nixbot

builds

succeeded container-test-run-certificates checks.aarch64-linux.certificates · build #513 · raw

1Machine state will be reset. To keep it, pass --keep-machine-state2start all VLans3(finished: start all VLans, in 0.00 seconds)45Test will time out and terminate in 3600.0 seconds6run the VM test script7additionally exposed symbols:8 ca, client, server,9 vlan1,10 start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh11start all VMs12ca: systemd-nspawn running (pid 52)13client: systemd-nspawn running (pid 55)14ca: Waiting for journal at /build/vm-state-ca/var/log/journal...15client: Waiting for journal at /build/vm-state-client/var/log/journal...16server: systemd-nspawn running (pid 59)17server: Waiting for journal at /build/vm-state-server/var/log/journal...18(finished: start all VMs, in 0.00 seconds)19nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE20nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.21nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE22nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.23nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE24nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.25Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.26Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.27Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.28░ Spawning container server on /build/vm-state-server.29░ Spawning container ca on /build/vm-state-ca.30░ Spawning container client on /build/vm-state-client.31ca # [6900449.562297] ca systemd-journald[78]: Journal started32ca # [6900449.562354] ca systemd-journald[78]: Runtime Journal (/run/log/journal/9149141571bc46b7b4b3f17fccf9695f) is 8M, max 2.5G, 2.4G free.33ca # [6900449.568719] ca systemd[1]: Starting Flush Journal to Persistent Storage...34ca # [6900449.569509] ca systemd[1]: Starting Network Name Resolution...35ca # [6900449.570169] ca systemd[1]: Starting Create Static Device Nodes in /dev...36ca # [6900449.579389] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/9149141571bc46b7b4b3f17fccf9695f is 1.450ms for 5 entries.37ca # [6900449.579389] ca systemd-journald[78]: System Journal (/var/log/journal/9149141571bc46b7b4b3f17fccf9695f) is 8M, max 4G, 3.9G free.38ca # [6900449.583997] ca systemd[1]: Finished Create Static Device Nodes in /dev.39ca # [6900449.584246] ca systemd[1]: Reached target Preparation for Local File Systems.40ca # [6900449.584332] ca systemd[1]: Reached target Local File Systems.41ca # [6900449.585058] ca systemd[1]: Listening on Boot Loader Control Service Socket.42ca # [6900449.585103] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container43ca # [6900449.585944] ca systemd[1]: Starting Save Transient machine-id to Disk...44ca # [6900449.585974] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys45ca # [6900449.593288] ca systemd[1]: Finished Flush Journal to Persistent Storage.46ca # [6900449.594857] ca systemd[1]: Starting Create System Files and Directories...47ca # [6900449.612094] ca systemd-tmpfiles[120]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted48ca # [6900449.612292] ca systemd-tmpfiles[120]: fchmod() of /var/log/journal failed: Operation not permitted49ca # [6900449.612429] ca systemd-tmpfiles[120]: fchmod() of /var/log/journal/9149141571bc46b7b4b3f17fccf9695f failed: Operation not permitted50ca # [6900449.612625] ca systemd-tmpfiles[120]: fchmod() of /run/log/journal failed: Operation not permitted51ca # [6900449.614233] ca systemd[1]: Finished Create System Files and Directories.52ca # [6900449.615302] ca systemd[1]: Starting Rebuild Journal Catalog...53ca # [6900449.616144] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP...54ca # [6900449.627532] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP.55server # [6900449.572161] server systemd-journald[69]: Journal started56server # [6900449.572228] server systemd-journald[69]: Runtime Journal (/run/log/journal/0bddfca937cf48e0b3e337a7fab2e296) is 8M, max 2.5G, 2.4G free.57server # [6900449.579286] server systemd[1]: Starting Flush Journal to Persistent Storage...58server # [6900449.580223] server systemd[1]: Starting Network Name Resolution...59server # [6900449.580861] server systemd[1]: Starting Create Static Device Nodes in /dev...60server # [6900449.589920] server systemd-journald[69]: Time spent on flushing to /var/log/journal/0bddfca937cf48e0b3e337a7fab2e296 is 1.974ms for 5 entries.61server # [6900449.589920] server systemd-journald[69]: System Journal (/var/log/journal/0bddfca937cf48e0b3e337a7fab2e296) is 8M, max 4G, 3.9G free.62server # [6900449.594249] server systemd[1]: Finished Create Static Device Nodes in /dev.63server # [6900449.594485] server systemd[1]: Reached target Preparation for Local File Systems.64server # [6900449.594569] server systemd[1]: Reached target Local File Systems.65server # [6900449.595356] server systemd[1]: Listening on Boot Loader Control Service Socket.66server # [6900449.595402] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container67server # [6900449.596491] server systemd[1]: Starting Save Transient machine-id to Disk...68server # [6900449.596523] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys69server # [6900449.607139] server systemd[1]: Finished Flush Journal to Persistent Storage.70server # [6900449.608518] server systemd[1]: Starting Create System Files and Directories...71server # [6900449.625568] server systemd-tmpfiles[112]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted72server # [6900449.625776] server systemd-tmpfiles[112]: fchmod() of /var/log/journal failed: Operation not permitted73server # [6900449.625911] server systemd-tmpfiles[112]: fchmod() of /var/log/journal/0bddfca937cf48e0b3e337a7fab2e296 failed: Operation not permitted74server # [6900449.626119] server systemd-tmpfiles[112]: fchmod() of /run/log/journal failed: Operation not permitted75server # [6900449.628006] server systemd[1]: Finished Create System Files and Directories.76server # [6900449.629039] server systemd[1]: Starting Rebuild Journal Catalog...77server # [6900449.629892] server systemd[1]: Starting Record System Boot/Shutdown in UTMP...78client # [6900449.605373] client systemd-journald[69]: Journal started79client # [6900449.605431] client systemd-journald[69]: Runtime Journal (/run/log/journal/8a7e8a04744440c18cd94d6fa216f301) is 8M, max 2.5G, 2.4G free.80client # [6900449.608333] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully.81client # [6900449.616866] client systemd[1]: Starting Flush Journal to Persistent Storage...82client # [6900449.617675] client systemd[1]: Starting Network Name Resolution...83client # [6900449.618367] client systemd[1]: Starting Create Static Device Nodes in /dev...84client # [6900449.627356] client systemd-journald[69]: Time spent on flushing to /var/log/journal/8a7e8a04744440c18cd94d6fa216f301 is 1.622ms for 6 entries.85client # [6900449.627356] client systemd-journald[69]: System Journal (/var/log/journal/8a7e8a04744440c18cd94d6fa216f301) is 8M, max 4G, 3.9G free.86client # [6900449.634884] client systemd[1]: Finished Create Static Device Nodes in /dev.87client # [6900449.635142] client systemd[1]: Reached target Preparation for Local File Systems.88client # [6900449.635228] client systemd[1]: Reached target Local File Systems.89client # [6900449.635958] client systemd[1]: Listening on Boot Loader Control Service Socket.90client # [6900449.636025] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container91client # [6900449.636916] client systemd[1]: Starting Save Transient machine-id to Disk...92client # [6900449.636953] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys93client # [6900449.641505] client systemd[1]: Finished Flush Journal to Persistent Storage.94client # [6900449.642444] client systemd[1]: Starting Create System Files and Directories...95client # [6900449.658152] client systemd-tmpfiles[115]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted96client # [6900449.658400] client systemd-tmpfiles[115]: fchmod() of /var/log/journal failed: Operation not permitted97client # [6900449.658582] client systemd-tmpfiles[115]: fchmod() of /var/log/journal/8a7e8a04744440c18cd94d6fa216f301 failed: Operation not permitted98client # [6900449.658849] client systemd-tmpfiles[115]: fchmod() of /run/log/journal failed: Operation not permitted99client # [6900449.660315] client systemd[1]: Finished Create System Files and Directories.100client # [6900449.661376] client systemd[1]: Starting Rebuild Journal Catalog...101client # [6900449.662119] client systemd[1]: Starting Record System Boot/Shutdown in UTMP...102client # [6900449.673919] client systemd[1]: Finished Record System Boot/Shutdown in UTMP.103client # [6900449.680628] client systemd[1]: Finished Rebuild Journal Catalog.104client # [6900449.681814] client systemd[1]: Starting Update is Completed...105client # [6900449.693821] client systemd[1]: Finished Update is Completed.106client # [6900449.760264] client systemd[1]: Finished Firewall.107client # [6900449.760439] client systemd[1]: Reached target Preparation for Network.108client # [6900449.760646] client systemd[1]: Listening on Network Management Resolve Hook Socket.109client # [6900449.761641] client systemd[1]: Starting Network Management...110client # [6900449.785734] client systemd[1]: Finished Save Transient machine-id to Disk.111ca # [6900449.637370] ca systemd[1]: Finished Rebuild Journal Catalog.112ca # [6900449.638497] ca systemd[1]: Starting Update is Completed...113ca # [6900449.648608] ca systemd[1]: Finished Update is Completed.114ca # [6900449.717915] ca systemd[1]: Finished Firewall.115ca # [6900449.718070] ca systemd[1]: Reached target Preparation for Network.116ca # [6900449.718294] ca systemd[1]: Listening on Network Management Resolve Hook Socket.117ca # [6900449.719364] ca systemd[1]: Starting Network Management...118ca # [6900449.787754] ca systemd[1]: Finished Save Transient machine-id to Disk.119server # [6900449.642915] server systemd[1]: Finished Record System Boot/Shutdown in UTMP.120server # [6900449.648108] server systemd[1]: Finished Rebuild Journal Catalog.121server # [6900449.649155] server systemd[1]: Starting Update is Completed...122server # [6900449.660266] server systemd[1]: Finished Update is Completed.123server # [6900449.724101] server systemd[1]: Finished Firewall.124server # [6900449.724253] server systemd[1]: Reached target Preparation for Network.125server # [6900449.724472] server systemd[1]: Listening on Network Management Resolve Hook Socket.126server # [6900449.760307] server systemd[1]: Starting Network Management...127server # [6900449.786735] server systemd[1]: Finished Save Transient machine-id to Disk.128server # [6900450.189753] server systemd-networkd[186]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted129server # [6900450.189851] server systemd-networkd[186]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted130server # [6900450.196779] server systemd-networkd[186]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.131server # [6900450.196958] server systemd-networkd[186]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.132server # [6900450.197098] server systemd-networkd[186]: lo: Link UP133server # [6900450.197102] server systemd-networkd[186]: lo: Gained carrier134server # [6900450.197267] server systemd-networkd[186]: eth1: Configuring with /etc/systemd/network/40-eth1.network.135server # [6900450.197620] server systemd[1]: Started Network Management.136server # [6900450.197723] server systemd-networkd[186]: eth1: Link UP137server # [6900450.197946] server systemd-networkd[186]: eth1: Gained carrier138server # [6900450.198665] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd...139server # [6900450.273500] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd.140server # [6900450.294883] server systemd-resolved[91]: Positive Trust Anchors:141server # [6900450.294895] server systemd-resolved[91]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d142server # [6900450.294899] server systemd-resolved[91]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16143server # [6900450.294932] server systemd-resolved[91]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test144server # [6900450.317637] server systemd-resolved[91]: Using system hostname 'server'.145server # [6900450.319032] server systemd[1]: Started Network Name Resolution.146server # [6900450.319123] server systemd[1]: Reached target Network.147server # [6900450.319199] server systemd[1]: Reached target Network is Online.148server # [6900450.319249] server systemd[1]: Reached target System Initialization.149server # [6900450.319506] server systemd[1]: Started Renew ACME Certificate for test.foo.150server # [6900450.319539] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container151server # [6900450.319569] server systemd[1]: Started Daily Cleanup of Temporary Directories.152server # [6900450.319588] server systemd[1]: Reached target Timer Units.153server # [6900450.319735] server systemd[1]: Listening on D-Bus System Message Bus Socket.154server # [6900450.319854] server systemd[1]: Listening on Nix Daemon Socket.155server # [6900450.319981] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.156server # [6900450.320025] server systemd[1]: Reached target Socket Units.157server # [6900450.320084] server systemd[1]: Reached target Basic System.158server # [6900450.321526] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure...159server # [6900450.322542] server systemd[1]: Starting Import lastlog data into lastlog2 database...160server # [6900450.322589] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem161server # [6900450.323595] server systemd[1]: Starting Name Service Cache Daemon (nsncd)...162server # [6900450.325138] server systemd[1]: Starting D-Bus System Message Bus...163server # [6900450.343378] server systemd[1]: Finished Import lastlog data into lastlog2 database.164server # [6900450.439155] server acme-setup-privileged[192]: + set -euo pipefail165server # [6900450.439155] server acme-setup-privileged[192]: + cd /var/lib/acme166server # [6900450.439460] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts167server # [6900450.440574] server acme-setup-privileged[192]: + chown -R acme .lego/accounts168client # [6900450.186951] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted169client # [6900450.187044] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted170client # [6900450.193917] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.171client # [6900450.194073] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.172client # [6900450.194223] client systemd-networkd[182]: lo: Link UP173client # [6900450.194227] client systemd-networkd[182]: lo: Gained carrier174client # [6900450.194398] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network.175client # [6900450.194778] client systemd[1]: Started Network Management.176client # [6900450.194863] client systemd-networkd[182]: eth1: Link UP177client # [6900450.195099] client systemd-networkd[182]: eth1: Gained carrier178client # [6900450.195863] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd...179client # [6900450.271914] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd.180client # [6900450.321871] client systemd-resolved[94]: Positive Trust Anchors:181client # [6900450.321884] client systemd-resolved[94]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d182client # [6900450.321888] client systemd-resolved[94]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16183client # [6900450.321924] client systemd-resolved[94]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test184client # [6900450.344710] client systemd-resolved[94]: Using system hostname 'client'.185client # [6900450.346093] client systemd[1]: Started Network Name Resolution.186client # [6900450.346180] client systemd[1]: Reached target Network.187client # [6900450.346254] client systemd[1]: Reached target System Initialization.188client # [6900450.346313] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container189client # [6900450.346346] client systemd[1]: Started Daily Cleanup of Temporary Directories.190client # [6900450.346365] client systemd[1]: Reached target Timer Units.191client # [6900450.346517] client systemd[1]: Listening on D-Bus System Message Bus Socket.192client # [6900450.346651] client systemd[1]: Listening on Nix Daemon Socket.193client # [6900450.346787] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.194client # [6900450.346813] client systemd[1]: Reached target Socket Units.195client # [6900450.346864] client systemd[1]: Reached target Basic System.196client # [6900450.348097] client systemd[1]: Starting Import lastlog data into lastlog2 database...197client # [6900450.349053] client systemd[1]: Starting Name Service Cache Daemon (nsncd)...198client # [6900450.350402] client systemd[1]: Starting D-Bus System Message Bus...199client # [6900450.368160] client systemd[1]: Finished Import lastlog data into lastlog2 database.200ca # [6900450.191029] ca systemd-networkd[195]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted201ca # [6900450.191114] ca systemd-networkd[195]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted202ca # [6900450.197963] ca systemd-networkd[195]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.203ca # [6900450.198135] ca systemd-networkd[195]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.204ca # [6900450.198269] ca systemd-networkd[195]: lo: Link UP205ca # [6900450.198272] ca systemd-networkd[195]: lo: Gained carrier206ca # [6900450.198455] ca systemd-networkd[195]: eth1: Configuring with /etc/systemd/network/40-eth1.network.207ca # [6900450.198807] ca systemd[1]: Started Network Management.208ca # [6900450.198897] ca systemd-networkd[195]: eth1: Link UP209ca # [6900450.199115] ca systemd-networkd[195]: eth1: Gained carrier210ca # [6900450.264323] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd...211ca # [6900450.270458] ca systemd-resolved[100]: Positive Trust Anchors:212ca # [6900450.270468] ca systemd-resolved[100]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d213ca # [6900450.270472] ca systemd-resolved[100]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16214ca # [6900450.270505] ca systemd-resolved[100]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test215ca # [6900450.276887] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd.216ca # [6900450.292675] ca systemd-resolved[100]: Using system hostname 'ca'.217ca # [6900450.294012] ca systemd[1]: Started Network Name Resolution.218ca # [6900450.294099] ca systemd[1]: Reached target Network.219ca # [6900450.294173] ca systemd[1]: Reached target Network is Online.220ca # [6900450.294229] ca systemd[1]: Reached target System Initialization.221ca # [6900450.294484] ca systemd[1]: Started Renew ACME Certificate for ca.foo.222ca # [6900450.294521] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container223ca # [6900450.294550] ca systemd[1]: Started Daily Cleanup of Temporary Directories.224ca # [6900450.294575] ca systemd[1]: Reached target Timer Units.225ca # [6900450.294726] ca systemd[1]: Listening on D-Bus System Message Bus Socket.226ca # [6900450.294847] ca systemd[1]: Listening on Nix Daemon Socket.227ca # [6900450.294976] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.228ca # [6900450.295002] ca systemd[1]: Reached target Socket Units.229ca # [6900450.295053] ca systemd[1]: Reached target Basic System.230ca # [6900450.296591] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure...231ca # [6900450.297557] ca systemd[1]: Starting Import lastlog data into lastlog2 database...232ca # [6900450.297603] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem233ca # [6900450.298870] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)...234ca # [6900450.300155] ca systemd[1]: Starting step-ca service...235ca # [6900450.301616] ca systemd[1]: Starting D-Bus System Message Bus...236ca # [6900450.319254] ca systemd[1]: Finished Import lastlog data into lastlog2 database.237ca # [6900450.416932] ca acme-setup-privileged[201]: + set -euo pipefail238ca # [6900450.416932] ca acme-setup-privileged[201]: + cd /var/lib/acme239ca # [6900450.416932] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts240ca # [6900450.418279] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts241ca # [6900450.419725] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo242ca # [6900450.419762] ca acme-setup-privileged[201]: + '[' -d ca.foo ']'243ca # [6900450.419762] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo244ca # [6900450.419762] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']'245ca # [6900450.461645] ca nsncd[203]: Aug 27 20:11:16.514 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"246ca # [6900450.464872] ca systemd[1]: Started Name Service Cache Daemon (nsncd).247ca # [6900450.465103] ca systemd[1]: Reached target Host and Network Name Lookups.248ca # [6900450.465215] ca systemd[1]: Reached target User and Group Name Lookups.249ca # [6900450.467440] ca systemd[1]: Starting User Login Management...250ca # [6900450.468722] ca systemd[1]: Starting Permit User Sessions...251ca # [6900450.480637] ca systemd[1]: Finished Permit User Sessions.252ca # [6900450.481773] ca systemd[1]: Started Console Getty.253ca # [6900450.481819] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0254ca # [6900450.481840] ca systemd[1]: Reached target Login Prompts.255ca # [6900450.551300] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully.256ca # [6900450.551431] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'...257ca # [6900450.552638] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync'258ca # [6900450.552771] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/nrvy3kisslkv7qydv3v2ib6szfdky5q3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"259ca # [6900450.553257] ca systemd[1]: Started D-Bus System Message Bus.260ca # [6900450.561496] ca dbus-broker-launch[205]: Ready261server # [6900450.441904] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo262server # [6900450.441904] server acme-setup-privileged[192]: + '[' -d test.foo ']'263server # [6900450.441904] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo264server # [6900450.442013] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']'265server # [6900450.462698] server nsncd[194]: Aug 27 20:11:16.515 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"266server # [6900450.464697] server systemd[1]: Started Name Service Cache Daemon (nsncd).267server # [6900450.464855] server systemd[1]: Reached target Host and Network Name Lookups.268server # [6900450.464913] server systemd[1]: Reached target User and Group Name Lookups.269server # [6900450.465999] server systemd[1]: Starting User Login Management...270server # [6900450.466770] server systemd[1]: Starting Permit User Sessions...271server # [6900450.477569] server systemd[1]: Finished Permit User Sessions.272server # [6900450.478768] server systemd[1]: Started Console Getty.273server # [6900450.478809] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0274server # [6900450.478827] server systemd[1]: Reached target Login Prompts.275server # [6900450.568254] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully.276server # [6900450.586710] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'...277server # [6900450.588413] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync'278server # [6900450.588413] server dbus-broker-launch[195]: Invalid user-name in /nix/store/aszr859gd9lnmlsj2dls188ya32g6xf8-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"279server # [6900450.588217] server systemd[1]: Started D-Bus System Message Bus.280server # [6900450.595607] server dbus-broker-launch[195]: Ready281client # [6900450.453735] client nsncd[189]: Aug 27 20:11:16.506 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"282client # [6900450.453645] client systemd[1]: Started Name Service Cache Daemon (nsncd).283client # [6900450.453705] client systemd[1]: Reached target Host and Network Name Lookups.284client # [6900450.453761] client systemd[1]: Reached target User and Group Name Lookups.285client # [6900450.465214] client systemd[1]: Starting User Login Management...286client # [6900450.466198] client systemd[1]: Starting Permit User Sessions...287client # [6900450.477627] client systemd[1]: Finished Permit User Sessions.288client # [6900450.479383] client systemd[1]: Started Console Getty.289client # [6900450.479428] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0290client # [6900450.479449] client systemd[1]: Reached target Login Prompts.291client # [6900450.572993] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'...292client # [6900450.573976] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync'293client # [6900450.573976] client dbus-broker-launch[190]: Invalid user-name in /nix/store/ssk8893k9jd7id6pd9yzim0h6prlbdma-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"294client # [6900450.574448] client systemd[1]: Started D-Bus System Message Bus.295client # [6900450.581223] client dbus-broker-launch[190]: Ready296client # [6900450.604249] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully.297ca # [6900450.975799] ca systemd-logind[230]: New seat seat0.298ca # [6900450.975973] ca systemd[1]: Started User Login Management.299ca # [6900451.012949] ca systemd[1]: Starting linger-users.service...300ca # [6900451.026380] ca systemd[1]: linger-users.service: Deactivated successfully.301ca # [6900451.026492] ca systemd[1]: Finished linger-users.service.302ca # [6900451.026548] ca acme-setup-start[219]: + set -euo pipefail303ca # [6900451.026824] ca acme-setup-start[219]: + test -e ca/key.pem304ca # [6900451.026824] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local305ca # [6900451.047746] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure.306ca # [6900451.050362] ca systemd[1]: Starting Ensure certificate for ca.foo...307ca # [6900451.180091] ca step-ca[204]: badger 2026/08/27 20:11:17 INFO: All 0 tables opened in 0s308ca # [6900451.184826] ca step-ca[204]: 2026/08/27 20:11:17 Building new tls configuration using step-ca x509 Signer Interface309ca # [6900451.189920] ca step-ca[204]: 2026/08/27 20:11:17 Starting Smallstep CA/0.30.2 (linux/arm64)310ca # [6900451.189920] ca step-ca[204]: 2026/08/27 20:11:17 Documentation: https://u.step.sm/docs/ca311ca # [6900451.189920] ca step-ca[204]: 2026/08/27 20:11:17 Community Discord: https://u.step.sm/discord312ca # [6900451.189920] ca step-ca[204]: 2026/08/27 20:11:17 Config file: /etc/smallstep/ca.json313ca # [6900451.189920] ca step-ca[204]: 2026/08/27 20:11:17 The primary server URL is https://ca.foo:1443314ca # [6900451.189920] ca step-ca[204]: 2026/08/27 20:11:17 Root certificates are available at https://ca.foo:1443/roots.pem315ca # [6900451.190248] ca step-ca[204]: 2026/08/27 20:11:17 X.509 Root Fingerprint: d639fb798088e87a90b5db04880a99cf6c5fad2ca4158aaceb65cc4996329246316ca # [6900451.190625] ca systemd[1]: Started step-ca service.317ca # [6900451.190975] ca step-ca[204]: 2026/08/27 20:11:17 Serving HTTPS on 0.0.0.0:1443 ...318client # [6900450.965580] client systemd-logind[205]: New seat seat0.319client # [6900450.965825] client systemd[1]: Started User Login Management.320client # [6900450.968209] client systemd[1]: Starting linger-users.service...321server # [6900450.968132] server systemd-logind[219]: New seat seat0.322client # [6900451.022614] client systemd[1]: linger-users.service: Deactivated successfully.323server # [6900450.968309] server systemd[1]: Started User Login Management.324server # [6900450.970674] server systemd[1]: Starting linger-users.service...325server # [6900451.009218] server acme-setup-start[208]: + set -euo pipefail326server # [6900451.009218] server acme-setup-start[208]: + test -e ca/key.pem327server # [6900451.009811] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local328server # [6900451.024090] server systemd[1]: linger-users.service: Deactivated successfully.329server # [6900451.024300] server systemd[1]: Finished linger-users.service.330server # [6900451.032628] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure.331server # [6900451.035292] server systemd[1]: Starting Ensure certificate for test.foo...332client # [6900451.022810] client systemd[1]: Finished linger-users.service.333client # [6900451.023355] client systemd[1]: Reached target Multi-User System.334client # [6900451.023560] client systemd[1]: Startup finished in 1.896s.335ca: must succeed: systemctl restart acme-order-renew-ca.foo.service 336server # [6900451.525924] server acme-test.foo-start[246]: Waiting to acquire lock in /run/acme/337server # [6900451.528892] server acme-test.foo-start[246]: + '[' -e out/acme-success ']'338server # [6900451.528979] server acme-test.foo-start[246]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=339server # [6900451.544324] server acme-test.foo-start[256]: + cd test.foo340server # [6900451.544849] server acme-test.foo-start[256]: + cp -vp cert.pem ../out/cert.pem341server # [6900451.545656] server acme-test.foo-start[257]: 'cert.pem' -> '../out/cert.pem'342ca # [6900451.544897] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/343server # [6900451.545991] server acme-test.foo-start[256]: + cp -vp key.pem ../out/key.pem344ca # [6900451.547578] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']'345server # [6900451.546864] server acme-test.foo-start[256]: 'key.pem' -> '../out/key.pem'346server # [6900451.547079] server acme-test.foo-start[246]: + cat out/cert.pem ca/cert.pem347ca # [6900451.547647] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses=348server # [6900451.548979] server acme-test.foo-start[246]: + cp ca/cert.pem out/chain.pem349ca # [6900451.562096] ca acme-ca.foo-start[293]: + cd ca.foo350server # [6900451.550299] server acme-test.foo-start[246]: + cat out/key.pem out/fullchain.pem351server # [6900451.552114] server acme-test.foo-start[246]: + for fixpath in out certificates352ca # [6900451.562504] ca acme-ca.foo-start[293]: + cp -vp cert.pem ../out/cert.pem353server # [6900451.552114] server acme-test.foo-start[246]: + '[' -d out ']'354ca # [6900451.563740] ca acme-ca.foo-start[294]: 'cert.pem' -> '../out/cert.pem'355server # [6900451.552114] server acme-test.foo-start[246]: + chmod -R u=rwX,g=rX,o= out356ca # [6900451.563978] ca acme-ca.foo-start[293]: + cp -vp key.pem ../out/key.pem357server # [6900451.553386] server acme-test.foo-start[246]: + chown -R acme:nginx out358ca # [6900451.565159] ca acme-ca.foo-start[293]: 'key.pem' -> '../out/key.pem'359server # [6900451.556896] server acme-test.foo-start[246]: + for fixpath in out certificates360ca # [6900451.565381] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem361server # [6900451.556896] server acme-test.foo-start[246]: + '[' -d certificates ']'362server # [6900451.564678] server systemd[1]: Finished Ensure certificate for test.foo.363ca # [6900451.566784] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem364server # [6900451.566944] server systemd[1]: Starting Nginx Web Server...365ca # [6900451.568849] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem366ca # [6900451.570836] ca acme-ca.foo-start[256]: + for fixpath in out certificates367ca # [6900451.570836] ca acme-ca.foo-start[256]: + '[' -d out ']'368ca # [6900451.570915] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out369ca # [6900451.572718] ca acme-ca.foo-start[256]: + chown -R acme:nginx out370ca # [6900451.575943] ca acme-ca.foo-start[256]: + for fixpath in out certificates371ca # [6900451.575943] ca acme-ca.foo-start[256]: + '[' -d certificates ']'372ca # [6900451.579026] ca systemd[1]: Finished Ensure certificate for ca.foo.373ca # [6900451.580642] ca systemd[1]: Starting Nginx Web Server...374client # [6900451.904177] client systemd-networkd[182]: eth1: Gained IPv6LL375ca # [6900451.972175] ca systemd-networkd[195]: eth1: Gained IPv6LL376ca # [6900452.095414] ca nginx-pre-start[305]: nginx: the configuration file /nix/store/fwgfm5i1iggggaqipdy1r2x2cxmzcbhr-nginx.conf syntax is ok377ca # [6900452.095815] ca nginx-pre-start[305]: nginx: configuration file /nix/store/fwgfm5i1iggggaqipdy1r2x2cxmzcbhr-nginx.conf test is successful378ca # [6900452.102037] ca systemd[1]: Started Nginx Web Server.379ca # [6900452.102771] ca systemd[1]: Reached target Multi-User System.380ca # [6900452.105029] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...381server # [6900452.077939] server nginx-pre-start[268]: nginx: the configuration file /nix/store/jz7kmd1pqz9d3z4szhmwj70infw1zqg3-nginx.conf syntax is ok382server # [6900452.078491] server nginx-pre-start[268]: nginx: configuration file /nix/store/jz7kmd1pqz9d3z4szhmwj70infw1zqg3-nginx.conf test is successful383server # [6900452.082607] server systemd[1]: Started Nginx Web Server.384server # [6900452.084088] server systemd[1]: Reached target Multi-User System.385server # [6900452.086490] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...386server # [6900452.224186] server systemd-networkd[186]: eth1: Gained IPv6LL387server # [6900452.591336] server acme-order-renew-test.foo-start[271]: Waiting to acquire lock in /run/acme/388server # [6900452.594403] server acme-order-renew-test.foo-start[271]: + set -euo pipefail389server # [6900452.594478] server acme-order-renew-test.foo-start[271]: + echo ad12aa6741ce4bd2c108390server # [6900452.594592] server acme-order-renew-test.foo-start[271]: + cmp -s domainhash.txt certificates/domainhash.txt391server # [6900452.595968] server acme-order-renew-test.foo-start[271]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run392server # [6900452.615600] server acme-order-renew-test.foo-start[282]: 2026/08/27 20:11:18 No key found for account none@none.tld. Generating a P256 key.393server # [6900452.615918] server acme-order-renew-test.foo-start[282]: 2026/08/27 20:11:18 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key394ca # [6900452.643515] ca acme-order-renew-ca.foo-start[308]: Waiting to acquire lock in /run/acme/395ca # [6900452.647169] ca acme-order-renew-ca.foo-start[308]: + set -euo pipefail396ca # [6900452.647243] ca acme-order-renew-ca.foo-start[308]: + echo 88dc4fc401a6091a1bd9397ca # [6900452.647361] ca acme-order-renew-ca.foo-start[308]: + cmp -s domainhash.txt certificates/domainhash.txt398ca # [6900452.648978] ca acme-order-renew-ca.foo-start[308]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run399ca # [6900452.664555] ca acme-order-renew-ca.foo-start[320]: 2026/08/27 20:11:18 No key found for account none@none.tld. Generating a P256 key.400ca # [6900452.664887] ca acme-order-renew-ca.foo-start[320]: 2026/08/27 20:11:18 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key401ca # [6900452.691763] ca step-ca[204]: time="2026-08-27T20:11:18Z" level=info duration="159.163µs" duration-ns=159163 fields.time="2026-08-27T20:11:18Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=61e0695c-05cb-4f63-8096-e6a20bd71d0c response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=402ca # [6900452.692357] ca acme-order-renew-ca.foo-start[320]: 2026/08/27 20:11:18 [INFO] acme: Registering account for none@none.tld403ca # [6900452.697494] ca step-ca[204]: time="2026-08-27T20:11:18Z" level=info duration=4.767588ms duration-ns=4767588 fields.time="2026-08-27T20:11:18Z" method=HEAD name=ca nonce=OFRZRDdQRTliNzBPUmQ3UTQ0eHJYTjZKWUNtaTFYY1c path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=1b19237e-3fc8-4177-a44e-d14375704f10 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=404ca # [6900452.701164] ca step-ca[204]: time="2026-08-27T20:11:18Z" level=info duration=2.551797ms duration-ns=2551797 fields.time="2026-08-27T20:11:18Z" method=POST name=ca nonce=MUJpblFxMmpGRUtWT0NaWEplUE5QaWNuc21kdVd5SXk path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=290738a9-6010-4607-abd3-7e79e679769f response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/3gzF24sm8Il7vAZCmCCxdXP7TDNI6l5n/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=405ca # [6900452.701758] ca acme-order-renew-ca.foo-start[320]: !!!! HEADS UP !!!!406ca # [6900452.701758] ca acme-order-renew-ca.foo-start[320]: Your account credentials have been saved in your407ca # [6900452.701758] ca acme-order-renew-ca.foo-start[320]: configuration directory at "accounts".408ca # [6900452.701758] ca acme-order-renew-ca.foo-start[320]: You should make a secure backup of this folder now. This409ca # [6900452.701758] ca acme-order-renew-ca.foo-start[320]: configuration directory will also contain private keys410ca # [6900452.701758] ca acme-order-renew-ca.foo-start[320]: generated by lego and certificates obtained from the ACME411ca # [6900452.701758] ca acme-order-renew-ca.foo-start[320]: server. Making regular backups of this folder is ideal.412ca # [6900452.701941] ca acme-order-renew-ca.foo-start[320]: 2026/08/27 20:11:18 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate413ca # [6900452.705171] ca step-ca[204]: time="2026-08-27T20:11:18Z" level=info duration=2.888041ms duration-ns=2888041 fields.time="2026-08-27T20:11:18Z" method=POST name=ca nonce=eHpqYlFkNmFHSWtsZVdBTVFYc1V2cGp6SjJSaUtiT1I path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=1a3894b8-d2d4-42f7-a587-482c5ef152a3 response="{\"id\":\"bYP8WWyrAsv78T5dZIckBlJ0XBptWIW0\",\"status\":\"pending\",\"expires\":\"2026-08-28T20:11:18Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-27T20:10:18Z\",\"notAfter\":\"2026-11-25T20:11:18Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/BBIKw5SVhGSKcFgUTuJ1yc8huwrjhUHj\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/bYP8WWyrAsv78T5dZIckBlJ0XBptWIW0/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=414ca # [6900452.764272] ca step-ca[204]: time="2026-08-27T20:11:18Z" level=info duration=2.12859ms duration-ns=2128590 fields.time="2026-08-27T20:11:18Z" method=POST name=ca nonce=eFFaaTBVelROUEdMdTRQd0hwQ3B6RUFzVm1OdG9BMEw path=/acme/acme/authz/BBIKw5SVhGSKcFgUTuJ1yc8huwrjhUHj protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=04c4dd2f-7e7a-4253-9c2c-eef68eab33e0 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"QLbx2RhHdl7fgTLWf1Ge0cZvRGMx4P0Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/BBIKw5SVhGSKcFgUTuJ1yc8huwrjhUHj/2GzuGLO9VsTdQj28wCjxgRKjhQ6SpjkS\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"QLbx2RhHdl7fgTLWf1Ge0cZvRGMx4P0Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/BBIKw5SVhGSKcFgUTuJ1yc8huwrjhUHj/jhQQTti6qrCpgmMYm80YXfZviyylAurL\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"QLbx2RhHdl7fgTLWf1Ge0cZvRGMx4P0Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/BBIKw5SVhGSKcFgUTuJ1yc8huwrjhUHj/5fLgWGMzhepZOnFX1d4pVsncwtxqHSG2\"}],\"wildcard\":false,\"expires\":\"2026-08-28T20:11:18Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=415ca # [6900452.764678] ca acme-order-renew-ca.foo-start[320]: 2026/08/27 20:11:18 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/BBIKw5SVhGSKcFgUTuJ1yc8huwrjhUHj416ca # [6900452.764678] ca acme-order-renew-ca.foo-start[320]: 2026/08/27 20:11:18 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01417ca # [6900452.764678] ca acme-order-renew-ca.foo-start[320]: 2026/08/27 20:11:18 [INFO] [ca.foo] acme: use http-01 solver418ca # [6900452.764678] ca acme-order-renew-ca.foo-start[320]: 2026/08/27 20:11:18 [INFO] [ca.foo] acme: Trying to solve HTTP-01419ca # [6900452.770142] ca step-ca[204]: time="2026-08-27T20:11:18Z" level=info duration=4.587425ms duration-ns=4587425 fields.time="2026-08-27T20:11:18Z" method=POST name=ca nonce=MENnUUNTYVNEekdQbFU1am5sNnB0MldVemxKMFRueTU path=/acme/acme/challenge/BBIKw5SVhGSKcFgUTuJ1yc8huwrjhUHj/jhQQTti6qrCpgmMYm80YXfZviyylAurL protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=894fc1d6-a5d2-4fd6-8ad8-d740e171d084 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"QLbx2RhHdl7fgTLWf1Ge0cZvRGMx4P0Z\",\"validated\":\"2026-08-27T20:11:18Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/BBIKw5SVhGSKcFgUTuJ1yc8huwrjhUHj/jhQQTti6qrCpgmMYm80YXfZviyylAurL\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=420ca # [6900452.770448] ca acme-order-renew-ca.foo-start[320]: 2026/08/27 20:11:18 [INFO] [ca.foo] The server validated our request421ca # [6900452.770525] ca acme-order-renew-ca.foo-start[320]: 2026/08/27 20:11:18 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates422ca # [6900452.779943] ca step-ca[204]: time="2026-08-27T20:11:18Z" level=info duration=8.322038ms duration-ns=8322038 fields.time="2026-08-27T20:11:18Z" method=POST name=ca nonce=WU9EdnVEQThJZ3QyUzRkd0xiSkROcmNraFNZM3FUek4 path=/acme/acme/order/bYP8WWyrAsv78T5dZIckBlJ0XBptWIW0/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=0c318d9d-18af-4e33-aea1-f26d9e24c51a response="{\"id\":\"bYP8WWyrAsv78T5dZIckBlJ0XBptWIW0\",\"status\":\"valid\",\"expires\":\"2026-08-28T20:11:18Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-27T20:10:18Z\",\"notAfter\":\"2026-11-25T20:11:18Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/BBIKw5SVhGSKcFgUTuJ1yc8huwrjhUHj\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/bYP8WWyrAsv78T5dZIckBlJ0XBptWIW0/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/4pfLGV94fjPjzHmnL1gTNYuWHtnNC7Gj\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=423ca # [6900452.782736] ca step-ca[204]: time="2026-08-27T20:11:18Z" level=info certificate="MIIB1DCCAXqgAwIBAgIRAPkRgxcY+SXyohm1H24+JvMwCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODI3MjAxMDE4WhcNMjYxMTI1MjAxMTE4WjARMQ8wDQYDVQQDEwZjYS5mb28wWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAQzRpmi4Ax6UswzSG7T4uq5CM3tmKPC0yxn7SLHmgoZSfBkVa/iiqhuxTT9pfKGlHfWrExssS/nXAtUkMysbMTPo4GkMIGhMA4GA1UdDwEB/wQEAwIHgDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHQYDVR0OBBYEFPIqIC0nmo7opUHyRTdUZpas4bOcMB8GA1UdIwQYMBaAFLX0fCTQX6/2wnn/zWVeal1ia6/jMBEGA1UdEQQKMAiCBmNhLmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSAAwRQIgIOY9z4Zu7XfASEnrlhTKDDe1re1Y7tFr+2Ikp362c8YCIQCoJv2mHXi4Qq1p8PJ1KPihxxoJVFkvnugRBPCgB23ohw==" duration=1.823706ms duration-ns=1823706 fields.time="2026-08-27T20:11:18Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=THlNcTlXY2I5QkdhQlFaeHhuOVZCeXZ5Q1hpck1ZdVI path=/acme/acme/certificate/4pfLGV94fjPjzHmnL1gTNYuWHtnNC7Gj protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=c678c1ab-4ec1-40dd-8826-1e08664a39e9 sans="map[dns:[ca.foo]]" serial=331068698822673802587787100772473120499 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-27T20:10:18Z" valid-to="2026-11-25T20:11:18Z"424ca # [6900452.783051] ca acme-order-renew-ca.foo-start[320]: 2026/08/27 20:11:18 [INFO] [ca.foo] Server responded with a certificate.425ca # [6900452.788308] ca acme-order-renew-ca.foo-start[308]: + mv domainhash.txt certificates/426ca # [6900452.790078] ca acme-order-renew-ca.foo-start[308]: + touch out/acme-success427ca # [6900452.791857] ca acme-order-renew-ca.foo-start[308]: + cmp -s certificates/ca.foo.crt out/fullchain.pem428ca # [6900452.793051] ca acme-order-renew-ca.foo-start[308]: + touch out/renewed429ca # [6900452.794591] ca acme-order-renew-ca.foo-start[308]: + echo Installing new certificate430ca # [6900452.794591] ca acme-order-renew-ca.foo-start[308]: Installing new certificate431ca # [6900452.794591] ca acme-order-renew-ca.foo-start[308]: + cp -vp certificates/ca.foo.crt out/fullchain.pem432ca # [6900452.796420] ca acme-order-renew-ca.foo-start[352]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem'433ca # [6900452.796791] ca acme-order-renew-ca.foo-start[308]: + cp -vp certificates/ca.foo.key out/key.pem434ca # [6900452.798206] ca acme-order-renew-ca.foo-start[353]: 'certificates/ca.foo.key' -> 'out/key.pem'435ca # [6900452.798509] ca acme-order-renew-ca.foo-start[308]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem436ca # [6900452.799915] ca acme-order-renew-ca.foo-start[354]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem'437ca # [6900452.800243] ca acme-order-renew-ca.foo-start[308]: + ln -sf fullchain.pem out/cert.pem438ca # [6900452.801932] ca acme-order-renew-ca.foo-start[308]: + cat out/key.pem out/fullchain.pem439ca # [6900452.803743] ca acme-order-renew-ca.foo-start[308]: + for fixpath in out certificates440ca # [6900452.803743] ca acme-order-renew-ca.foo-start[308]: + '[' -d out ']'441ca # [6900452.803836] ca acme-order-renew-ca.foo-start[308]: + chmod -R u=rwX,g=rX,o= out442ca # [6900452.805456] ca acme-order-renew-ca.foo-start[308]: + chown -R acme:nginx out443ca # [6900452.808297] ca acme-order-renew-ca.foo-start[308]: + for fixpath in out certificates444ca # [6900452.808297] ca acme-order-renew-ca.foo-start[308]: + '[' -d certificates ']'445ca # [6900452.808297] ca acme-order-renew-ca.foo-start[308]: + chmod -R u=rwX,g=rX,o= certificates446ca # [6900452.809808] ca acme-order-renew-ca.foo-start[308]: + chown -R acme:nginx certificates447ca # [6900452.812499] ca acme-order-renew-ca.foo-start[308]: + chmod -R u=rwX,g=,o= accounts/.448ca # [6900452.973684] ca systemd[1]: Reloading Nginx Web Server...449ca # [6900452.977728] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.450ca # [6900452.977960] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.451ca # [6900453.506557] ca nginx[370]: nginx: the configuration file /nix/store/fwgfm5i1iggggaqipdy1r2x2cxmzcbhr-nginx.conf syntax is ok452ca # [6900453.507104] ca nginx[370]: nginx: configuration file /nix/store/fwgfm5i1iggggaqipdy1r2x2cxmzcbhr-nginx.conf test is successful453server # [6900453.655308] server acme-order-renew-test.foo-start[282]: 2026/08/27 20:11:19 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 2 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority454server # [6900453.661155] server acme-order-renew-test.foo-start[271]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.455server # [6900453.661155] server acme-order-renew-test.foo-start[271]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.456server # [6900453.661155] server acme-order-renew-test.foo-start[271]: + exit 10457server # [6900453.663697] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a458server # [6900453.663897] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'.459server # [6900453.664292] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo.460server # [6900453.664799] server systemd[1]: Startup finished in 4.537s.461ca # [6900454.013389] ca systemd[1]: Reloaded Nginx Web Server.462ca # [6900454.013856] ca systemd[1]: Startup finished in 4.876s.463ca # [6900454.288188] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...464ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 3.43 seconds)465ca # [6900454.822941] ca acme-order-renew-ca.foo-start[385]: Waiting to acquire lock in /run/acme/466ca # [6900454.826252] ca acme-order-renew-ca.foo-start[385]: + set -euo pipefail467ca # [6900454.826353] ca acme-order-renew-ca.foo-start[385]: + echo 88dc4fc401a6091a1bd9468ca # [6900454.826439] ca acme-order-renew-ca.foo-start[385]: + cmp -s domainhash.txt certificates/domainhash.txt469ca # [6900454.827551] ca acme-order-renew-ca.foo-start[385]: + '[' -e certificates/ca.foo.key ']'470ca # [6900454.827551] ca acme-order-renew-ca.foo-start[385]: + '[' -e certificates/ca.foo.crt ']'471ca # [6900454.828111] ca acme-order-renew-ca.foo-start[393]: ++ find accounts -name none@none.tld.key472ca # [6900454.831173] ca acme-order-renew-ca.foo-start[385]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']'473ca # [6900454.831262] ca acme-order-renew-ca.foo-start[385]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic474ca # [6900454.884088] ca step-ca[204]: time="2026-08-27T20:11:20Z" level=info duration="66.681µs" duration-ns=66681 fields.time="2026-08-27T20:11:20Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=e32085af-78c0-4b1e-b78d-d48bd9f46d2f response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=475ca # [6900454.884726] ca acme-order-renew-ca.foo-start[394]: 2026/08/27 20:11:20 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint476ca # [6900454.884726] ca acme-order-renew-ca.foo-start[394]: 2026/08/27 20:11:20 [INFO] [ca.foo] The certificate expires at 2026-11-25T20:11:18Z, the renewal can be performed in 1439h59m37.062356822s: no renewal.477ca # [6900454.885402] ca acme-order-renew-ca.foo-start[385]: + mv domainhash.txt certificates/478ca # [6900454.887083] ca acme-order-renew-ca.foo-start[385]: + touch out/acme-success479ca # [6900454.888994] ca acme-order-renew-ca.foo-start[385]: + cmp -s certificates/ca.foo.crt out/fullchain.pem480ca # [6900454.890387] ca acme-order-renew-ca.foo-start[385]: + for fixpath in out certificates481ca # [6900454.890387] ca acme-order-renew-ca.foo-start[385]: + '[' -d out ']'482ca # [6900454.890468] ca acme-order-renew-ca.foo-start[385]: + chmod -R u=rwX,g=rX,o= out483ca # [6900454.892187] ca acme-order-renew-ca.foo-start[385]: + chown -R acme:nginx out484ca # [6900454.895275] ca acme-order-renew-ca.foo-start[385]: + for fixpath in out certificates485ca # [6900454.895275] ca acme-order-renew-ca.foo-start[385]: + '[' -d certificates ']'486ca # [6900454.895352] ca acme-order-renew-ca.foo-start[385]: + chmod -R u=rwX,g=rX,o= certificates487ca # [6900454.896971] ca acme-order-renew-ca.foo-start[385]: + chown -R acme:nginx certificates488ca # [6900454.900738] ca acme-order-renew-ca.foo-start[385]: + chmod -R u=rwX,g=,o= accounts/.489ca # [6900455.050634] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.490ca # [6900455.050988] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.491server: must succeed: systemctl restart acme-test.foo.service492server # [6900458.084699] server systemd[1]: acme-test.foo.service: Deactivated successfully.493server # [6900458.085073] server systemd[1]: Stopped Ensure certificate for test.foo.494server # [6900458.086386] server systemd[1]: Stopping Ensure certificate for test.foo...495server # [6900458.093926] server systemd[1]: Starting Ensure certificate for test.foo...496server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.53 seconds)497client: waiting for success: curl -v https://test.foo498* Host test.foo:443 was resolved.499* IPv6: 2001:db8:1::3500* IPv4: 192.168.1.3501* Trying [2001:db8:1::3]:443...502* ALPN: curl offers h2,http/1.1503} [5 bytes data]504* TLSv1.3 (OUT), TLS handshake, Client hello (1):505} [1552 bytes data]506* SSL Trust Anchors:507* OpenSSL default paths (fallback)508{ [5 bytes data]509* TLSv1.3 (IN), TLS handshake, Server hello (2):510{ [1210 bytes data]511* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):512{ [1 bytes data]513* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):514{ [19 bytes data]515* TLSv1.3 (IN), TLS handshake, Certificate (11):516{ [1008 bytes data]517* TLSv1.3 (IN), TLS handshake, CERT verify (15):518{ [111 bytes data]519* TLSv1.3 (IN), TLS handshake, Finished (20):520{ [52 bytes data]521* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):522} [1 bytes data]523* TLSv1.3 (OUT), TLS handshake, Finished (20):524} [52 bytes data]525* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey526* ALPN: server accepted h2527* Server certificate:528* subject: CN=test.foo529* start date: Aug 27 20:11:17 2026 GMT530* expire date: Sep 26 20:11:17 2028 GMT531* issuer: CN=minica root ca 5ba28a532* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384533* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384534* subjectAltName: "test.foo" matches cert's "test.foo"535* OpenSSL verify result: 13536* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)537* closing connection #0538curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)539More details here: https://curl.se/docs/sslcerts.html540541curl failed to verify the legitimacy of the server and therefore could not542establish a secure connection to it. To learn more about this situation and543how to fix it, please visit the webpage mentioned above.544server # [6900458.564172] server acme-test.foo-start[317]: Waiting to acquire lock in /run/acme/545server # [6900458.567071] server acme-test.foo-start[317]: + '[' -e out/acme-success ']'546server # [6900458.567105] server acme-test.foo-start[317]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=547server # [6900458.582913] server acme-test.foo-start[326]: + cd test.foo548server # [6900458.583140] server acme-test.foo-start[326]: + cp -vp cert.pem ../out/cert.pem549server # [6900458.584615] server acme-test.foo-start[327]: 'cert.pem' -> '../out/cert.pem'550server # [6900458.584868] server acme-test.foo-start[326]: + cp -vp key.pem ../out/key.pem551server # [6900458.586171] server acme-test.foo-start[326]: 'key.pem' -> '../out/key.pem'552server # [6900458.586424] server acme-test.foo-start[317]: + cat out/cert.pem ca/cert.pem553server # [6900458.588235] server acme-test.foo-start[317]: + cp ca/cert.pem out/chain.pem554server # [6900458.589872] server acme-test.foo-start[317]: + cat out/key.pem out/fullchain.pem555server # [6900458.591925] server acme-test.foo-start[317]: + for fixpath in out certificates556server # [6900458.591948] server acme-test.foo-start[317]: + '[' -d out ']'557server # [6900458.591948] server acme-test.foo-start[317]: + chmod -R u=rwX,g=rX,o= out558server # [6900458.593911] server acme-test.foo-start[317]: + chown -R acme:nginx out559server # [6900458.597235] server acme-test.foo-start[317]: + for fixpath in out certificates560server # [6900458.597235] server acme-test.foo-start[317]: + '[' -d certificates ']'561server # [6900458.600532] server systemd[1]: Finished Ensure certificate for test.foo.562server # [6900458.603162] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...563server # [6900459.139805] server acme-order-renew-test.foo-start[334]: Waiting to acquire lock in /run/acme/564server # [6900459.142428] server acme-order-renew-test.foo-start[334]: + set -euo pipefail565server # [6900459.142504] server acme-order-renew-test.foo-start[334]: + echo ad12aa6741ce4bd2c108566server # [6900459.142620] server acme-order-renew-test.foo-start[334]: + cmp -s domainhash.txt certificates/domainhash.txt567server # [6900459.143842] server acme-order-renew-test.foo-start[334]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run568server # [6900459.194992] server acme-order-renew-test.foo-start[342]: 2026/08/27 20:11:25 [INFO] acme: Registering account for none@none.tld569server # [6900459.227081] server acme-order-renew-test.foo-start[342]: !!!! HEADS UP !!!!570server # [6900459.227081] server acme-order-renew-test.foo-start[342]: Your account credentials have been saved in your571server # [6900459.227081] server acme-order-renew-test.foo-start[342]: configuration directory at "accounts".572server # [6900459.227081] server acme-order-renew-test.foo-start[342]: You should make a secure backup of this folder now. This573server # [6900459.227081] server acme-order-renew-test.foo-start[342]: configuration directory will also contain private keys574server # [6900459.227081] server acme-order-renew-test.foo-start[342]: generated by lego and certificates obtained from the ACME575server # [6900459.227081] server acme-order-renew-test.foo-start[342]: server. Making regular backups of this folder is ideal.576server # [6900459.227287] server acme-order-renew-test.foo-start[342]: 2026/08/27 20:11:25 [INFO] [test.foo] acme: Obtaining bundled SAN certificate577server # [6900459.304441] server acme-order-renew-test.foo-start[342]: 2026/08/27 20:11:25 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/BDOoMNqo8mN6mTeAdDqMeXI1fjo5HHPh578server # [6900459.304441] server acme-order-renew-test.foo-start[342]: 2026/08/27 20:11:25 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01579server # [6900459.304441] server acme-order-renew-test.foo-start[342]: 2026/08/27 20:11:25 [INFO] [test.foo] acme: use http-01 solver580server # [6900459.304441] server acme-order-renew-test.foo-start[342]: 2026/08/27 20:11:25 [INFO] [test.foo] acme: Trying to solve HTTP-01581server # [6900459.315988] server acme-order-renew-test.foo-start[342]: 2026/08/27 20:11:25 [INFO] [test.foo] The server validated our request582server # [6900459.316082] server acme-order-renew-test.foo-start[342]: 2026/08/27 20:11:25 [INFO] [test.foo] acme: Validations succeeded; requesting certificates583server # [6900459.333032] server acme-order-renew-test.foo-start[342]: 2026/08/27 20:11:25 [INFO] [test.foo] Server responded with a certificate.584server # [6900459.338598] server acme-order-renew-test.foo-start[334]: + mv domainhash.txt certificates/585server # [6900459.340660] server acme-order-renew-test.foo-start[334]: + touch out/acme-success586server # [6900459.342277] server acme-order-renew-test.foo-start[334]: + cmp -s certificates/test.foo.crt out/fullchain.pem587server # [6900459.343445] server acme-order-renew-test.foo-start[334]: + touch out/renewed588server # [6900459.344897] server acme-order-renew-test.foo-start[334]: + echo Installing new certificate589server # [6900459.344897] server acme-order-renew-test.foo-start[334]: Installing new certificate590server # [6900459.344897] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.crt out/fullchain.pem591server # [6900459.346464] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.crt' -> 'out/fullchain.pem'592server # [6900459.346827] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.key out/key.pem593server # [6900459.348254] server acme-order-renew-test.foo-start[375]: 'certificates/test.foo.key' -> 'out/key.pem'594server # [6900459.348571] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem595server # [6900459.350010] server acme-order-renew-test.foo-start[376]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem'596server # [6900459.350307] server acme-order-renew-test.foo-start[334]: + ln -sf fullchain.pem out/cert.pem597server # [6900459.351787] server acme-order-renew-test.foo-start[334]: + cat out/key.pem out/fullchain.pem598server # [6900459.353579] server acme-order-renew-test.foo-start[334]: + for fixpath in out certificates599server # [6900459.353579] server acme-order-renew-test.foo-start[334]: + '[' -d out ']'600server # [6900459.353674] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=rX,o= out601server # [6900459.355446] server acme-order-renew-test.foo-start[334]: + chown -R acme:nginx out602server # [6900459.358322] server acme-order-renew-test.foo-start[334]: + for fixpath in out certificates603server # [6900459.358322] server acme-order-renew-test.foo-start[334]: + '[' -d certificates ']'604server # [6900459.358322] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=rX,o= certificates605server # [6900459.359805] server acme-order-renew-test.foo-start[334]: + chown -R acme:nginx certificates606server # [6900459.362849] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=,o= accounts/.607ca # [6900459.194472] ca step-ca[204]: time="2026-08-27T20:11:25Z" level=info duration="45.601µs" duration-ns=45601 fields.time="2026-08-27T20:11:25Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=31705537-f68d-4231-b62c-150ce5da805b response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=608ca # [6900459.218749] ca step-ca[204]: time="2026-08-27T20:11:25Z" level=info duration=21.221541ms duration-ns=21221541 fields.time="2026-08-27T20:11:25Z" method=HEAD name=ca nonce=ZHl6UFJDZHJxTjlya2gwbWVVVEk1RzlLb0lVdGJvZHI path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=1d2cb3ef-32c3-4905-a7e3-7acdbfd4039c size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=609ca # [6900459.226606] ca step-ca[204]: time="2026-08-27T20:11:25Z" level=info duration=4.992071ms duration-ns=4992071 fields.time="2026-08-27T20:11:25Z" method=POST name=ca nonce=QlU5NTc4NTB4YkFXUHlpVnhOczdIRXVBb095Ykc3T0E path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=4b90f2e7-f5b0-4903-aeec-b1c57af7404d response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/xRMSmTS39bgBpwdn4dq9cWBCeNwY5Gli/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=610ca # [6900459.234987] ca step-ca[204]: time="2026-08-27T20:11:25Z" level=info duration=4.772908ms duration-ns=4772908 fields.time="2026-08-27T20:11:25Z" method=POST name=ca nonce=czcwQUxVVG1zaTE3UmtJWUZpVjJkd1hPNFpscFljMnM path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=43d97c4f-c0a6-4d84-829c-6eff80ab07ea response="{\"id\":\"xyr4S4nmHJq5MN7UdgI7zYptW8bB0hDP\",\"status\":\"pending\",\"expires\":\"2026-08-28T20:11:25Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-27T20:10:25Z\",\"notAfter\":\"2026-11-25T20:11:25Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/BDOoMNqo8mN6mTeAdDqMeXI1fjo5HHPh\"],\"finalize\":\"https://ca.foo/acme/acme/order/xyr4S4nmHJq5MN7UdgI7zYptW8bB0hDP/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=611ca # [6900459.303927] ca step-ca[204]: time="2026-08-27T20:11:25Z" level=info duration=8.856126ms duration-ns=8856126 fields.time="2026-08-27T20:11:25Z" method=POST name=ca nonce=SUV1MVI4MDQ3QWo5YWdRUkRjcnVaUGVERmczTkdHZG4 path=/acme/acme/authz/BDOoMNqo8mN6mTeAdDqMeXI1fjo5HHPh protocol=HTTP/1.1 referer= remote-address="::1" request-id=8ab00660-2234-40be-aa7d-e7a2bb664bc9 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"URrQVjd8sZNI6hL9yhjM1ETk0dZTdNbl\",\"url\":\"https://ca.foo/acme/acme/challenge/BDOoMNqo8mN6mTeAdDqMeXI1fjo5HHPh/LRY4zgl9lFendBuVXHre2dmNiYnV3Mve\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"URrQVjd8sZNI6hL9yhjM1ETk0dZTdNbl\",\"url\":\"https://ca.foo/acme/acme/challenge/BDOoMNqo8mN6mTeAdDqMeXI1fjo5HHPh/ElbapKuYKgNGYsLhXRSWRzEvropNqXuL\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"URrQVjd8sZNI6hL9yhjM1ETk0dZTdNbl\",\"url\":\"https://ca.foo/acme/acme/challenge/BDOoMNqo8mN6mTeAdDqMeXI1fjo5HHPh/kQlR5SZi5IzlmjoDKwv4rBghWyWXbQue\"}],\"wildcard\":false,\"expires\":\"2026-08-28T20:11:25Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=612ca # [6900459.315559] ca step-ca[204]: time="2026-08-27T20:11:25Z" level=info duration=7.883832ms duration-ns=7883832 fields.time="2026-08-27T20:11:25Z" method=POST name=ca nonce=TklPdWFna3N1N1JzTUR1NWRsME5mVmxmTTVGRkdQelY path=/acme/acme/challenge/BDOoMNqo8mN6mTeAdDqMeXI1fjo5HHPh/ElbapKuYKgNGYsLhXRSWRzEvropNqXuL protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=6caf30e4-16fe-45c7-a75a-331b21782ca8 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"URrQVjd8sZNI6hL9yhjM1ETk0dZTdNbl\",\"validated\":\"2026-08-27T20:11:25Z\",\"url\":\"https://ca.foo/acme/acme/challenge/BDOoMNqo8mN6mTeAdDqMeXI1fjo5HHPh/ElbapKuYKgNGYsLhXRSWRzEvropNqXuL\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=613ca # [6900459.327263] ca step-ca[204]: time="2026-08-27T20:11:25Z" level=info duration=8.067874ms duration-ns=8067874 fields.time="2026-08-27T20:11:25Z" method=POST name=ca nonce=NHN3eFkxT2FjZXBiMVZFZFh0dHNZYWp6cERwUldBVkc path=/acme/acme/order/xyr4S4nmHJq5MN7UdgI7zYptW8bB0hDP/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=be175969-60e7-44c0-a1f9-687fc6f7227d response="{\"id\":\"xyr4S4nmHJq5MN7UdgI7zYptW8bB0hDP\",\"status\":\"valid\",\"expires\":\"2026-08-28T20:11:25Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-27T20:10:25Z\",\"notAfter\":\"2026-11-25T20:11:25Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/BDOoMNqo8mN6mTeAdDqMeXI1fjo5HHPh\"],\"finalize\":\"https://ca.foo/acme/acme/order/xyr4S4nmHJq5MN7UdgI7zYptW8bB0hDP/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/SmP81e19Xr0TfHQrhqy5yhf2TNkDc462\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=614ca # [6900459.332650] ca step-ca[204]: time="2026-08-27T20:11:25Z" level=info certificate="MIIB1zCCAX2gAwIBAgIQBzOinynSk5BabKX5xmK+7TAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MjcyMDEwMjVaFw0yNjExMjUyMDExMjVaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEI74y4dTSOWEFXZw1bBxg3Xy0kXbiajoNfSAbIkeJjNpmgvecaBGDS6dClN3XGrKSJVsidj+Uo4VF/IVJluIzdqOBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBR9BKzCqN5ArTO1rEi+65zQNljAsDAfBgNVHSMEGDAWgBS19Hwk0F+v9sJ5/81lXmpdYmuv4zATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSAAwRQIgWUYcyWdgUchljw+7Eo/HNPJjx2P7xvB0rhD50AONiRgCIQC8jja1db+lBOu+5Pw2Mk9GKN4c3Q4mX/GE8NcuwS9Dqw==" duration=1.789305ms duration-ns=1789305 fields.time="2026-08-27T20:11:25Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=WlpKNG1OTDhwaGFTRkV6cjVFTmtWdkh2VzF4bVVqcVM path=/acme/acme/certificate/SmP81e19Xr0TfHQrhqy5yhf2TNkDc462 protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=95f53062-77a3-4369-bb99-1a956dd87c38 sans="map[dns:[test.foo]]" serial=9572701470856775333534175212467306221 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-27T20:10:25Z" valid-to="2026-11-25T20:11:25Z"615* Host test.foo:443 was resolved.616* IPv6: 2001:db8:1::3617* IPv4: 192.168.1.3618* Trying [2001:db8:1::3]:443...619* ALPN: curl offers h2,http/1.1620} [5 bytes data]621* TLSv1.3 (OUT), TLS handshake, Client hello (1):622} [1552 bytes data]623* SSL Trust Anchors:624* OpenSSL default paths (fallback)625{ [5 bytes data]626* TLSv1.3 (IN), TLS handshake, Server hello (2):627{ [1210 bytes data]628* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):629{ [1 bytes data]630* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):631{ [19 bytes data]632* TLSv1.3 (IN), TLS handshake, Certificate (11):633{ [1008 bytes data]634* TLSv1.3 (IN), TLS handshake, CERT verify (15):635{ [111 bytes data]636* TLSv1.3 (IN), TLS handshake, Finished (20):637{ [52 bytes data]638* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):639} [1 bytes data]640* TLSv1.3 (OUT), TLS handshake, Finished (20):641} [52 bytes data]642* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey643* ALPN: server accepted h2644* Server certificate:645* subject: CN=test.foo646* start date: Aug 27 20:11:17 2026 GMT647* expire date: Sep 26 20:11:17 2028 GMT648* issuer: CN=minica root ca 5ba28a649* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384650* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384651* subjectAltName: "test.foo" matches cert's "test.foo"652* OpenSSL verify result: 13653* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)654* closing connection #0655curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)656More details here: https://curl.se/docs/sslcerts.html657658curl failed to verify the legitimacy of the server and therefore could not659establish a secure connection to it. To learn more about this situation and660how to fix it, please visit the webpage mentioned above.661server # [6900459.512342] server systemd[1]: Reloading Nginx Web Server...662server # [6900459.517417] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully.663server # [6900459.517731] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo.664server # [6900460.006211] server nginx[392]: nginx: the configuration file /nix/store/jz7kmd1pqz9d3z4szhmwj70infw1zqg3-nginx.conf syntax is ok665server # [6900460.006889] server nginx[392]: nginx: configuration file /nix/store/jz7kmd1pqz9d3z4szhmwj70infw1zqg3-nginx.conf test is successful666* Host test.foo:443 was resolved.667* IPv6: 2001:db8:1::3668* IPv4: 192.168.1.3669* Trying [2001:db8:1::3]:443...670* ALPN: curl offers h2,http/1.1671} [5 bytes data]672* TLSv1.3 (OUT), TLS handshake, Client hello (1):673} [1552 bytes data]674* SSL Trust Anchors:675* OpenSSL default paths (fallback)676{ [5 bytes data]677* TLSv1.3 (IN), TLS handshake, Server hello (2):678{ [1210 bytes data]679* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):680{ [1 bytes data]681* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):682{ [19 bytes data]683* TLSv1.3 (IN), TLS handshake, Certificate (11):684{ [931 bytes data]685* TLSv1.3 (IN), TLS handshake, CERT verify (15):686{ [80 bytes data]687* TLSv1.3 (IN), TLS handshake, Finished (20):688{ [52 bytes data]689* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):690} [1 bytes data]691* TLSv1.3 (OUT), TLS handshake, Finished (20):692} [52 bytes data]693* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey694* ALPN: server accepted h2695* Server certificate:696* subject: CN=test.foo697* start date: Aug 27 20:10:25 2026 GMT698* expire date: Nov 25 20:11:25 2026 GMT699* issuer: CN=Clan Intermediate CA700* Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256701* Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256702* Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256703* subjectAltName: "test.foo" matches cert's "test.foo"704* OpenSSL verify result: 0705* SSL certificate verified via OpenSSL.706* Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 33680 707 % Total % Received % Xferd Average Speed Time Time Time Current708 Dload Upload Total Spent Left Speed709 0 0 0 0 0 0 0 0 0* using HTTP/2710* [HTTP/2] [1] OPENED stream for https://test.foo/711* [HTTP/2] [1] [:method: GET]712* [HTTP/2] [1] [:scheme: https]713* [HTTP/2] [1] [:authority: test.foo]714* [HTTP/2] [1] [:path: /]715* [HTTP/2] [1] [user-agent: curl/8.21.0]716* [HTTP/2] [1] [accept: */*]717} [5 bytes data]718719720721722723* Request completely sent off724{ [5 bytes data]725* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):726{ [265 bytes data]727* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):728{ [265 bytes data]729730731732733734735736{ [5 bytes data]737100 20 100 20 0 0 664 0 0738* Connection #0 to host test.foo:443 left intact739client: (finished: waiting for success: curl -v https://test.foo, in 2.15 seconds)740client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2741Certificate:742 Data:743 Version: 3 (0x2)744 Serial Number:745 07:33:a2:9f:29:d2:93:90:5a:6c:a5:f9:c6:62:be:ed746 Signature Algorithm: ecdsa-with-SHA256747 Issuer: CN=Clan Intermediate CA748 Validity749 Not Before: Aug 27 20:10:25 2026 GMT750 Not After : Nov 25 20:11:25 2026 GMT751 Subject: CN=test.foo752 Subject Public Key Info:753 Public Key Algorithm: id-ecPublicKey754 Public-Key: (256 bit)755 pub:756 04:23:be:32:e1:d4:d2:39:61:05:5d:9c:35:6c:1c:757 60:dd:7c:b4:91:76:e2:6a:3a:0d:7d:20:1b:22:47:758 89:8c:da:66:82:f7:9c:68:11:83:4b:a7:42:94:dd:759 d7:1a:b2:92:25:5b:22:76:3f:94:a3:85:45:fc:85:760 49:96:e2:33:76761 ASN1 OID: prime256v1762 NIST CURVE: P-256763 X509v3 extensions:764 X509v3 Key Usage: critical765 Digital Signature766 X509v3 Extended Key Usage: 767 TLS Web Server Authentication, TLS Web Client Authentication768 X509v3 Subject Key Identifier: 769 7D:04:AC:C2:A8:DE:40:AD:33:B5:AC:48:BE:EB:9C:D0:36:58:C0:B0770 X509v3 Authority Key Identifier: 771 B5:F4:7C:24:D0:5F:AF:F6:C2:79:FF:CD:65:5E:6A:5D:62:6B:AF:E3772 X509v3 Subject Alternative Name: 773 DNS:test.foo774 1.3.6.1.4.1.37476.9000.64.1: 775 0......acme..776 Signature Algorithm: ecdsa-with-SHA256777 Signature Value:778 30:45:02:20:59:46:1c:c9:67:60:51:c8:65:8f:0f:bb:12:8f:779 c7:34:f2:63:c7:63:fb:c6:f0:74:ae:10:f9:d0:03:8d:89:18:780 02:21:00:bc:8e:36:b5:75:bf:a5:04:eb:be:e4:fc:36:32:4f:781 46:28:de:1c:dd:0e:26:5f:f1:84:f0:d7:2e:c1:2f:43:ab782client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2, in 0.05 seconds)783(finished: run the VM test script, in 12.17 seconds)784server # [6900460.514531] server systemd[1]: Reloaded Nginx Web Server.785test script finished in 12.28s786cleanup787kill NspawnMachine (pid 52)788kill NspawnMachine (pid 55)789kill NspawnMachine (pid 59)790Container ca terminated by signal KILL.791Container client terminated by signal KILL.792(finished: cleanup, in 0.34 seconds)793Container server terminated by signal KILL.