nixbot

builds

succeeded container-test-run-certificates checks.aarch64-linux.certificates · build #530 · raw

1Machine state will be reset. To keep it, pass --keep-machine-state2start all VLans3(finished: start all VLans, in 0.00 seconds)45Test will time out and terminate in 3600.0 seconds6run the VM test script7additionally exposed symbols:8 ca, client, server,9 vlan1,10 start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh11start all VMs12ca: systemd-nspawn running (pid 52)13client: systemd-nspawn running (pid 54)14ca: Waiting for journal at /build/vm-state-ca/var/log/journal...15server: systemd-nspawn running (pid 57)16client: Waiting for journal at /build/vm-state-client/var/log/journal...17server: Waiting for journal at /build/vm-state-server/var/log/journal...18(finished: start all VMs, in 0.00 seconds)19nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE20nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.21nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE22nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.23nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE24nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.25Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.26Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.27Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.28░ Spawning container ca on /build/vm-state-ca.29░ Spawning container client on /build/vm-state-client.30░ Spawning container server on /build/vm-state-server.31ca # No journal files were found.32ca # No journal boot entry found for the specified boot (+0).33server # No journal files were found.34server # No journal boot entry found for the specified boot (+0).35client # No journal files were found.36client # No journal boot entry found for the specified boot (+0).37ca # [7209370.739433] ca systemd-journald[78]: Journal started38ca # [7209370.739485] ca systemd-journald[78]: Runtime Journal (/run/log/journal/7d469d5520b442ed9a6b448bb9744884) is 8M, max 2.5G, 2.4G free.39ca # [7209370.742298] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully.40ca # [7209370.752752] ca systemd[1]: Starting Flush Journal to Persistent Storage...41ca # [7209370.753558] ca systemd[1]: Starting Network Name Resolution...42ca # [7209370.754208] ca systemd[1]: Starting Create Static Device Nodes in /dev...43ca # [7209370.761414] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/7d469d5520b442ed9a6b448bb9744884 is 1.469ms for 6 entries.44ca # [7209370.761414] ca systemd-journald[78]: System Journal (/var/log/journal/7d469d5520b442ed9a6b448bb9744884) is 8M, max 4G, 3.9G free.45ca # [7209370.772321] ca systemd[1]: Finished Create Static Device Nodes in /dev.46ca # [7209370.773056] ca systemd[1]: Reached target Preparation for Local File Systems.47ca # [7209370.773172] ca systemd[1]: Reached target Local File Systems.48ca # [7209370.773991] ca systemd[1]: Listening on Boot Loader Control Service Socket.49ca # [7209370.774036] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container50ca # [7209370.774926] ca systemd[1]: Starting Save Transient machine-id to Disk...51ca # [7209370.774961] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys52ca # [7209370.831983] ca systemd[1]: Finished Flush Journal to Persistent Storage.53ca # [7209370.833458] ca systemd[1]: Starting Create System Files and Directories...54ca # [7209370.884077] ca systemd[1]: Finished Firewall.55ca # [7209370.884228] ca systemd[1]: Reached target Preparation for Network.56ca # [7209370.884441] ca systemd[1]: Listening on Network Management Resolve Hook Socket.57ca # [7209370.885444] ca systemd[1]: Starting Network Management...58ca # [7209370.896944] ca systemd-tmpfiles[157]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted59ca # [7209370.897342] ca systemd-tmpfiles[157]: fchmod() of /var/log/journal failed: Operation not permitted60ca # [7209370.897591] ca systemd-tmpfiles[157]: fchmod() of /var/log/journal/7d469d5520b442ed9a6b448bb9744884 failed: Operation not permitted61ca # [7209370.897976] ca systemd-tmpfiles[157]: fchmod() of /run/log/journal failed: Operation not permitted62ca # [7209370.899887] ca systemd[1]: Finished Create System Files and Directories.63ca # [7209370.900978] ca systemd[1]: Starting Rebuild Journal Catalog...64ca # [7209370.901702] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP...65ca # [7209370.912670] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP.66ca # [7209370.921675] ca systemd[1]: Finished Rebuild Journal Catalog.67ca # [7209370.922676] ca systemd[1]: Starting Update is Completed...68ca # [7209370.932476] ca systemd[1]: Finished Update is Completed.69ca # [7209370.946080] ca systemd[1]: Finished Save Transient machine-id to Disk.70ca # [7209371.323712] ca systemd-networkd[188]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted71ca # [7209371.323805] ca systemd-networkd[188]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted72ca # [7209371.330560] ca systemd-networkd[188]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.73ca # [7209371.330720] ca systemd-networkd[188]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.74ca # [7209371.330878] ca systemd-networkd[188]: lo: Link UP75ca # [7209371.330883] ca systemd-networkd[188]: lo: Gained carrier76ca # [7209371.331088] ca systemd-networkd[188]: eth1: Configuring with /etc/systemd/network/40-eth1.network.77ca # [7209371.331454] ca systemd[1]: Started Network Management.78ca # [7209371.340705] ca systemd-networkd[188]: eth1: Link UP79ca # [7209371.340946] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd...80ca # [7209371.341302] ca systemd-networkd[188]: eth1: Gained carrier81ca # [7209371.381459] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd.82ca # [7209371.488396] ca systemd-resolved[104]: Positive Trust Anchors:83ca # [7209371.488410] ca systemd-resolved[104]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d84ca # [7209371.488413] ca systemd-resolved[104]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b1685ca # [7209371.488447] ca systemd-resolved[104]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test86ca # [7209371.510393] ca systemd-resolved[104]: Using system hostname 'ca'.87ca # [7209371.511780] ca systemd[1]: Started Network Name Resolution.88ca # [7209371.511932] ca systemd[1]: Reached target Network.89ca # [7209371.512060] ca systemd[1]: Reached target Network is Online.90ca # [7209371.512155] ca systemd[1]: Reached target System Initialization.91ca # [7209371.512557] ca systemd[1]: Started Renew ACME Certificate for ca.foo.92ca # [7209371.512622] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container93ca # [7209371.512673] ca systemd[1]: Started Daily Cleanup of Temporary Directories.94ca # [7209371.512711] ca systemd[1]: Reached target Timer Units.95ca # [7209371.512919] ca systemd[1]: Listening on D-Bus System Message Bus Socket.96ca # [7209371.513106] ca systemd[1]: Listening on Nix Daemon Socket.97ca # [7209371.513331] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.98ca # [7209371.513377] ca systemd[1]: Reached target Socket Units.99server # [7209370.713764] server systemd-journald[69]: Journal started100ca # [7209371.513455] ca systemd[1]: Reached target Basic System.101server # [7209370.713826] server systemd-journald[69]: Runtime Journal (/run/log/journal/22dd6f32f5ee4e7f8feee8d0b7d1468a) is 8M, max 2.5G, 2.4G free.102ca # [7209371.532576] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure...103server # [7209370.719963] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully.104ca # [7209371.533883] ca systemd[1]: Starting Import lastlog data into lastlog2 database...105server # [7209370.729473] server systemd[1]: Starting Flush Journal to Persistent Storage...106server # [7209370.730314] server systemd[1]: Starting Network Name Resolution...107server # [7209370.731132] server systemd[1]: Starting Create Static Device Nodes in /dev...108server # [7209370.739193] server systemd-journald[69]: Time spent on flushing to /var/log/journal/22dd6f32f5ee4e7f8feee8d0b7d1468a is 1.535ms for 6 entries.109server # [7209370.739193] server systemd-journald[69]: System Journal (/var/log/journal/22dd6f32f5ee4e7f8feee8d0b7d1468a) is 8M, max 4G, 3.9G free.110ca # [7209371.533951] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem111server # [7209370.746458] server systemd[1]: Finished Create Static Device Nodes in /dev.112server # [7209370.747155] server systemd[1]: Reached target Preparation for Local File Systems.113server # [7209370.747293] server systemd[1]: Reached target Local File Systems.114ca # [7209371.535399] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)...115ca # [7209371.537102] ca systemd[1]: Starting step-ca service...116ca # [7209371.539452] ca systemd[1]: Starting D-Bus System Message Bus...117server # [7209370.748162] server systemd[1]: Listening on Boot Loader Control Service Socket.118ca # [7209371.555085] ca systemd[1]: Finished Import lastlog data into lastlog2 database.119server # [7209370.748209] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container120server # [7209370.749141] server systemd[1]: Starting Save Transient machine-id to Disk...121server # [7209370.749177] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys122server # [7209370.831175] server systemd[1]: Finished Flush Journal to Persistent Storage.123server # [7209370.832982] server systemd[1]: Starting Create System Files and Directories...124server # [7209370.872833] server systemd[1]: Finished Firewall.125server # [7209370.873071] server systemd[1]: Reached target Preparation for Network.126server # [7209370.873282] server systemd[1]: Listening on Network Management Resolve Hook Socket.127server # [7209370.876132] server systemd[1]: Starting Network Management...128server # [7209370.888131] server systemd-tmpfiles[157]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted129server # [7209370.888305] server systemd-tmpfiles[157]: fchmod() of /var/log/journal failed: Operation not permitted130server # [7209370.888420] server systemd-tmpfiles[157]: fchmod() of /var/log/journal/22dd6f32f5ee4e7f8feee8d0b7d1468a failed: Operation not permitted131server # [7209370.888616] server systemd-tmpfiles[157]: fchmod() of /run/log/journal failed: Operation not permitted132server # [7209370.891345] server systemd[1]: Finished Create System Files and Directories.133server # [7209370.892460] server systemd[1]: Starting Rebuild Journal Catalog...134server # [7209370.893224] server systemd[1]: Starting Record System Boot/Shutdown in UTMP...135server # [7209370.908566] server systemd[1]: Finished Record System Boot/Shutdown in UTMP.136server # [7209370.913183] server systemd[1]: Finished Rebuild Journal Catalog.137server # [7209370.914289] server systemd[1]: Starting Update is Completed...138server # [7209370.925119] server systemd[1]: Finished Update is Completed.139server # [7209370.946105] server systemd[1]: Finished Save Transient machine-id to Disk.140server # [7209371.327796] server systemd-networkd[179]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted141server # [7209371.327890] server systemd-networkd[179]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted142server # [7209371.334645] server systemd-networkd[179]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.143server # [7209371.334806] server systemd-networkd[179]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.144server # [7209371.334964] server systemd-networkd[179]: lo: Link UP145server # [7209371.334968] server systemd-networkd[179]: lo: Gained carrier146server # [7209371.335146] server systemd-networkd[179]: eth1: Configuring with /etc/systemd/network/40-eth1.network.147client # [7209370.721978] client systemd-journald[69]: Journal started148client # [7209370.722028] client systemd-journald[69]: Runtime Journal (/run/log/journal/5cb75fa9a85e45408f2147ae0c6d5f44) is 8M, max 2.5G, 2.4G free.149client # [7209370.726630] client systemd[1]: Finished Apply Kernel Variables.150client # [7209370.734006] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully.151client # [7209370.743733] client systemd[1]: Starting Flush Journal to Persistent Storage...152client # [7209370.744496] client systemd[1]: Starting Network Name Resolution...153client # [7209370.745106] client systemd[1]: Starting Create Static Device Nodes in /dev...154client # [7209370.752486] client systemd-journald[69]: Time spent on flushing to /var/log/journal/5cb75fa9a85e45408f2147ae0c6d5f44 is 1.857ms for 7 entries.155client # [7209370.752486] client systemd-journald[69]: System Journal (/var/log/journal/5cb75fa9a85e45408f2147ae0c6d5f44) is 8M, max 4G, 3.9G free.156client # [7209370.760643] client systemd[1]: Finished Create Static Device Nodes in /dev.157client # [7209370.761375] client systemd[1]: Reached target Preparation for Local File Systems.158client # [7209370.761501] client systemd[1]: Reached target Local File Systems.159client # [7209370.762320] client systemd[1]: Listening on Boot Loader Control Service Socket.160client # [7209370.762366] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container161client # [7209370.763215] client systemd[1]: Starting Save Transient machine-id to Disk...162client # [7209370.763252] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys163client # [7209370.831650] client systemd[1]: Finished Flush Journal to Persistent Storage.164client # [7209370.835566] client systemd[1]: Starting Create System Files and Directories...165client # [7209370.872851] client systemd[1]: Finished Firewall.166client # [7209370.873080] client systemd[1]: Reached target Preparation for Network.167client # [7209370.873287] client systemd[1]: Listening on Network Management Resolve Hook Socket.168client # [7209370.874694] client systemd[1]: Starting Network Management...169client # [7209370.887856] client systemd-tmpfiles[153]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted170client # [7209370.888401] client systemd-tmpfiles[153]: fchmod() of /var/log/journal failed: Operation not permitted171client # [7209370.888531] client systemd-tmpfiles[153]: fchmod() of /var/log/journal/5cb75fa9a85e45408f2147ae0c6d5f44 failed: Operation not permitted172client # [7209370.888729] client systemd-tmpfiles[153]: fchmod() of /run/log/journal failed: Operation not permitted173client # [7209370.891378] client systemd[1]: Finished Create System Files and Directories.174client # [7209370.892586] client systemd[1]: Starting Rebuild Journal Catalog...175client # [7209370.893283] client systemd[1]: Starting Record System Boot/Shutdown in UTMP...176client # [7209370.904602] client systemd[1]: Finished Record System Boot/Shutdown in UTMP.177client # [7209370.914302] client systemd[1]: Finished Rebuild Journal Catalog.178client # [7209370.915263] client systemd[1]: Starting Update is Completed...179client # [7209370.925119] client systemd[1]: Finished Update is Completed.180client # [7209370.944895] client systemd[1]: Finished Save Transient machine-id to Disk.181client # [7209371.316587] client systemd-networkd[175]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted182client # [7209371.316677] client systemd-networkd[175]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted183client # [7209371.323453] client systemd-networkd[175]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.184client # [7209371.323616] client systemd-networkd[175]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.185client # [7209371.323779] client systemd-networkd[175]: lo: Link UP186client # [7209371.323783] client systemd-networkd[175]: lo: Gained carrier187server # [7209371.335590] server systemd[1]: Started Network Management.188server # [7209371.340784] server systemd-networkd[179]: eth1: Link UP189server # [7209371.341318] server systemd-networkd[179]: eth1: Gained carrier190server # [7209371.341403] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd...191server # [7209371.381730] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd.192server # [7209371.465401] server systemd-resolved[94]: Positive Trust Anchors:193server # [7209371.465413] server systemd-resolved[94]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d194server # [7209371.465417] server systemd-resolved[94]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16195server # [7209371.465451] server systemd-resolved[94]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test196server # [7209371.487606] server systemd-resolved[94]: Using system hostname 'server'.197server # [7209371.488947] server systemd[1]: Started Network Name Resolution.198server # [7209371.489035] server systemd[1]: Reached target Network.199server # [7209371.489081] server systemd[1]: Reached target Network is Online.200server # [7209371.489120] server systemd[1]: Reached target System Initialization.201server # [7209371.489334] server systemd[1]: Started Renew ACME Certificate for test.foo.202server # [7209371.489371] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container203server # [7209371.489391] server systemd[1]: Started Daily Cleanup of Temporary Directories.204server # [7209371.489407] server systemd[1]: Reached target Timer Units.205server # [7209371.489522] server systemd[1]: Listening on D-Bus System Message Bus Socket.206server # [7209371.489780] server systemd[1]: Listening on Nix Daemon Socket.207server # [7209371.489901] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.208server # [7209371.489921] server systemd[1]: Reached target Socket Units.209server # [7209371.489959] server systemd[1]: Reached target Basic System.210server # [7209371.491243] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure...211server # [7209371.491958] server systemd[1]: Starting Import lastlog data into lastlog2 database...212server # [7209371.491993] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem213server # [7209371.492756] server systemd[1]: Starting Name Service Cache Daemon (nsncd)...214server # [7209371.493919] server systemd[1]: Starting D-Bus System Message Bus...215server # [7209371.550260] server systemd[1]: Finished Import lastlog data into lastlog2 database.216client # [7209371.323976] client systemd-networkd[175]: eth1: Configuring with /etc/systemd/network/40-eth1.network.217client # [7209371.324423] client systemd[1]: Started Network Management.218client # [7209371.340340] client systemd-networkd[175]: eth1: Link UP219client # [7209371.340821] client systemd-networkd[175]: eth1: Gained carrier220client # [7209371.341233] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd...221client # [7209371.358364] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd.222client # [7209371.482829] client systemd-resolved[96]: Positive Trust Anchors:223client # [7209371.482842] client systemd-resolved[96]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d224client # [7209371.482845] client systemd-resolved[96]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16225client # [7209371.482880] client systemd-resolved[96]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test226client # [7209371.504820] client systemd-resolved[96]: Using system hostname 'client'.227client # [7209371.506117] client systemd[1]: Started Network Name Resolution.228client # [7209371.506187] client systemd[1]: Reached target Network.229client # [7209371.506238] client systemd[1]: Reached target System Initialization.230client # [7209371.506281] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container231client # [7209371.506307] client systemd[1]: Started Daily Cleanup of Temporary Directories.232client # [7209371.506325] client systemd[1]: Reached target Timer Units.233client # [7209371.506440] client systemd[1]: Listening on D-Bus System Message Bus Socket.234client # [7209371.506548] client systemd[1]: Listening on Nix Daemon Socket.235client # [7209371.506648] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.236client # [7209371.506668] client systemd[1]: Reached target Socket Units.237client # [7209371.506701] client systemd[1]: Reached target Basic System.238client # [7209371.532485] client systemd[1]: Starting Import lastlog data into lastlog2 database...239client # [7209371.533372] client systemd[1]: Starting Name Service Cache Daemon (nsncd)...240client # [7209371.534595] client systemd[1]: Starting D-Bus System Message Bus...241client # [7209371.553629] client systemd[1]: Finished Import lastlog data into lastlog2 database.242ca # [7209371.676640] ca acme-setup-privileged[201]: + set -euo pipefail243ca # [7209371.676640] ca acme-setup-privileged[201]: + cd /var/lib/acme244ca # [7209371.677055] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts245ca # [7209371.678761] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts246ca # [7209371.680584] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo247ca # [7209371.680650] ca acme-setup-privileged[201]: + '[' -d ca.foo ']'248ca # [7209371.680650] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo249ca # [7209371.680650] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']'250ca # [7209371.726458] ca nsncd[203]: Aug 31 09:59:57.779 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"251ca # [7209371.729697] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully.252ca # [7209371.730562] ca systemd[1]: Started Name Service Cache Daemon (nsncd).253ca # [7209371.730618] ca systemd[1]: Reached target Host and Network Name Lookups.254ca # [7209371.730835] ca systemd[1]: Reached target User and Group Name Lookups.255ca # [7209371.732209] ca systemd[1]: Starting User Login Management...256ca # [7209371.732901] ca systemd[1]: Starting Permit User Sessions...257ca # [7209371.741878] ca systemd[1]: Finished Permit User Sessions.258ca # [7209371.742908] ca systemd[1]: Started Console Getty.259ca # [7209371.742951] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0260ca # [7209371.742966] ca systemd[1]: Reached target Login Prompts.261ca # [7209371.822042] ca dbus-broker-launch[207]: Looking up NSS user entry for 'systemd-timesync'...262ca # [7209371.822725] ca dbus-broker-launch[207]: NSS returned no entry for 'systemd-timesync'263ca # [7209371.822725] ca dbus-broker-launch[207]: Invalid user-name in /nix/store/nrvy3kisslkv7qydv3v2ib6szfdky5q3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"264ca # [7209371.823725] ca systemd[1]: Started D-Bus System Message Bus.265ca # [7209371.830799] ca dbus-broker-launch[207]: Ready266client # [7209371.698965] client nsncd[189]: Aug 31 09:59:57.752 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"267client # [7209371.699098] client systemd[1]: Started Name Service Cache Daemon (nsncd).268client # [7209371.699166] client systemd[1]: Reached target Host and Network Name Lookups.269client # [7209371.699221] client systemd[1]: Reached target User and Group Name Lookups.270client # [7209371.724986] client systemd[1]: Starting User Login Management...271client # [7209371.725835] client systemd[1]: Starting Permit User Sessions...272client # [7209371.733049] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully.273client # [7209371.737288] client systemd[1]: Finished Permit User Sessions.274client # [7209371.738289] client systemd[1]: Started Console Getty.275client # [7209371.738327] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0276client # [7209371.738349] client systemd[1]: Reached target Login Prompts.277client # [7209371.838166] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'...278client # [7209371.839607] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync'279client # [7209371.839607] client dbus-broker-launch[190]: Invalid user-name in /nix/store/ssk8893k9jd7id6pd9yzim0h6prlbdma-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"280client # [7209371.840407] client systemd[1]: Started D-Bus System Message Bus.281client # [7209371.847644] client dbus-broker-launch[190]: Ready282server # [7209371.690932] server acme-setup-privileged[192]: + set -euo pipefail283server # [7209371.690932] server acme-setup-privileged[192]: + cd /var/lib/acme284server # [7209371.690932] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts285server # [7209371.692603] server acme-setup-privileged[192]: + chown -R acme .lego/accounts286server # [7209371.694817] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo287server # [7209371.694817] server acme-setup-privileged[192]: + '[' -d test.foo ']'288server # [7209371.694817] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo289server # [7209371.694817] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']'290server # [7209371.698189] server nsncd[194]: Aug 31 09:59:57.751 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"291server # [7209371.709637] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully.292server # [7209371.725858] server systemd[1]: Started Name Service Cache Daemon (nsncd).293server # [7209371.727968] server systemd[1]: Reached target Host and Network Name Lookups.294server # [7209371.728187] server systemd[1]: Reached target User and Group Name Lookups.295server # [7209371.729471] server systemd[1]: Starting User Login Management...296server # [7209371.730254] server systemd[1]: Starting Permit User Sessions...297server # [7209371.740023] server systemd[1]: Finished Permit User Sessions.298server # [7209371.741639] server systemd[1]: Started Console Getty.299server # [7209371.741717] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0300server # [7209371.741757] server systemd[1]: Reached target Login Prompts.301server # [7209371.813578] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'...302server # [7209371.814160] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync'303server # [7209371.814160] server dbus-broker-launch[195]: Invalid user-name in /nix/store/aszr859gd9lnmlsj2dls188ya32g6xf8-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"304server # [7209371.814647] server systemd[1]: Started D-Bus System Message Bus.305server # [7209371.822087] server dbus-broker-launch[195]: Ready306ca # [7209372.345398] ca systemd-logind[235]: New seat seat0.307ca # [7209372.345572] ca systemd[1]: Started User Login Management.308ca # [7209372.373032] ca systemd[1]: Starting linger-users.service...309ca # [7209372.380928] ca acme-setup-start[219]: + set -euo pipefail310ca # [7209372.380928] ca acme-setup-start[219]: + test -e ca/key.pem311ca # [7209372.381208] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local312ca # [7209372.387930] ca systemd[1]: linger-users.service: Deactivated successfully.313ca # [7209372.387994] ca systemd[1]: Finished linger-users.service.314ca # [7209372.399432] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure.315ca # [7209372.400933] ca systemd[1]: Starting Ensure certificate for ca.foo...316ca # [7209372.580814] ca step-ca[204]: badger 2026/08/31 09:59:58 INFO: All 0 tables opened in 0s317ca # [7209372.588019] ca step-ca[204]: 2026/08/31 09:59:58 Building new tls configuration using step-ca x509 Signer Interface318ca # [7209372.593398] ca step-ca[204]: 2026/08/31 09:59:58 Starting Smallstep CA/0.30.2 (linux/arm64)319ca # [7209372.593398] ca step-ca[204]: 2026/08/31 09:59:58 Documentation: https://u.step.sm/docs/ca320ca # [7209372.593398] ca step-ca[204]: 2026/08/31 09:59:58 Community Discord: https://u.step.sm/discord321ca # [7209372.593398] ca step-ca[204]: 2026/08/31 09:59:58 Config file: /etc/smallstep/ca.json322ca # [7209372.593398] ca step-ca[204]: 2026/08/31 09:59:58 The primary server URL is https://ca.foo:1443323ca # [7209372.593398] ca step-ca[204]: 2026/08/31 09:59:58 Root certificates are available at https://ca.foo:1443/roots.pem324ca # [7209372.593398] ca step-ca[204]: 2026/08/31 09:59:58 X.509 Root Fingerprint: d8313f02428bf1dbd1c3ac697d9dbdb634b8b2133fa80e84a29326a25d92a16f325ca # [7209372.593825] ca systemd[1]: Started step-ca service.326ca # [7209372.594153] ca step-ca[204]: 2026/08/31 09:59:58 Serving HTTPS on 0.0.0.0:1443 ...327server # [7209372.341537] server systemd-logind[219]: New seat seat0.328server # [7209372.341694] server systemd[1]: Started User Login Management.329server # [7209372.372796] server systemd[1]: Starting linger-users.service...330server # [7209372.383623] server systemd[1]: linger-users.service: Deactivated successfully.331server # [7209372.383737] server systemd[1]: Finished linger-users.service.332server # [7209372.385449] server acme-setup-start[217]: + set -euo pipefail333server # [7209372.385673] server acme-setup-start[217]: + test -e ca/key.pem334server # [7209372.385673] server acme-setup-start[217]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local335server # [7209372.405777] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure.336server # [7209372.407188] server systemd[1]: Starting Ensure certificate for test.foo...337ca: must succeed: systemctl restart acme-order-renew-ca.foo.service 338client # [7209372.334770] client systemd-logind[205]: New seat seat0.339client # [7209372.334980] client systemd[1]: Started User Login Management.340client # [7209372.336263] client systemd[1]: Starting linger-users.service...341client # [7209372.380712] client systemd[1]: linger-users.service: Deactivated successfully.342client # [7209372.380857] client systemd[1]: Finished linger-users.service.343client # [7209372.381261] client systemd[1]: Reached target Multi-User System.344client # [7209372.381426] client systemd[1]: Startup finished in 2.179s.345client # [7209372.544193] client systemd-networkd[175]: eth1: Gained IPv6LL346ca # [7209372.864227] ca systemd-networkd[188]: eth1: Gained IPv6LL347ca # [7209372.938479] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/348ca # [7209372.941611] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']'349ca # [7209372.941669] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses=350ca # [7209372.957210] ca acme-ca.foo-start[293]: + cd ca.foo351ca # [7209372.957528] ca acme-ca.foo-start[293]: + cp -vp cert.pem ../out/cert.pem352ca # [7209372.958868] ca acme-ca.foo-start[294]: 'cert.pem' -> '../out/cert.pem'353ca # [7209372.959113] ca acme-ca.foo-start[293]: + cp -vp key.pem ../out/key.pem354ca # [7209372.960469] ca acme-ca.foo-start[293]: 'key.pem' -> '../out/key.pem'355ca # [7209372.960759] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem356ca # [7209372.962743] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem357ca # [7209372.964280] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem358ca # [7209372.966051] ca acme-ca.foo-start[256]: + for fixpath in out certificates359ca # [7209372.966051] ca acme-ca.foo-start[256]: + '[' -d out ']'360ca # [7209372.966112] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out361ca # [7209372.967933] ca acme-ca.foo-start[256]: + chown -R acme:nginx out362ca # [7209372.970962] ca acme-ca.foo-start[256]: + for fixpath in out certificates363ca # [7209372.970993] ca acme-ca.foo-start[256]: + '[' -d certificates ']'364ca # [7209373.008245] ca systemd[1]: Finished Ensure certificate for ca.foo.365ca # [7209373.010490] ca systemd[1]: Starting Nginx Web Server...366server # [7209372.930647] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/367server # [7209372.934321] server acme-test.foo-start[245]: + '[' -e out/acme-success ']'368server # [7209372.934403] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=369server # [7209372.945978] server acme-test.foo-start[255]: + cd test.foo370server # [7209372.946267] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem371server # [7209372.947785] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem'372server # [7209372.948093] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem373server # [7209372.949429] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem'374server # [7209372.949673] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem375server # [7209372.951487] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem376server # [7209372.953237] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem377server # [7209372.955131] server acme-test.foo-start[245]: + for fixpath in out certificates378server # [7209372.955153] server acme-test.foo-start[245]: + '[' -d out ']'379server # [7209372.955153] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out380server # [7209372.956706] server acme-test.foo-start[245]: + chown -R acme:nginx out381server # [7209372.960376] server acme-test.foo-start[245]: + for fixpath in out certificates382server # [7209372.960400] server acme-test.foo-start[245]: + '[' -d certificates ']'383server # [7209372.963966] server systemd[1]: Finished Ensure certificate for test.foo.384server # [7209372.965674] server systemd[1]: Starting Nginx Web Server...385server # [7209373.152218] server systemd-networkd[179]: eth1: Gained IPv6LL386ca # [7209373.595570] ca nginx-pre-start[305]: nginx: the configuration file /nix/store/97701lrj6pl2vidb5ipr1j6mjy5775bj-nginx.conf syntax is ok387ca # [7209373.595900] ca nginx-pre-start[305]: nginx: configuration file /nix/store/97701lrj6pl2vidb5ipr1j6mjy5775bj-nginx.conf test is successful388ca # [7209373.600385] ca systemd[1]: Started Nginx Web Server.389ca # [7209373.600741] ca systemd[1]: Reached target Multi-User System.390ca # [7209373.602037] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...391server # [7209373.591992] server nginx-pre-start[267]: nginx: the configuration file /nix/store/ldafm91pv9vld74irca8avm5fh9l2p2m-nginx.conf syntax is ok392server # [7209373.592364] server nginx-pre-start[267]: nginx: configuration file /nix/store/ldafm91pv9vld74irca8avm5fh9l2p2m-nginx.conf test is successful393server # [7209373.597375] server systemd[1]: Started Nginx Web Server.394server # [7209373.597784] server systemd[1]: Reached target Multi-User System.395server # [7209373.599197] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...396server # [7209374.284705] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/397server # [7209374.287130] server acme-order-renew-test.foo-start[270]: + set -euo pipefail398server # [7209374.287206] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108399server # [7209374.287370] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt400server # [7209374.288658] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run401server # [7209374.306634] server acme-order-renew-test.foo-start[282]: 2026/08/31 10:00:00 No key found for account none@none.tld. Generating a P256 key.402server # [7209374.306962] server acme-order-renew-test.foo-start[282]: 2026/08/31 10:00:00 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key403server # [7209374.340391] server acme-order-renew-test.foo-start[282]: 2026/08/31 10:00:00 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority404server # [7209374.343482] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.405server # [7209374.343482] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.406server # [7209374.343544] server acme-order-renew-test.foo-start[270]: + exit 10407server # [7209374.346971] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a408server # [7209374.347094] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'.409server # [7209374.347414] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo.410server # [7209374.347745] server systemd[1]: Startup finished in 4.153s.411ca # [7209374.268282] ca acme-order-renew-ca.foo-start[308]: Waiting to acquire lock in /run/acme/412ca # [7209374.271401] ca acme-order-renew-ca.foo-start[308]: + set -euo pipefail413ca # [7209374.271480] ca acme-order-renew-ca.foo-start[308]: + echo 88dc4fc401a6091a1bd9414ca # [7209374.271598] ca acme-order-renew-ca.foo-start[308]: + cmp -s domainhash.txt certificates/domainhash.txt415ca # [7209374.273010] ca acme-order-renew-ca.foo-start[308]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run416ca # [7209374.302160] ca acme-order-renew-ca.foo-start[319]: 2026/08/31 10:00:00 No key found for account none@none.tld. Generating a P256 key.417ca # [7209374.304041] ca acme-order-renew-ca.foo-start[319]: 2026/08/31 10:00:00 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key418ca # [7209374.330614] ca step-ca[204]: time="2026-08-31T10:00:00Z" level=info duration="107.241µs" duration-ns=107241 fields.time="2026-08-31T10:00:00Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=e162e782-bcd4-4a48-9ddf-f9b4ce23a2b4 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=419ca # [7209374.332603] ca acme-order-renew-ca.foo-start[319]: 2026/08/31 10:00:00 [INFO] acme: Registering account for none@none.tld420ca # [7209374.334729] ca step-ca[204]: time="2026-08-31T10:00:00Z" level=info duration=1.836145ms duration-ns=1836145 fields.time="2026-08-31T10:00:00Z" method=HEAD name=ca nonce=c09Ec3U2ZE54cW5zaHBzdFpzQ05sZEpmaWdPN1pnM1E path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=8b92d9e3-cd3f-4696-b988-20997206925b size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=421ca # [7209374.337489] ca step-ca[204]: time="2026-08-31T10:00:00Z" level=info duration=2.068389ms duration-ns=2068389 fields.time="2026-08-31T10:00:00Z" method=POST name=ca nonce=TFBPcjZ4R3c2Vkl6QUFtMlV0TjNNSXg0UUxWblNmS0g path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=9c556dee-f27b-435f-b7ff-298512cd86bf response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/TGW6NV8eixsyMR8sqlYbsN9ZEoiIUoWg/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=422ca # [7209374.337816] ca acme-order-renew-ca.foo-start[319]: !!!! HEADS UP !!!!423ca # [7209374.337816] ca acme-order-renew-ca.foo-start[319]: Your account credentials have been saved in your424ca # [7209374.337816] ca acme-order-renew-ca.foo-start[319]: configuration directory at "accounts".425ca # [7209374.337816] ca acme-order-renew-ca.foo-start[319]: You should make a secure backup of this folder now. This426ca # [7209374.337816] ca acme-order-renew-ca.foo-start[319]: configuration directory will also contain private keys427ca # [7209374.337816] ca acme-order-renew-ca.foo-start[319]: generated by lego and certificates obtained from the ACME428ca # [7209374.337816] ca acme-order-renew-ca.foo-start[319]: server. Making regular backups of this folder is ideal.429ca # [7209374.338149] ca acme-order-renew-ca.foo-start[319]: 2026/08/31 10:00:00 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate430ca # [7209374.341988] ca step-ca[204]: time="2026-08-31T10:00:00Z" level=info duration=3.266885ms duration-ns=3266885 fields.time="2026-08-31T10:00:00Z" method=POST name=ca nonce=blJwYVlrSFlraUFkaFdlTVZHSXRUSDJIRndDRXlwVnE path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=64b932fd-a4cd-4cf4-a2c5-f35489cb30b3 response="{\"id\":\"u8YwpF11rbTaeHs9whoyLZC4YfGfkKIS\",\"status\":\"pending\",\"expires\":\"2026-09-01T10:00:00Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-31T09:59:00Z\",\"notAfter\":\"2026-11-29T10:00:00Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/3tcCruCX9AQy9vdk7yq0wvmJkXfrRUUN\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/u8YwpF11rbTaeHs9whoyLZC4YfGfkKIS/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=431ca # [7209374.402131] ca step-ca[204]: time="2026-08-31T10:00:00Z" level=info duration=3.241965ms duration-ns=3241965 fields.time="2026-08-31T10:00:00Z" method=POST name=ca nonce=MkFsZlNzSlUzS1QyWmRoYXlnOXFzSlYwcGk4aTdKUHA path=/acme/acme/authz/3tcCruCX9AQy9vdk7yq0wvmJkXfrRUUN protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=5cb9fd28-da0b-432b-b44f-33afd549c3ba response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"3MuDDA8BjDot5pv7f1aemh9H9q7RCfCW\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/3tcCruCX9AQy9vdk7yq0wvmJkXfrRUUN/Z23unmpk7wLpqHocGhJRiUP7ofunzc5c\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"3MuDDA8BjDot5pv7f1aemh9H9q7RCfCW\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/3tcCruCX9AQy9vdk7yq0wvmJkXfrRUUN/XmOVMc9cxDiH86gbxAhZexJqxaoRAgmH\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"3MuDDA8BjDot5pv7f1aemh9H9q7RCfCW\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/3tcCruCX9AQy9vdk7yq0wvmJkXfrRUUN/sfZekIZhmVZC3yGxvg7b3a7CY8N9csDb\"}],\"wildcard\":false,\"expires\":\"2026-09-01T10:00:00Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=432ca # [7209374.402424] ca acme-order-renew-ca.foo-start[319]: 2026/08/31 10:00:00 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/3tcCruCX9AQy9vdk7yq0wvmJkXfrRUUN433ca # [7209374.402424] ca acme-order-renew-ca.foo-start[319]: 2026/08/31 10:00:00 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01434ca # [7209374.402424] ca acme-order-renew-ca.foo-start[319]: 2026/08/31 10:00:00 [INFO] [ca.foo] acme: use http-01 solver435ca # [7209374.402503] ca acme-order-renew-ca.foo-start[319]: 2026/08/31 10:00:00 [INFO] [ca.foo] acme: Trying to solve HTTP-01436ca # [7209374.405920] ca step-ca[204]: time="2026-08-31T10:00:00Z" level=info duration=3.008162ms duration-ns=3008162 fields.time="2026-08-31T10:00:00Z" method=POST name=ca nonce=aGF2U0tLZlRGUUE4MFRneFA5dXdUMnpMb241VExTb1o path=/acme/acme/challenge/3tcCruCX9AQy9vdk7yq0wvmJkXfrRUUN/XmOVMc9cxDiH86gbxAhZexJqxaoRAgmH protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=da8fdb8f-1fa5-4171-80e2-440177976705 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"3MuDDA8BjDot5pv7f1aemh9H9q7RCfCW\",\"validated\":\"2026-08-31T10:00:00Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/3tcCruCX9AQy9vdk7yq0wvmJkXfrRUUN/XmOVMc9cxDiH86gbxAhZexJqxaoRAgmH\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=437ca # [7209374.406224] ca acme-order-renew-ca.foo-start[319]: 2026/08/31 10:00:00 [INFO] [ca.foo] The server validated our request438ca # [7209374.406289] ca acme-order-renew-ca.foo-start[319]: 2026/08/31 10:00:00 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates439ca # [7209374.411767] ca step-ca[204]: time="2026-08-31T10:00:00Z" level=info duration=4.648224ms duration-ns=4648224 fields.time="2026-08-31T10:00:00Z" method=POST name=ca nonce=ajRFdDdpcTNIbDNZUnJqZWJ2MEpzbTM1QmNaOXg5VEw path=/acme/acme/order/u8YwpF11rbTaeHs9whoyLZC4YfGfkKIS/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=8076b539-108b-4280-b3a0-30fb2c61d229 response="{\"id\":\"u8YwpF11rbTaeHs9whoyLZC4YfGfkKIS\",\"status\":\"valid\",\"expires\":\"2026-09-01T10:00:00Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-31T09:59:00Z\",\"notAfter\":\"2026-11-29T10:00:00Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/3tcCruCX9AQy9vdk7yq0wvmJkXfrRUUN\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/u8YwpF11rbTaeHs9whoyLZC4YfGfkKIS/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/rADvf5RD9ccwExRy2i8GAgZgX2iJPBrc\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=440ca # [7209374.413492] ca step-ca[204]: time="2026-08-31T10:00:00Z" level=info certificate=MIIB0zCCAXmgAwIBAgIQfSHdmWeQeVG1e6be51OUbjAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MzEwOTU5MDBaFw0yNjExMjkxMDAwMDBaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABFv4TnEWW5JjPQ8fwDdpwkiQfTVlO76FkIS+pvH3qn0B/OvR6mlXkk7d2XyMyPgSN/Qq02muK+q09CGjTSS3adWjgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUeAToN1a/IulIP1WdjF1/IKCnerUwHwYDVR0jBBgwFoAUfhxJ9/ma1l0Dp91a/5v5pz7xYscwEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNIADBFAiEA23RMTpMlqdxiTzURztiKO1OwtO2zkveDhkW2A/FjIBcCIB+DHT77lADObcZR0pFolq/iSd8djcDjFtiecQs15jV8 duration=1.105816ms duration-ns=1105816 fields.time="2026-08-31T10:00:00Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=NlY2dGQyS3dmSkNEWE9sMkRaZGNXVkxOSzhQRFBzcXY path=/acme/acme/certificate/rADvf5RD9ccwExRy2i8GAgZgX2iJPBrc protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=ffc3135d-2f7c-4cbf-a03d-3c16973bde05 sans="map[dns:[ca.foo]]" serial=166329339835929019369555708365314954350 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-31T09:59:00Z" valid-to="2026-11-29T10:00:00Z"441ca # [7209374.413687] ca acme-order-renew-ca.foo-start[319]: 2026/08/31 10:00:00 [INFO] [ca.foo] Server responded with a certificate.442ca # [7209374.417791] ca acme-order-renew-ca.foo-start[308]: + mv domainhash.txt certificates/443ca # [7209374.419373] ca acme-order-renew-ca.foo-start[308]: + touch out/acme-success444ca # [7209374.420711] ca acme-order-renew-ca.foo-start[308]: + cmp -s certificates/ca.foo.crt out/fullchain.pem445ca # [7209374.421758] ca acme-order-renew-ca.foo-start[308]: + touch out/renewed446ca # [7209374.423166] ca acme-order-renew-ca.foo-start[308]: + echo Installing new certificate447ca # [7209374.423166] ca acme-order-renew-ca.foo-start[308]: Installing new certificate448ca # [7209374.423166] ca acme-order-renew-ca.foo-start[308]: + cp -vp certificates/ca.foo.crt out/fullchain.pem449ca # [7209374.424710] ca acme-order-renew-ca.foo-start[352]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem'450ca # [7209374.424928] ca acme-order-renew-ca.foo-start[308]: + cp -vp certificates/ca.foo.key out/key.pem451ca # [7209374.426312] ca acme-order-renew-ca.foo-start[353]: 'certificates/ca.foo.key' -> 'out/key.pem'452ca # [7209374.426540] ca acme-order-renew-ca.foo-start[308]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem453ca # [7209374.427962] ca acme-order-renew-ca.foo-start[354]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem'454ca # [7209374.428210] ca acme-order-renew-ca.foo-start[308]: + ln -sf fullchain.pem out/cert.pem455ca # [7209374.429787] ca acme-order-renew-ca.foo-start[308]: + cat out/key.pem out/fullchain.pem456ca # [7209374.432295] ca acme-order-renew-ca.foo-start[308]: + for fixpath in out certificates457ca # [7209374.432327] ca acme-order-renew-ca.foo-start[308]: + '[' -d out ']'458ca # [7209374.432327] ca acme-order-renew-ca.foo-start[308]: + chmod -R u=rwX,g=rX,o= out459ca # [7209374.434498] ca acme-order-renew-ca.foo-start[308]: + chown -R acme:nginx out460ca # [7209374.436746] ca acme-order-renew-ca.foo-start[308]: + for fixpath in out certificates461ca # [7209374.436773] ca acme-order-renew-ca.foo-start[308]: + '[' -d certificates ']'462ca # [7209374.436773] ca acme-order-renew-ca.foo-start[308]: + chmod -R u=rwX,g=rX,o= certificates463ca # [7209374.438209] ca acme-order-renew-ca.foo-start[308]: + chown -R acme:nginx certificates464ca # [7209374.440320] ca acme-order-renew-ca.foo-start[308]: + chmod -R u=rwX,g=,o= accounts/.465ca # [7209374.584673] ca systemd[1]: Reloading Nginx Web Server...466ca # [7209374.589254] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.467ca # [7209374.589436] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.468ca # [7209375.133459] ca nginx[370]: nginx: the configuration file /nix/store/97701lrj6pl2vidb5ipr1j6mjy5775bj-nginx.conf syntax is ok469ca # [7209375.133949] ca nginx[370]: nginx: configuration file /nix/store/97701lrj6pl2vidb5ipr1j6mjy5775bj-nginx.conf test is successful470ca # [7209375.769025] ca systemd[1]: Reloaded Nginx Web Server.471ca # [7209375.769484] ca systemd[1]: Startup finished in 5.551s.472ca # [7209375.814499] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...473ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 4.14 seconds)474ca # [7209376.543504] ca acme-order-renew-ca.foo-start[385]: Waiting to acquire lock in /run/acme/475ca # [7209376.546221] ca acme-order-renew-ca.foo-start[385]: + set -euo pipefail476ca # [7209376.546299] ca acme-order-renew-ca.foo-start[385]: + echo 88dc4fc401a6091a1bd9477ca # [7209376.546419] ca acme-order-renew-ca.foo-start[385]: + cmp -s domainhash.txt certificates/domainhash.txt478ca # [7209376.547495] ca acme-order-renew-ca.foo-start[385]: + '[' -e certificates/ca.foo.key ']'479ca # [7209376.547535] ca acme-order-renew-ca.foo-start[385]: + '[' -e certificates/ca.foo.crt ']'480ca # [7209376.548345] ca acme-order-renew-ca.foo-start[393]: ++ find accounts -name none@none.tld.key481ca # [7209376.551698] ca acme-order-renew-ca.foo-start[385]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']'482ca # [7209376.551743] ca acme-order-renew-ca.foo-start[385]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic483ca # [7209376.590793] ca step-ca[204]: time="2026-08-31T10:00:02Z" level=info duration="42.56µs" duration-ns=42560 fields.time="2026-08-31T10:00:02Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=e90984eb-cf69-417a-a236-8fefbd6e6aad response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=484ca # [7209376.591564] ca acme-order-renew-ca.foo-start[394]: 2026/08/31 10:00:02 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint485ca # [7209376.591564] ca acme-order-renew-ca.foo-start[394]: 2026/08/31 10:00:02 [INFO] [ca.foo] The certificate expires at 2026-11-29T10:00:00Z, the renewal can be performed in 1439h59m37.355527277s: no renewal.486ca # [7209376.591935] ca acme-order-renew-ca.foo-start[385]: + mv domainhash.txt certificates/487ca # [7209376.593629] ca acme-order-renew-ca.foo-start[385]: + touch out/acme-success488ca # [7209376.595024] ca acme-order-renew-ca.foo-start[385]: + cmp -s certificates/ca.foo.crt out/fullchain.pem489ca # [7209376.596062] ca acme-order-renew-ca.foo-start[385]: + for fixpath in out certificates490ca # [7209376.596062] ca acme-order-renew-ca.foo-start[385]: + '[' -d out ']'491ca # [7209376.596161] ca acme-order-renew-ca.foo-start[385]: + chmod -R u=rwX,g=rX,o= out492ca # [7209376.597661] ca acme-order-renew-ca.foo-start[385]: + chown -R acme:nginx out493ca # [7209376.599886] ca acme-order-renew-ca.foo-start[385]: + for fixpath in out certificates494ca # [7209376.599886] ca acme-order-renew-ca.foo-start[385]: + '[' -d certificates ']'495ca # [7209376.600078] ca acme-order-renew-ca.foo-start[385]: + chmod -R u=rwX,g=rX,o= certificates496ca # [7209376.601375] ca acme-order-renew-ca.foo-start[385]: + chown -R acme:nginx certificates497ca # [7209376.604071] ca acme-order-renew-ca.foo-start[385]: + chmod -R u=rwX,g=,o= accounts/.498ca # [7209376.789621] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.499ca # [7209376.789824] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.500server: must succeed: systemctl restart acme-test.foo.service501server # [7209379.819211] server systemd[1]: acme-test.foo.service: Deactivated successfully.502server # [7209379.819381] server systemd[1]: Stopped Ensure certificate for test.foo.503server # [7209379.820447] server systemd[1]: Stopping Ensure certificate for test.foo...504server # [7209379.822382] server systemd[1]: Starting Ensure certificate for test.foo...505server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.79 seconds)506client: waiting for success: curl -v https://test.foo507* Trying [2001:db8:1::3]:443...508* Host test.foo:443 was resolved.509* IPv6: 2001:db8:1::3510* IPv4: 192.168.1.3511* ALPN: curl offers h2,http/1.1512} [5 bytes data]513* TLSv1.3 (OUT), TLS handshake, Client hello (1):514} [1552 bytes data]515* SSL Trust Anchors:516* OpenSSL default paths (fallback)517{ [5 bytes data]518* TLSv1.3 (IN), TLS handshake, Server hello (2):519{ [1210 bytes data]520* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):521{ [1 bytes data]522* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):523{ [19 bytes data]524* TLSv1.3 (IN), TLS handshake, Certificate (11):525{ [1007 bytes data]526* TLSv1.3 (IN), TLS handshake, CERT verify (15):527{ [110 bytes data]528* TLSv1.3 (IN), TLS handshake, Finished (20):529{ [52 bytes data]530* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):531} [1 bytes data]532* TLSv1.3 (OUT), TLS handshake, Finished (20):533} [52 bytes data]534* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey535* ALPN: server accepted h2536* Server certificate:537* subject: CN=test.foo538* start date: Aug 31 09:59:58 2026 GMT539* expire date: Sep 30 09:59:58 2028 GMT540* issuer: CN=minica root ca 4a6e0e541* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384542* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384543* subjectAltName: "test.foo" matches cert's "test.foo"544* OpenSSL verify result: 13545* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)546* closing connection #0547curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)548More details here: https://curl.se/docs/sslcerts.html549550curl failed to verify the legitimacy of the server and therefore could not551establish a secure connection to it. To learn more about this situation and552how to fix it, please visit the webpage mentioned above.553server # [7209380.560519] server acme-test.foo-start[317]: Waiting to acquire lock in /run/acme/554server # [7209380.563342] server acme-test.foo-start[317]: + '[' -e out/acme-success ']'555server # [7209380.563381] server acme-test.foo-start[317]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=556server # [7209380.574430] server acme-test.foo-start[327]: + cd test.foo557server # [7209380.574684] server acme-test.foo-start[327]: + cp -vp cert.pem ../out/cert.pem558server # [7209380.576154] server acme-test.foo-start[328]: 'cert.pem' -> '../out/cert.pem'559server # [7209380.576381] server acme-test.foo-start[327]: + cp -vp key.pem ../out/key.pem560server # [7209380.577666] server acme-test.foo-start[327]: 'key.pem' -> '../out/key.pem'561server # [7209380.577903] server acme-test.foo-start[317]: + cat out/cert.pem ca/cert.pem562server # [7209380.579869] server acme-test.foo-start[317]: + cp ca/cert.pem out/chain.pem563server # [7209380.581581] server acme-test.foo-start[317]: + cat out/key.pem out/fullchain.pem564server # [7209380.583248] server acme-test.foo-start[317]: + for fixpath in out certificates565server # [7209380.583272] server acme-test.foo-start[317]: + '[' -d out ']'566server # [7209380.583290] server acme-test.foo-start[317]: + chmod -R u=rwX,g=rX,o= out567server # [7209380.584794] server acme-test.foo-start[317]: + chown -R acme:nginx out568server # [7209380.587199] server acme-test.foo-start[317]: + for fixpath in out certificates569server # [7209380.587240] server acme-test.foo-start[317]: + '[' -d certificates ']'570server # [7209380.591615] server systemd[1]: Finished Ensure certificate for test.foo.571server # [7209380.594096] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...572server # [7209381.304741] server acme-order-renew-test.foo-start[335]: Waiting to acquire lock in /run/acme/573server # [7209381.307879] server acme-order-renew-test.foo-start[335]: + set -euo pipefail574server # [7209381.307966] server acme-order-renew-test.foo-start[335]: + echo ad12aa6741ce4bd2c108575server # [7209381.308089] server acme-order-renew-test.foo-start[335]: + cmp -s domainhash.txt certificates/domainhash.txt576server # [7209381.309220] server acme-order-renew-test.foo-start[335]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run577server # [7209381.384455] server acme-order-renew-test.foo-start[343]: 2026/08/31 10:00:07 [INFO] acme: Registering account for none@none.tld578server # [7209381.400155] server acme-order-renew-test.foo-start[343]: !!!! HEADS UP !!!!579server # [7209381.400155] server acme-order-renew-test.foo-start[343]: Your account credentials have been saved in your580server # [7209381.400155] server acme-order-renew-test.foo-start[343]: configuration directory at "accounts".581server # [7209381.400155] server acme-order-renew-test.foo-start[343]: You should make a secure backup of this folder now. This582server # [7209381.400155] server acme-order-renew-test.foo-start[343]: configuration directory will also contain private keys583server # [7209381.400155] server acme-order-renew-test.foo-start[343]: generated by lego and certificates obtained from the ACME584server # [7209381.400155] server acme-order-renew-test.foo-start[343]: server. Making regular backups of this folder is ideal.585server # [7209381.400756] server acme-order-renew-test.foo-start[343]: 2026/08/31 10:00:07 [INFO] [test.foo] acme: Obtaining bundled SAN certificate586server # [7209381.478197] server acme-order-renew-test.foo-start[343]: 2026/08/31 10:00:07 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/7d3ZshfB1buDMrvq3ZoCzk6tLxiAV5ze587server # [7209381.478197] server acme-order-renew-test.foo-start[343]: 2026/08/31 10:00:07 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01588server # [7209381.478197] server acme-order-renew-test.foo-start[343]: 2026/08/31 10:00:07 [INFO] [test.foo] acme: use http-01 solver589server # [7209381.478197] server acme-order-renew-test.foo-start[343]: 2026/08/31 10:00:07 [INFO] [test.foo] acme: Trying to solve HTTP-01590server # [7209381.489587] server acme-order-renew-test.foo-start[343]: 2026/08/31 10:00:07 [INFO] [test.foo] The server validated our request591server # [7209381.489725] server acme-order-renew-test.foo-start[343]: 2026/08/31 10:00:07 [INFO] [test.foo] acme: Validations succeeded; requesting certificates592server # [7209381.511267] server acme-order-renew-test.foo-start[343]: 2026/08/31 10:00:07 [INFO] [test.foo] Server responded with a certificate.593server # [7209381.515956] server acme-order-renew-test.foo-start[335]: + mv domainhash.txt certificates/594server # [7209381.518863] server acme-order-renew-test.foo-start[335]: + touch out/acme-success595server # [7209381.520662] server acme-order-renew-test.foo-start[335]: + cmp -s certificates/test.foo.crt out/fullchain.pem596server # [7209381.521849] server acme-order-renew-test.foo-start[335]: + touch out/renewed597server # [7209381.523530] server acme-order-renew-test.foo-start[335]: + echo Installing new certificate598server # [7209381.523530] server acme-order-renew-test.foo-start[335]: Installing new certificate599server # [7209381.523615] server acme-order-renew-test.foo-start[335]: + cp -vp certificates/test.foo.crt out/fullchain.pem600server # [7209381.525061] server acme-order-renew-test.foo-start[375]: 'certificates/test.foo.crt' -> 'out/fullchain.pem'601server # [7209381.525300] server acme-order-renew-test.foo-start[335]: + cp -vp certificates/test.foo.key out/key.pem602server # [7209381.526737] server acme-order-renew-test.foo-start[376]: 'certificates/test.foo.key' -> 'out/key.pem'603server # [7209381.526959] server acme-order-renew-test.foo-start[335]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem604server # [7209381.528416] server acme-order-renew-test.foo-start[377]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem'605server # [7209381.528636] server acme-order-renew-test.foo-start[335]: + ln -sf fullchain.pem out/cert.pem606server # [7209381.530324] server acme-order-renew-test.foo-start[335]: + cat out/key.pem out/fullchain.pem607server # [7209381.532087] server acme-order-renew-test.foo-start[335]: + for fixpath in out certificates608server # [7209381.532128] server acme-order-renew-test.foo-start[335]: + '[' -d out ']'609server # [7209381.532128] server acme-order-renew-test.foo-start[335]: + chmod -R u=rwX,g=rX,o= out610server # [7209381.533723] server acme-order-renew-test.foo-start[335]: + chown -R acme:nginx out611server # [7209381.536328] server acme-order-renew-test.foo-start[335]: + for fixpath in out certificates612server # [7209381.536328] server acme-order-renew-test.foo-start[335]: + '[' -d certificates ']'613server # [7209381.536328] server acme-order-renew-test.foo-start[335]: + chmod -R u=rwX,g=rX,o= certificates614server # [7209381.537699] server acme-order-renew-test.foo-start[335]: + chown -R acme:nginx certificates615server # [7209381.540717] server acme-order-renew-test.foo-start[335]: + chmod -R u=rwX,g=,o= accounts/.616* Trying [2001:db8:1::3]:443...617* Host test.foo:443 was resolved.618* IPv6: 2001:db8:1::3619* IPv4: 192.168.1.3620* ALPN: curl offers h2,http/1.1621} [5 bytes data]622* TLSv1.3 (OUT), TLS handshake, Client hello (1):623} [1552 bytes data]624* SSL Trust Anchors:625* OpenSSL default paths (fallback)626{ [5 bytes data]627* TLSv1.3 (IN), TLS handshake, Server hello (2):628{ [1210 bytes data]629* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):630{ [1 bytes data]631* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):632{ [19 bytes data]633* TLSv1.3 (IN), TLS handshake, Certificate (11):634{ [1007 bytes data]635* TLSv1.3 (IN), TLS handshake, CERT verify (15):636{ [110 bytes data]637* TLSv1.3 (IN), TLS handshake, Finished (20):638{ [52 bytes data]639* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):640} [1 bytes data]641* TLSv1.3 (OUT), TLS handshake, Finished (20):642} [52 bytes data]643* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey644* ALPN: server accepted h2645* Server certificate:646* subject: CN=test.foo647* start date: Aug 31 09:59:58 2026 GMT648* expire date: Sep 30 09:59:58 2028 GMT649* issuer: CN=minica root ca 4a6e0e650* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384651* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384652* subjectAltName: "test.foo" matches cert's "test.foo"653* OpenSSL verify result: 13654* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)655* closing connection #0656curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)657More details here: https://curl.se/docs/sslcerts.html658659curl failed to verify the legitimacy of the server and therefore could not660establish a secure connection to it. To learn more about this situation and661how to fix it, please visit the webpage mentioned above.662ca # [7209381.383489] ca step-ca[204]: time="2026-08-31T10:00:07Z" level=info duration="46.881µs" duration-ns=46881 fields.time="2026-08-31T10:00:07Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=ed80f812-5973-4232-8b33-157a67f69a9a response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=663ca # [7209381.391090] ca step-ca[204]: time="2026-08-31T10:00:07Z" level=info duration=2.078349ms duration-ns=2078349 fields.time="2026-08-31T10:00:07Z" method=HEAD name=ca nonce=aFJvMFptRWYxYlhSQWF1cnZvbXk0RnJXejBMalpBemw path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=d39fe785-a198-4118-869a-e769921dc4a5 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=664ca # [7209381.399093] ca step-ca[204]: time="2026-08-31T10:00:07Z" level=info duration=3.60193ms duration-ns=3601930 fields.time="2026-08-31T10:00:07Z" method=POST name=ca nonce=NVBxcHc3NGp3bzJxZklPZWFNT0NKYjJwMFU3WGpCdng path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=a6e31f52-1dd0-436b-87e6-c52592a1d048 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/6WYUHpE3JYVE95EpvR7Y4OwSKqYwc0qd/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=665ca # [7209381.411159] ca step-ca[204]: time="2026-08-31T10:00:07Z" level=info duration=7.100219ms duration-ns=7100219 fields.time="2026-08-31T10:00:07Z" method=POST name=ca nonce=RW5TVGd5cGZNdkJ0UDYyNFlGVmpwUjJCNHM1d0tyQVI path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=5fa3ec21-a0bd-4650-8d87-3c80fde4c745 response="{\"id\":\"5RQkcXJUhEHEfzoB0MOmRkVsG8hSEYkq\",\"status\":\"pending\",\"expires\":\"2026-09-01T10:00:07Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-31T09:59:07Z\",\"notAfter\":\"2026-11-29T10:00:07Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/7d3ZshfB1buDMrvq3ZoCzk6tLxiAV5ze\"],\"finalize\":\"https://ca.foo/acme/acme/order/5RQkcXJUhEHEfzoB0MOmRkVsG8hSEYkq/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=666ca # [7209381.477364] ca step-ca[204]: time="2026-08-31T10:00:07Z" level=info duration=5.344755ms duration-ns=5344755 fields.time="2026-08-31T10:00:07Z" method=POST name=ca nonce=SXRGWmVBTlgzNjBSRnZXdlNaWFc1cGZDSUh6TGc0MHI path=/acme/acme/authz/7d3ZshfB1buDMrvq3ZoCzk6tLxiAV5ze protocol=HTTP/1.1 referer= remote-address="::1" request-id=79a40ae8-6e74-4bbf-907c-60f69e437b0e response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"U7QQYI7mevy5HxA65SYG8ZDXvE2GvNvp\",\"url\":\"https://ca.foo/acme/acme/challenge/7d3ZshfB1buDMrvq3ZoCzk6tLxiAV5ze/fWgIZGcaQIxQunGrhMrYyqu2pweO1MSQ\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"U7QQYI7mevy5HxA65SYG8ZDXvE2GvNvp\",\"url\":\"https://ca.foo/acme/acme/challenge/7d3ZshfB1buDMrvq3ZoCzk6tLxiAV5ze/yKFBwmYV32u897kdVdl1NUZ9fMeBh4RV\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"U7QQYI7mevy5HxA65SYG8ZDXvE2GvNvp\",\"url\":\"https://ca.foo/acme/acme/challenge/7d3ZshfB1buDMrvq3ZoCzk6tLxiAV5ze/Y74tIxrQxVtMxToPPg7H6yzVIzJWP9qY\"}],\"wildcard\":false,\"expires\":\"2026-09-01T10:00:07Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=667ca # [7209381.488929] ca step-ca[204]: time="2026-08-31T10:00:07Z" level=info duration=6.957417ms duration-ns=6957417 fields.time="2026-08-31T10:00:07Z" method=POST name=ca nonce=QXIyTWlXOEtmQXE1WEVaeG44bFFZVDRYTEhMdnpaRjM path=/acme/acme/challenge/7d3ZshfB1buDMrvq3ZoCzk6tLxiAV5ze/yKFBwmYV32u897kdVdl1NUZ9fMeBh4RV protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=c6b6600d-b777-45a5-8f41-5be0047ed5ff response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"U7QQYI7mevy5HxA65SYG8ZDXvE2GvNvp\",\"validated\":\"2026-08-31T10:00:07Z\",\"url\":\"https://ca.foo/acme/acme/challenge/7d3ZshfB1buDMrvq3ZoCzk6tLxiAV5ze/yKFBwmYV32u897kdVdl1NUZ9fMeBh4RV\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=668ca # [7209381.501229] ca step-ca[204]: time="2026-08-31T10:00:07Z" level=info duration=8.64356ms duration-ns=8643560 fields.time="2026-08-31T10:00:07Z" method=POST name=ca nonce=ekJ5ZTM0dHFiMGRFV3FOZGJTRW5NZEJ1YmVONU0zV0U path=/acme/acme/order/5RQkcXJUhEHEfzoB0MOmRkVsG8hSEYkq/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=c5ef492b-24c5-4d07-9ea6-3d47e8adb45c response="{\"id\":\"5RQkcXJUhEHEfzoB0MOmRkVsG8hSEYkq\",\"status\":\"valid\",\"expires\":\"2026-09-01T10:00:07Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-31T09:59:07Z\",\"notAfter\":\"2026-11-29T10:00:07Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/7d3ZshfB1buDMrvq3ZoCzk6tLxiAV5ze\"],\"finalize\":\"https://ca.foo/acme/acme/order/5RQkcXJUhEHEfzoB0MOmRkVsG8hSEYkq/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/LaSjnLtUmDFBxXdh6Lbb5lUw6DEMSCEa\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=669ca # [7209381.511008] ca step-ca[204]: time="2026-08-31T10:00:07Z" level=info certificate=MIIB2TCCAX6gAwIBAgIRAJhpXl/mdfAW8QfVu5ZjZoYwCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODMxMDk1OTA3WhcNMjYxMTI5MTAwMDA3WjATMREwDwYDVQQDEwh0ZXN0LmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABL/ANseA4Gciq0JOo6TBQgecQI9iHsxtRDlhNTxNTjgM6o+3reDjGrRKFDvRT4oS4TtPvlXpXifD4wVSirAkauCjgaYwgaMwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUG0y3vwBk+c85viju9L9Z6pE7FvAwHwYDVR0jBBgwFoAUfhxJ9/ma1l0Dp91a/5v5pz7xYscwEwYDVR0RBAwwCoIIdGVzdC5mb28wHQYMKwYBBAGCpGTGKEABBA0wCwIBBgQEYWNtZQQAMAoGCCqGSM49BAMCA0kAMEYCIQDFikhdbBzSlqTmli/Fd444hjSWqUuO9yd3gMhWMO6FpAIhALaojS6+Auqfmch/1FZw4ekf+r2P+wmXixeJlBGGxyFY duration=4.022456ms duration-ns=4022456 fields.time="2026-08-31T10:00:07Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=VTVOUUhVckhrelk2a2JuWDBENGVwbk1XQmVzNjFuUVM path=/acme/acme/certificate/LaSjnLtUmDFBxXdh6Lbb5lUw6DEMSCEa protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=41517401-8e7f-47a5-97ea-233bbb722197 sans="map[dns:[test.foo]]" serial=202589760673955682065462918951714645638 size=1352 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-31T09:59:07Z" valid-to="2026-11-29T10:00:07Z"670server # [7209381.770348] server systemd[1]: Reloading Nginx Web Server...671server # [7209381.774550] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully.672server # [7209381.774780] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo.673* Host test.foo:443 was resolved.674* IPv6: 2001:db8:1::3675* IPv4: 192.168.1.3676* Trying [2001:db8:1::3]:443...677* ALPN: curl offers h2,http/1.1678} [5 bytes data]679* TLSv1.3 (OUT), TLS handshake, Client hello (1):680} [1552 bytes data]681* SSL Trust Anchors:682* OpenSSL default paths (fallback)683{ [5 bytes data]684* TLSv1.3 (IN), TLS handshake, Server hello (2):685{ [1210 bytes data]686* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):687{ [1 bytes data]688* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):689{ [19 bytes data]690* TLSv1.3 (IN), TLS handshake, Certificate (11):691{ [1007 bytes data]692* TLSv1.3 (IN), TLS handshake, CERT verify (15):693{ [111 bytes data]694* TLSv1.3 (IN), TLS handshake, Finished (20):695{ [52 bytes data]696* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):697} [1 bytes data]698* TLSv1.3 (OUT), TLS handshake, Finished (20):699} [52 bytes data]700* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey701* ALPN: server accepted h2702* Server certificate:703* subject: CN=test.foo704* start date: Aug 31 09:59:58 2026 GMT705* expire date: Sep 30 09:59:58 2028 GMT706* issuer: CN=minica root ca 4a6e0e707* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384708* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384709* subjectAltName: "test.foo" matches cert's "test.foo"710* OpenSSL verify result: 13711* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)712* closing connection #0713curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)714More details here: https://curl.se/docs/sslcerts.html715716curl failed to verify the legitimacy of the server and therefore could not717establish a secure connection to it. To learn more about this situation and718how to fix it, please visit the webpage mentioned above.719server # [7209382.679410] server nginx[393]: nginx: the configuration file /nix/store/ldafm91pv9vld74irca8avm5fh9l2p2m-nginx.conf syntax is ok720server # [7209382.679762] server nginx[393]: nginx: configuration file /nix/store/ldafm91pv9vld74irca8avm5fh9l2p2m-nginx.conf test is successful721* Host test.foo:443 was resolved.722* IPv6: 2001:db8:1::3723* IPv4: 192.168.1.3724* Trying [2001:db8:1::3]:443...725* ALPN: curl offers h2,http/1.1726} [5 bytes data]727* TLSv1.3 (OUT), TLS handshake, Client hello (1):728} [1552 bytes data]729* SSL Trust Anchors:730* OpenSSL default paths (fallback)731{ [5 bytes data]732* TLSv1.3 (IN), TLS handshake, Server hello (2):733{ [1210 bytes data]734* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):735{ [1 bytes data]736* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):737{ [19 bytes data]738* TLSv1.3 (IN), TLS handshake, Certificate (11):739{ [934 bytes data]740* TLSv1.3 (IN), TLS handshake, CERT verify (15):741{ [79 bytes data]742* TLSv1.3 (IN), TLS handshake, Finished (20):743{ [52 bytes data]744* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):745} [1 bytes data]746* TLSv1.3 (OUT), TLS handshake, Finished (20):747} [52 bytes data]748* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey749* ALPN: server accepted h2750* Server certificate:751* subject: CN=test.foo752* start date: Aug 31 09:59:07 2026 GMT753* expire date: Nov 29 10:00:07 2026 GMT754* issuer: CN=Clan Intermediate CA755* Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256756* Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256757* Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256758* subjectAltName: "test.foo" matches cert's "test.foo"759* OpenSSL verify result: 0760* SSL certificate verified via OpenSSL.761* Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 34062 762 % Total % Received % Xferd Average Speed Time Time Time Current763 Dload Upload Total Spent Left Speed764 0 0 0 0 0 0 0 0 0* using HTTP/2765* [HTTP/2] [1] OPENED stream for https://test.foo/766* [HTTP/2] [1] [:method: GET]767* [HTTP/2] [1] [:scheme: https]768* [HTTP/2] [1] [:authority: test.foo]769* [HTTP/2] [1] [:path: /]770* [HTTP/2] [1] [user-agent: curl/8.21.0]771* [HTTP/2] [1] [accept: */*]772} [5 bytes data]773774775776777778* Request completely sent off779{ [5 bytes data]780* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):781{ [265 bytes data]782* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):783{ [265 bytes data]784785786787788789790791{ [5 bytes data]792100 20 100 20 0 0 822 0 0793* Connection #0 to host test.foo:443 left intact794client: (finished: waiting for success: curl -v https://test.foo, in 3.18 seconds)795client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2796Certificate:797 Data:798 Version: 3 (0x2)799 Serial Number:800 98:69:5e:5f:e6:75:f0:16:f1:07:d5:bb:96:63:66:86801 Signature Algorithm: ecdsa-with-SHA256802 Issuer: CN=Clan Intermediate CA803 Validity804 Not Before: Aug 31 09:59:07 2026 GMT805 Not After : Nov 29 10:00:07 2026 GMT806 Subject: CN=test.foo807 Subject Public Key Info:808 Public Key Algorithm: id-ecPublicKey809 Public-Key: (256 bit)810 pub:811 04:bf:c0:36:c7:80:e0:67:22:ab:42:4e:a3:a4:c1:812 42:07:9c:40:8f:62:1e:cc:6d:44:39:61:35:3c:4d:813 4e:38:0c:ea:8f:b7:ad:e0:e3:1a:b4:4a:14:3b:d1:814 4f:8a:12:e1:3b:4f:be:55:e9:5e:27:c3:e3:05:52:815 8a:b0:24:6a:e0816 ASN1 OID: prime256v1817 NIST CURVE: P-256818 X509v3 extensions:819 X509v3 Key Usage: critical820 Digital Signature821 X509v3 Extended Key Usage: 822 TLS Web Server Authentication, TLS Web Client Authentication823 X509v3 Subject Key Identifier: 824 1B:4C:B7:BF:00:64:F9:CF:39:BE:28:EE:F4:BF:59:EA:91:3B:16:F0825 X509v3 Authority Key Identifier: 826 7E:1C:49:F7:F9:9A:D6:5D:03:A7:DD:5A:FF:9B:F9:A7:3E:F1:62:C7827 X509v3 Subject Alternative Name: 828 DNS:test.foo829 1.3.6.1.4.1.37476.9000.64.1: 830 0......acme..831 Signature Algorithm: ecdsa-with-SHA256832 Signature Value:833 30:46:02:21:00:c5:8a:48:5d:6c:1c:d2:96:a4:e6:96:2f:c5:834 77:8e:38:86:34:96:a9:4b:8e:f7:27:77:80:c8:56:30:ee:85:835 a4:02:21:00:b6:a8:8d:2e:be:02:ea:9f:99:c8:7f:d4:56:70:836 e1:e9:1f:fa:bd:8f:fb:09:97:8b:17:89:94:11:86:c7:21:58837client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2, in 0.04 seconds)838(finished: run the VM test script, in 14.15 seconds)839server # [7209383.617141] server systemd[1]: Reloaded Nginx Web Server.840test script finished in 14.89s841cleanup842kill NspawnMachine (pid 52)843kill NspawnMachine (pid 54)844kill NspawnMachine (pid 57)845Container ca terminated by signal KILL.846Container client terminated by signal KILL.847Container server terminated by signal KILL.848(finished: cleanup, in 0.54 seconds)