' -d out ']' container-test-run-certificates> ca # [7605053.027439] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [7605053.028263] ca acme-ca.foo-start[256]: + chown -R acme:nginx out container-test-run-certificates> ca # [7605053.029641] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [7605053.029641] ca acme-ca.foo-start[256]: + '[' -d certificates ']' container-test-run-certificates> ca # [7605053.050078] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [7605053.050831] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> client # [7605053.181175] client systemd-networkd[182]: eth1: Gained IPv6LL container-test-run-certificates> server # [7605053.309137] server systemd-networkd[186]: eth1: Gained IPv6LL container-test-run-certificates> server # [7605053.367672] server nginx-pre-start[267]: nginx: the configuration file /nix/store/nfgk30pbmji62whlqlbylrn263ifbnzr-nginx.conf syntax is ok container-test-run-certificates> server # [7605053.367847] server nginx-pre-start[267]: nginx: configuration file /nix/store/nfgk30pbmji62whlqlbylrn263ifbnzr-nginx.conf test is successful container-test-run-certificates> server # [7605053.370188] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [7605053.370393] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [7605053.370967] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [7605053.373849] ca nginx-pre-start[295]: nginx: the configuration file /nix/store/qy667v7x86g27a1fq9zsc0f3ainxp9il-nginx.conf syntax is ok container-test-run-certificates> ca # [7605053.374100] ca nginx-pre-start[295]: nginx: configuration file /nix/store/qy667v7x86g27a1fq9zsc0f3ainxp9il-nginx.conf test is successful container-test-run-certificates> ca # [7605053.384129] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [7605053.384321] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [7605053.384862] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> server # [7605053.706396] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7605053.708043] server acme-order-renew-test.foo-start[270]: + set -euo pipefail container-test-run-certificates> server # [7605053.708125] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [7605053.708145] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [7605053.708870] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [7605053.717671] server acme-order-renew-test.foo-start[281]: 2026/08/27 10:31:51 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [7605053.717856] server acme-order-renew-test.foo-start[281]: 2026/08/27 10:31:51 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> server # [7605053.732183] server acme-order-renew-test.foo-start[281]: 2026/08/27 10:31:51 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [7605053.732353] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [7605053.732353] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [7605053.732384] server acme-order-renew-test.foo-start[270]: + exit 10 container-test-run-certificates> server # [7605053.733702] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [7605053.733784] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [7605053.733944] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [7605053.734126] server systemd[1]: Startup finished in 2.235s. container-test-run-certificates> ca # [7605053.718857] ca acme-order-renew-ca.foo-start[298]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [7605053.720236] ca acme-order-renew-ca.foo-start[298]: + set -euo pipefail container-test-run-certificates> ca # [7605053.720275] ca acme-order-renew-ca.foo-start[298]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [7605053.720327] ca acme-order-renew-ca.foo-start[298]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [7605053.720892] ca acme-order-renew-ca.foo-start[298]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [7605053.729418] ca acme-order-renew-ca.foo-start[310]: 2026/08/27 10:31:51 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [7605053.729569] ca acme-order-renew-ca.foo-start[310]: 2026/08/27 10:31:51 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [7605053.740832] ca step-ca[204]: time="2026-08-27T10:31:51Z" level=info duration="72.357µs" duration-ns=72357 fields.time="2026-08-27T10:31:51Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=ed722557-aabe-4bd4-969b-5492f8501b52 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7605053.740963] ca acme-order-renew-ca.foo-start[310]: 2026/08/27 10:31:51 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [7605053.758067] ca systemd-networkd[195]: eth1: Gained IPv6LL container-test-run-certificates> ca # [7605053.758469] ca step-ca[204]: time="2026-08-27T10:31:51Z" level=info duration=17.405ms duration-ns=17405000 fields.time="2026-08-27T10:31:51Z" method=HEAD name=ca nonce=SGIxVlA5OXhsY25qTWhPU2VNUjcxMFRTSURPWDNPM0I path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=a89195e3-c94d-4da5-88f8-265d092afa0b size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7605053.759591] ca step-ca[204]: time="2026-08-27T10:31:51Z" level=info duration="793.535µs" duration-ns=793535 fields.time="2026-08-27T10:31:51Z" method=POST name=ca nonce=Y3BCREJxSE90TldkUFZZTEVSR1k4eXdqTnlCcVJvQmk path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=36194818-bcd2-4040-9278-5daef234a62a response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/9548ffHoUt6W5JMn9DtDn8wdNUgYHGme/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7605053.759701] ca acme-order-renew-ca.foo-start[310]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [7605053.759701] ca acme-order-renew-ca.foo-start[310]: Your account credentials have been saved in your container-test-run-certificates> ca # [7605053.759701] ca acme-order-renew-ca.foo-start[310]: configuration directory at "accounts". container-test-run-certificates> ca # [7605053.759701] ca acme-order-renew-ca.foo-start[310]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [7605053.759701] ca acme-order-renew-ca.foo-start[310]: configuration directory will also contain private keys container-test-run-certificates> ca # [7605053.759701] ca acme-order-renew-ca.foo-start[310]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [7605053.759701] ca acme-order-renew-ca.foo-start[310]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [7605053.759781] ca acme-order-renew-ca.foo-start[310]: 2026/08/27 10:31:51 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [7605053.761149] ca step-ca[204]: time="2026-08-27T10:31:51Z" level=info duration=1.244344ms duration-ns=1244344 fields.time="2026-08-27T10:31:51Z" method=POST name=ca nonce=ZUhsQkxOWGFRZERuenBIOGVObTQ3REN1TDVsS3lpRHQ path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=de8c1859-7b42-4f8c-9e10-61d02bb5a90b response="{\"id\":\"Crvi7b2wgXzWbVMif9F1BTNQrZ7GQ2bF\",\"status\":\"pending\",\"expires\":\"2026-08-28T10:31:51Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-27T10:30:51Z\",\"notAfter\":\"2026-11-25T10:31:51Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/GaD9SEujq0YZgbgwnhtQCratumfSa36Z\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/Crvi7b2wgXzWbVMif9F1BTNQrZ7GQ2bF/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7605053.818200] ca step-ca[204]: time="2026-08-27T10:31:51Z" level=info duration="646.828µs" duration-ns=646828 fields.time="2026-08-27T10:31:51Z" method=POST name=ca nonce=eHp1ZnRxMVRMVklXbWYybEFpT0cxOUNrWkM4ZlRmbkQ path=/acme/acme/authz/GaD9SEujq0YZgbgwnhtQCratumfSa36Z protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=bf0e8b97-e826-4632-9a19-e49319b9cb21 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"SWy5R4h6G01hgeWeuFo78hKRv7vEL52A\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/GaD9SEujq0YZgbgwnhtQCratumfSa36Z/icchZhlKS1YnBDZLPih6VkmWR2MB6jvQ\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"SWy5R4h6G01hgeWeuFo78hKRv7vEL52A\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/GaD9SEujq0YZgbgwnhtQCratumfSa36Z/4lV8IHJubP56hJsPAevuOrkNuulKg7Gm\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"SWy5R4h6G01hgeWeuFo78hKRv7vEL52A\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/GaD9SEujq0YZgbgwnhtQCratumfSa36Z/GUpkC5gnvBGdNei8HobqlogOUEHZxTDm\"}],\"wildcard\":false,\"expires\":\"2026-08-28T10:31:51Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7605053.818480] ca acme-order-renew-ca.foo-start[310]: 2026/08/27 10:31:51 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/GaD9SEujq0YZgbgwnhtQCratumfSa36Z container-test-run-certificates> ca # [7605053.818480] ca acme-order-renew-ca.foo-start[310]: 2026/08/27 10:31:51 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [7605053.818480] ca acme-order-renew-ca.foo-start[310]: 2026/08/27 10:31:51 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [7605053.818480] ca acme-order-renew-ca.foo-start[310]: 2026/08/27 10:31:51 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [7605053.820060] ca step-ca[204]: time="2026-08-27T10:31:51Z" level=info duration=1.574074ms duration-ns=1574074 fields.time="2026-08-27T10:31:51Z" method=POST name=ca nonce=RjA0bmprMnYzQ0xFM1Z1S1FWMkFDNkxUVktDd05ISFg path=/acme/acme/challenge/GaD9SEujq0YZgbgwnhtQCratumfSa36Z/4lV8IHJubP56hJsPAevuOrkNuulKg7Gm protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=02def66c-20c8-459c-8e5e-5dcf2dce6021 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"SWy5R4h6G01hgeWeuFo78hKRv7vEL52A\",\"validated\":\"2026-08-27T10:31:51Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/GaD9SEujq0YZgbgwnhtQCratumfSa36Z/4lV8IHJubP56hJsPAevuOrkNuulKg7Gm\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7605053.820145] ca acme-order-renew-ca.foo-start[310]: 2026/08/27 10:31:51 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [7605053.820171] ca acme-order-renew-ca.foo-start[310]: 2026/08/27 10:31:51 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [7605053.822234] ca step-ca[204]: time="2026-08-27T10:31:51Z" level=info duration=1.821261ms duration-ns=1821261 fields.time="2026-08-27T10:31:51Z" method=POST name=ca nonce=RjdjZ1dTQ1NKZEVPajBUU1RIYXZJZGoxSzVoY09VQ1Y path=/acme/acme/order/Crvi7b2wgXzWbVMif9F1BTNQrZ7GQ2bF/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=4d19156b-c041-4ea6-b3fb-3581c87db124 response="{\"id\":\"Crvi7b2wgXzWbVMif9F1BTNQrZ7GQ2bF\",\"status\":\"valid\",\"expires\":\"2026-08-28T10:31:51Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-27T10:30:51Z\",\"notAfter\":\"2026-11-25T10:31:51Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/GaD9SEujq0YZgbgwnhtQCratumfSa36Z\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/Crvi7b2wgXzWbVMif9F1BTNQrZ7GQ2bF/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/BJWwPkC8rvvH2HBrTkNVoqqOYoU3pn07\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7605053.822819] ca step-ca[204]: time="2026-08-27T10:31:51Z" level=info certificate="MIIB1DCCAXmgAwIBAgIQBKH5zoflY8K2mnN8GyPkBDAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MjcxMDMwNTFaFw0yNjExMjUxMDMxNTFaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABMOSbRNEw6opWAjI35zwE/gqSGhGMsKY3l4LoFyCmSAzyaUDLpgiXPKUiPF196DBzbcPysMmQhShGpL/nFJ7XjejgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUO6HJPIO7uZftpEmlwO4aqudvzWcwHwYDVR0jBBgwFoAU3QubZJ5CQUCWzj+rypbQu+tplKkwEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNJADBGAiEAo+CXIF5Se0FadyDmBSIo4nJPeq/ZIqW8G2jJAiPMdoYCIQCBhjo2OaedXxFPTXEuLPV50zPuaNcoynimp12QjL400Q==" duration="398.18µs" duration-ns=398180 fields.time="2026-08-27T10:31:51Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=b0VtWHZPUXhCbEl5UFc4ZW01S3NjV2FScGZacVU2cHI path=/acme/acme/certificate/BJWwPkC8rvvH2HBrTkNVoqqOYoU3pn07 protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=8dcc4cc2-bea6-46dd-b4a7-f9e9e4e6e320 sans="map[dns:[ca.foo]]" serial=6157938460414349388879190277316928516 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-08-27T10:30:51Z" valid-to="2026-11-25T10:31:51Z" container-test-run-certificates> ca # [7605053.822876] ca acme-order-renew-ca.foo-start[310]: 2026/08/27 10:31:51 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [7605053.825137] ca acme-order-renew-ca.foo-start[298]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [7605053.826201] ca acme-order-renew-ca.foo-start[298]: + touch out/acme-success container-test-run-certificates> ca # [7605053.827017] ca acme-order-renew-ca.foo-start[298]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [7605053.827634] ca acme-order-renew-ca.foo-start[298]: + touch out/renewed container-test-run-certificates> ca # [7605053.828428] ca acme-order-renew-ca.foo-start[298]: + echo Installing new certificate container-test-run-certificates> ca # [7605053.828428] ca acme-order-renew-ca.foo-start[298]: Installing new certificate container-test-run-certificates> ca # [7605053.828449] ca acme-order-renew-ca.foo-start[298]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [7605053.829208] ca acme-order-renew-ca.foo-start[331]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [7605053.829350] ca acme-order-renew-ca.foo-start[298]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [7605053.830103] ca acme-order-renew-ca.foo-start[332]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [7605053.830256] ca acme-order-renew-ca.foo-start[298]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [7605053.831054] ca acme-order-renew-ca.foo-start[333]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [7605053.831230] ca acme-order-renew-ca.foo-start[298]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [7605053.832058] ca acme-order-renew-ca.foo-start[298]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [7605053.832986] ca acme-order-renew-ca.foo-start[298]: + for fixpath in out certificates container-test-run-certificates> ca # [7605053.832996] ca acme-order-renew-ca.foo-start[298]: + '[' -d out ']' container-test-run-certificates> ca # [7605053.832996] ca acme-order-renew-ca.foo-start[298]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [7605053.833812] ca acme-order-renew-ca.foo-start[298]: + chown -R acme:nginx out container-test-run-certificates> ca # [7605053.835123] ca acme-order-renew-ca.foo-start[298]: + for fixpath in out certificates container-test-run-certificates> ca # [7605053.835133] ca acme-order-renew-ca.foo-start[298]: + '[' -d certificates ']' container-test-run-certificates> ca # [7605053.835133] ca acme-order-renew-ca.foo-start[298]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [7605053.835949] ca acme-order-renew-ca.foo-start[298]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [7605053.837148] ca acme-order-renew-ca.foo-start[298]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [7605053.919395] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [7605053.921748] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [7605053.921843] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> ca # [7605054.253045] ca nginx[349]: nginx: the configuration file /nix/store/qy667v7x86g27a1fq9zsc0f3ainxp9il-nginx.conf syntax is ok container-test-run-certificates> ca # [7605054.253188] ca nginx[349]: nginx: configuration file /nix/store/qy667v7x86g27a1fq9zsc0f3ainxp9il-nginx.conf test is successful container-test-run-certificates> ca # [7605054.583698] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [7605054.583853] ca systemd[1]: Startup finished in 3.076s. container-test-run-certificates> ca # [7605054.891030] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 1.10 seconds) container-test-run-certificates> ca # [7605055.229106] ca acme-order-renew-ca.foo-start[364]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [7605055.230943] ca acme-order-renew-ca.foo-start[364]: + set -euo pipefail container-test-run-certificates> ca # [7605055.231076] ca acme-order-renew-ca.foo-start[364]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [7605055.231076] ca acme-order-renew-ca.foo-start[364]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [7605055.231699] ca acme-order-renew-ca.foo-start[364]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [7605055.231699] ca acme-order-renew-ca.foo-start[364]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [7605055.231962] ca acme-order-renew-ca.foo-start[372]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [7605055.233328] ca acme-order-renew-ca.foo-start[364]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [7605055.233328] ca acme-order-renew-ca.foo-start[364]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [7605055.253931] ca step-ca[204]: time="2026-08-27T10:31:52Z" level=info duration="34.746µs" duration-ns=34746 fields.time="2026-08-27T10:31:52Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=f06cd098-a175-4be0-973d-ae4419bd016c response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7605055.254279] ca acme-order-renew-ca.foo-start[373]: 2026/08/27 10:31:52 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [7605055.254279] ca acme-order-renew-ca.foo-start[373]: 2026/08/27 10:31:52 [INFO] [ca.foo] The certificate expires at 2026-11-25T10:31:51Z, the renewal can be performed in 1439h59m38.380211287s: no renewal. container-test-run-certificates> ca # [7605055.254388] ca acme-order-renew-ca.foo-start[364]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [7605055.255360] ca acme-order-renew-ca.foo-start[364]: + touch out/acme-success container-test-run-certificates> ca # [7605055.256256] ca acme-order-renew-ca.foo-start[364]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [7605055.256864] ca acme-order-renew-ca.foo-start[364]: + for fixpath in out certificates container-test-run-certificates> ca # [7605055.256875] ca acme-order-renew-ca.foo-start[364]: + '[' -d out ']' container-test-run-certificates> ca # [7605055.256886] ca acme-order-renew-ca.foo-start[364]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [7605055.257711] ca acme-order-renew-ca.foo-start[364]: + chown -R acme:nginx out container-test-run-certificates> ca # [7605055.259306] ca acme-order-renew-ca.foo-start[364]: + for fixpath in out certificates container-test-run-certificates> ca # [7605055.259306] ca acme-order-renew-ca.foo-start[364]: + '[' -d certificates ']' container-test-run-certificates> ca # [7605055.259343] ca acme-order-renew-ca.foo-start[364]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [7605055.260258] ca acme-order-renew-ca.foo-start[364]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [7605055.261499] ca acme-order-renew-ca.foo-start[364]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [7605055.343976] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [7605055.344130] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [7605058.350583] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [7605058.350663] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [7605058.351221] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [7605058.351975] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.34 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1008 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 27 10:31:50 2026 GMT container-test-run-certificates> * expire date: Sep 26 10:31:50 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 6a5089 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [7605058.672595] server acme-test.foo-start[305]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7605058.674551] server acme-test.foo-start[305]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [7605058.674551] server acme-test.foo-start[305]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [7605058.679013] server acme-test.foo-start[316]: + cd test.foo container-test-run-certificates> server # [7605058.679174] server acme-test.foo-start[316]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [7605058.680006] server acme-test.foo-start[317]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [7605058.680137] server acme-test.foo-start[316]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [7605058.680794] server acme-test.foo-start[316]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [7605058.680929] server acme-test.foo-start[305]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [7605058.681865] server acme-test.foo-start[305]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [7605058.683084] server acme-test.foo-start[305]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [7605058.683991] server acme-test.foo-start[305]: + for fixpath in out certificates container-test-run-certificates> server # [7605058.683991] server acme-test.foo-start[305]: + '[' -d out ']' container-test-run-certificates> server # [7605058.683991] server acme-test.foo-start[305]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [7605058.684793] server acme-test.foo-start[305]: + chown -R acme:nginx out container-test-run-certificates> server # [7605058.686146] server acme-test.foo-start[305]: + for fixpath in out certificates container-test-run-certificates> server # [7605058.686146] server acme-test.foo-start[305]: + '[' -d certificates ']' container-test-run-certificates> server # [7605058.687529] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [7605058.688559] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [7605059.015301] server acme-order-renew-test.foo-start[324]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7605059.016994] server acme-order-renew-test.foo-start[324]: + set -euo pipefail container-test-run-certificates> server # [7605059.017060] server acme-order-renew-test.foo-start[324]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [7605059.017090] server acme-order-renew-test.foo-start[324]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [7605059.017866] server acme-order-renew-test.foo-start[324]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [7605059.039585] server acme-order-renew-test.foo-start[332]: 2026/08/27 10:31:56 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [7605059.094203] server acme-order-renew-test.foo-start[332]: !!!! HEADS UP !!!! container-test-run-certificates> server # [7605059.094203] server acme-order-renew-test.foo-start[332]: Your account credentials have been saved in your container-test-run-certificates> server # [7605059.094203] server acme-order-renew-test.foo-start[332]: configuration directory at "accounts". container-test-run-certificates> server # [7605059.094203] server acme-order-renew-test.foo-start[332]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [7605059.094203] server acme-order-renew-test.foo-start[332]: configuration directory will also contain private keys container-test-run-certificates> server # [7605059.094203] server acme-order-renew-test.foo-start[332]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [7605059.094203] server acme-order-renew-test.foo-start[332]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [7605059.094203] server acme-order-renew-test.foo-start[332]: 2026/08/27 10:31:56 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [7605059.155955] server acme-order-renew-test.foo-start[332]: 2026/08/27 10:31:56 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/xPJWY9VhhWyQH7RVPKm8J0e1Eam385Z6 container-test-run-certificates> server # [7605059.155955] server acme-order-renew-test.foo-start[332]: 2026/08/27 10:31:56 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [7605059.155955] server acme-order-renew-test.foo-start[332]: 2026/08/27 10:31:56 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [7605059.155955] server acme-order-renew-test.foo-start[332]: 2026/08/27 10:31:56 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [7605059.158592] server acme-order-renew-test.foo-start[332]: 2026/08/27 10:31:56 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [7605059.158622] server acme-order-renew-test.foo-start[332]: 2026/08/27 10:31:56 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [7605059.162624] server acme-order-renew-test.foo-start[332]: 2026/08/27 10:31:56 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [7605059.165236] server acme-order-renew-test.foo-start[324]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [7605059.166123] server acme-order-renew-test.foo-start[324]: + touch out/acme-success container-test-run-certificates> server # [7605059.167148] server acme-order-renew-test.foo-start[324]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [7605059.167648] server acme-order-renew-test.foo-start[324]: + touch out/renewed container-test-run-certificates> server # [7605059.168358] server acme-order-renew-test.foo-start[324]: + echo Installing new certificate container-test-run-certificates> server # [7605059.168358] server acme-order-renew-test.foo-start[324]: Installing new certificate container-test-run-certificates> server # [7605059.168381] server acme-order-renew-test.foo-start[324]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [7605059.169035] server acme-order-renew-test.foo-start[353]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [7605059.169184] server acme-order-renew-test.foo-start[324]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [7605059.169816] server acme-order-renew-test.foo-start[354]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [7605059.169918] server acme-order-renew-test.foo-start[324]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [7605059.170573] server acme-order-renew-test.foo-start[355]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [7605059.170679] server acme-order-renew-test.foo-start[324]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [7605059.171457] server acme-order-renew-test.foo-start[324]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [7605059.172253] server acme-order-renew-test.foo-start[324]: + for fixpath in out certificates container-test-run-certificates> server # [7605059.172264] server acme-order-renew-test.foo-start[324]: + '[' -d out ']' container-test-run-certificates> server # [7605059.172264] server acme-order-renew-test.foo-start[324]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [7605059.172998] server acme-order-renew-test.foo-start[324]: + chown -R acme:nginx out container-test-run-certificates> server # [7605059.174302] server acme-order-renew-test.foo-start[324]: + for fixpath in out certificates container-test-run-certificates> server # [7605059.174320] server acme-order-renew-test.foo-start[324]: + '[' -d certificates ']' container-test-run-certificates> server # [7605059.174320] server acme-order-renew-test.foo-start[324]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [7605059.175051] server acme-order-renew-test.foo-start[324]: + chown -R acme:nginx certificates container-test-run-certificates> server # [7605059.176562] server acme-order-renew-test.foo-start[324]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> server # [7605059.257242] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [7605059.259144] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [7605059.259231] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> ca # [7605059.039414] ca step-ca[204]: time="2026-08-27T10:31:56Z" level=info duration="35.316µs" duration-ns=35316 fields.time="2026-08-27T10:31:56Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=6419c267-7f78-4dc6-a23a-b06ebbb3f713 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7605059.090746] ca step-ca[204]: time="2026-08-27T10:31:56Z" level=info duration=50.384084ms duration-ns=50384084 fields.time="2026-08-27T10:31:56Z" method=HEAD name=ca nonce=elF5OXppZ0wwcU14Z1AwVk1ma2dKaklzVjlUWm1TTTI path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=12355ad5-90bc-45d5-9c7f-660de677f4eb size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7605059.094024] ca step-ca[204]: time="2026-08-27T10:31:56Z" level=info duration=2.340297ms duration-ns=2340297 fields.time="2026-08-27T10:31:56Z" method=POST name=ca nonce=aWlMTVJJc3hVbkhPc2xpM3ZadU9TVjNBT3FBUE1UUmU path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=8d6ec4b8-ab64-42eb-becf-b4793f6d6f54 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/TT0WYc9d2lQ5sZwrfQi64bDkcyw2MJlp/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7605059.096140] ca step-ca[204]: time="2026-08-27T10:31:56Z" level=info duration=1.322672ms duration-ns=1322672 fields.time="2026-08-27T10:31:56Z" method=POST name=ca nonce=ajlKV01iaVdmc3VkaktOMWtXR1BrN2pEMUcxQ295S2U path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=29e33e26-1a8b-4565-833f-b69d5a2cf365 response="{\"id\":\"uwqCg8rtLaqh1xKnSVwzIv3t71b2kCjP\",\"status\":\"pending\",\"expires\":\"2026-08-28T10:31:56Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-27T10:30:56Z\",\"notAfter\":\"2026-11-25T10:31:56Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/xPJWY9VhhWyQH7RVPKm8J0e1Eam385Z6\"],\"finalize\":\"https://ca.foo/acme/acme/order/uwqCg8rtLaqh1xKnSVwzIv3t71b2kCjP/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7605059.155728] ca step-ca[204]: time="2026-08-27T10:31:56Z" level=info duration=2.328726ms duration-ns=2328726 fields.time="2026-08-27T10:31:56Z" method=POST name=ca nonce=aWJicTBTak5zbm5SVWs4RFZyNDJaOW0yRGZzbGdUUXQ path=/acme/acme/authz/xPJWY9VhhWyQH7RVPKm8J0e1Eam385Z6 protocol=HTTP/1.1 referer= remote-address="::1" request-id=7e40af78-7a76-4320-9cbe-66f0edee4689 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"SjZObDW5MwVqzF7brP3zMSBtPTuGCOL1\",\"url\":\"https://ca.foo/acme/acme/challenge/xPJWY9VhhWyQH7RVPKm8J0e1Eam385Z6/NmJbtyfI5iWmLCzpgg6f4HucGr7tKu7n\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"SjZObDW5MwVqzF7brP3zMSBtPTuGCOL1\",\"url\":\"https://ca.foo/acme/acme/challenge/xPJWY9VhhWyQH7RVPKm8J0e1Eam385Z6/SZAk0HPmrag1EF3tCnZztm1bpSG6aM7B\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"SjZObDW5MwVqzF7brP3zMSBtPTuGCOL1\",\"url\":\"https://ca.foo/acme/acme/challenge/xPJWY9VhhWyQH7RVPKm8J0e1Eam385Z6/ZprEOEeakD5cqrSPm7tmZGQgjMMMfSyC\"}],\"wildcard\":false,\"expires\":\"2026-08-28T10:31:56Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7605059.158397] ca step-ca[204]: time="2026-08-27T10:31:56Z" level=info duration=1.685966ms duration-ns=1685966 fields.time="2026-08-27T10:31:56Z" method=POST name=ca nonce=Y1A0UGVXS3RZMUdSeG5EbDdKN3Y4bmxoS1NhcGlKNmU path=/acme/acme/challenge/xPJWY9VhhWyQH7RVPKm8J0e1Eam385Z6/SZAk0HPmrag1EF3tCnZztm1bpSG6aM7B protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=63e624a8-48b6-43e5-b91f-39bcb4598ca7 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"SjZObDW5MwVqzF7brP3zMSBtPTuGCOL1\",\"validated\":\"2026-08-27T10:31:56Z\",\"url\":\"https://ca.foo/acme/acme/challenge/xPJWY9VhhWyQH7RVPKm8J0e1Eam385Z6/SZAk0HPmrag1EF3tCnZztm1bpSG6aM7B\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7605059.161260] ca step-ca[204]: time="2026-08-27T10:31:56Z" level=info duration=1.900079ms duration-ns=1900079 fields.time="2026-08-27T10:31:56Z" method=POST name=ca nonce=ZTZxQ1ZoRFlvb3FxQkV2RGs4WmdFSnFZbWFnaWZQOEw path=/acme/acme/order/uwqCg8rtLaqh1xKnSVwzIv3t71b2kCjP/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=7425f8ab-63bb-4351-b5ec-140a04033676 response="{\"id\":\"uwqCg8rtLaqh1xKnSVwzIv3t71b2kCjP\",\"status\":\"valid\",\"expires\":\"2026-08-28T10:31:56Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-27T10:30:56Z\",\"notAfter\":\"2026-11-25T10:31:56Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/xPJWY9VhhWyQH7RVPKm8J0e1Eam385Z6\"],\"finalize\":\"https://ca.foo/acme/acme/order/uwqCg8rtLaqh1xKnSVwzIv3t71b2kCjP/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/S63C207wPN5i4t0UwDUYiIKet3Ay8KGr\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7605059.162508] ca step-ca[204]: time="2026-08-27T10:31:56Z" level=info certificate="MIIB2DCCAX6gAwIBAgIRAIvPRMuTRT/rkH/MvmyfHl0wCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODI3MTAzMDU2WhcNMjYxMTI1MTAzMTU2WjATMREwDwYDVQQDEwh0ZXN0LmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABJXoJ9zOt5WbAAgGvZwUTPkCKAknAChwEXFHtn2PWvPG+Woq0B+UUlj1FzVmsF1+gG2oi22BF+v7wZ8oMz34v9ajgaYwgaMwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUzsFXofmTdl9+dyWyQrqk8t75MLEwHwYDVR0jBBgwFoAU3QubZJ5CQUCWzj+rypbQu+tplKkwEwYDVR0RBAwwCoIIdGVzdC5mb28wHQYMKwYBBAGCpGTGKEABBA0wCwIBBgQEYWNtZQQAMAoGCCqGSM49BAMCA0gAMEUCIQCbxMZnqKsstO3cYcFTypJ3dvK1DZFxwpWM6b3eqgIavAIgDDH3t2GA+V8L1uCujk1U7Kx/GctIMadW6iwGjuyvvRQ=" duration="509.99µs" duration-ns=509990 fields.time="2026-08-27T10:31:56Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=TWdCWlBUaE5ZWE1qcnhLd2tyUlhRVkdxaUJxbUFtU20 path=/acme/acme/certificate/S63C207wPN5i4t0UwDUYiIKet3Ay8KGr protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=fa239591-83d8-43ed-a54d-d6a0618f7747 sans="map[dns:[test.foo]]" serial=185838892196568068541761032628358553181 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-08-27T10:30:56Z" valid-to="2026-11-25T10:31:56Z" container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1008 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [112 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 27 10:31:50 2026 GMT container-test-run-certificates> * expire date: Sep 26 10:31:50 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 6a5089 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [7605059.594802] server nginx[371]: nginx: the configuration file /nix/store/nfgk30pbmji62whlqlbylrn263ifbnzr-nginx.conf syntax is ok container-test-run-certificates> server # [7605059.595021] server nginx[371]: nginx: configuration file /nix/store/nfgk30pbmji62whlqlbylrn263ifbnzr-nginx.conf test is successful container-test-run-certificates> server # [7605059.920899] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [931 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [79 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 27 10:30:56 2026 GMT container-test-run-certificates> * expire date: Nov 25 10:31:56 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 36556 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 1829 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 2.06 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> 8b:cf:44:cb:93:45:3f:eb:90:7f:cc:be:6c:9f:1e:5d container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Aug 27 10:30:56 2026 GMT container-test-run-certificates> Not After : Nov 25 10:31:56 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:95:e8:27:dc:ce:b7:95:9b:00:08:06:bd:9c:14: container-test-run-certificates> 4c:f9:02:28:09:27:00:28:70:11:71:47:b6:7d:8f: container-test-run-certificates> 5a:f3:c6:f9:6a:2a:d0:1f:94:52:58:f5:17:35:66: container-test-run-certificates> b0:5d:7e:80:6d:a8:8b:6d:81:17:eb:fb:c1:9f:28: container-test-run-certificates> 33:3d:f8:bf:d6 container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> CE:C1:57:A1:F9:93:76:5F:7E:77:25:B2:42:BA:A4:F2:DE:F9:30:B1 container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> DD:0B:9B:64:9E:42:41:40:96:CE:3F:AB:CA:96:D0:BB:EB:69:94:A9 container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:45:02:21:00:9b:c4:c6:67:a8:ab:2c:b4:ed:dc:61:c1:53: container-test-run-certificates> ca:92:77:76:f2:b5:0d:91:71:c2:95:8c:e9:bd:de:aa:02:1a: container-test-run-certificates> bc:02:20:0c:31:f7:b7:61:80:f9:5f:0b:d6:e0:ae:8e:4d:54: container-test-run-certificates> ec:ac:7f:19:cb:48:31:a7:56:ea:2c:06:8e:ec:af:bd:14 container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.02 seconds) container-test-run-certificates> (finished: run the VM test script, in 9.52 seconds) container-test-run-certificates> test script finished in 10.02s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> kill NspawnMachine (pid 53) container-test-run-certificates> kill NspawnMachine (pid 55) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> Container server terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.29 seconds) post-build step Upload to niks3: ok time=2026-08-27T10:31:59.195Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-27T10:31:59.819Z level=INFO msg="Uploading 1 narinfos" time=2026-08-27T10:32:00.385Z level=INFO msg="Upload complete. (1.277s)"