nixbot

builds

succeeded container-test-run-certificates checks.aarch64-linux.certificates · build #537 · raw

1Machine state will be reset. To keep it, pass --keep-machine-state2start all VLans3(finished: start all VLans, in 0.00 seconds)45Test will time out and terminate in 3600.0 seconds6run the VM test script7additionally exposed symbols:8 ca, client, server,9 vlan1,10 start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh11start all VMs12ca: systemd-nspawn running (pid 53)13client: systemd-nspawn running (pid 54)14server: systemd-nspawn running (pid 55)15ca: Waiting for journal at /build/vm-state-ca/var/log/journal...16client: Waiting for journal at /build/vm-state-client/var/log/journal...17server: Waiting for journal at /build/vm-state-server/var/log/journal...18(finished: start all VMs, in 0.00 seconds)19nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE20nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.21nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE22nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.23nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE24nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.25Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.26Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.27░ Spawning container client on /build/vm-state-client.28░ Spawning container server on /build/vm-state-server.29Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.30░ Spawning container ca on /build/vm-state-ca.31ca # [7204947.117445] ca systemd-journald[77]: Journal started32ca # [7204947.117499] ca systemd-journald[77]: Runtime Journal (/run/log/journal/26e35ffe7fb442268f534aa2291d3347) is 8M, max 2.5G, 2.4G free.33ca # [7204947.121477] ca systemd[1]: Finished Apply Kernel Variables.34ca # [7204947.131267] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully.35ca # [7204947.146321] ca systemd[1]: Starting Flush Journal to Persistent Storage...36ca # [7204947.147278] ca systemd[1]: Starting Network Name Resolution...37ca # [7204947.147997] ca systemd[1]: Starting Create Static Device Nodes in /dev...38ca # [7204947.158374] ca systemd-journald[77]: Time spent on flushing to /var/log/journal/26e35ffe7fb442268f534aa2291d3347 is 1.214ms for 7 entries.39ca # [7204947.158374] ca systemd-journald[77]: System Journal (/var/log/journal/26e35ffe7fb442268f534aa2291d3347) is 8M, max 4G, 3.9G free.40ca # [7204947.166605] ca systemd[1]: Finished Create Static Device Nodes in /dev.41ca # [7204947.167525] ca systemd[1]: Reached target Preparation for Local File Systems.42ca # [7204947.167772] ca systemd[1]: Reached target Local File Systems.43ca # [7204947.169330] ca systemd[1]: Listening on Boot Loader Control Service Socket.44ca # [7204947.169438] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container45ca # [7204947.170472] ca systemd[1]: Starting Save Transient machine-id to Disk...46ca # [7204947.170539] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys47ca # [7204947.188517] ca systemd[1]: Finished Flush Journal to Persistent Storage.48ca # [7204947.190585] ca systemd[1]: Starting Create System Files and Directories...49ca # [7204947.210349] ca systemd-tmpfiles[129]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted50ca # [7204947.210593] ca systemd-tmpfiles[129]: fchmod() of /var/log/journal failed: Operation not permitted51ca # [7204947.210756] ca systemd-tmpfiles[129]: fchmod() of /var/log/journal/26e35ffe7fb442268f534aa2291d3347 failed: Operation not permitted52ca # [7204947.211003] ca systemd-tmpfiles[129]: fchmod() of /run/log/journal failed: Operation not permitted53ca # [7204947.212738] ca systemd[1]: Finished Create System Files and Directories.54ca # [7204947.214098] ca systemd[1]: Starting Rebuild Journal Catalog...55ca # [7204947.214971] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP...56ca # [7204947.230964] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP.57ca # [7204947.235450] ca systemd[1]: Finished Rebuild Journal Catalog.58ca # [7204947.236836] ca systemd[1]: Starting Update is Completed...59server # [7204947.107630] server systemd-journald[69]: Journal started60server # [7204947.107679] server systemd-journald[69]: Runtime Journal (/run/log/journal/06e7d046303c4aeeb7494425408d899a) is 8M, max 2.5G, 2.4G free.61server # [7204947.109112] server systemd[1]: Listening on Journal Log Access Socket.62server # [7204947.109590] server systemd[1]: Finished Apply Kernel Variables.63server # [7204947.118247] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully.64server # [7204947.128370] server systemd[1]: Starting Flush Journal to Persistent Storage...65server # [7204947.129245] server systemd[1]: Starting Network Name Resolution...66server # [7204947.129938] server systemd[1]: Starting Create Static Device Nodes in /dev...67server # [7204947.139527] server systemd-journald[69]: Time spent on flushing to /var/log/journal/06e7d046303c4aeeb7494425408d899a is 1.383ms for 8 entries.68server # [7204947.139527] server systemd-journald[69]: System Journal (/var/log/journal/06e7d046303c4aeeb7494425408d899a) is 8M, max 4G, 3.9G free.69server # [7204947.146870] server systemd[1]: Finished Create Static Device Nodes in /dev.70server # [7204947.147832] server systemd[1]: Reached target Preparation for Local File Systems.71server # [7204947.148017] server systemd[1]: Reached target Local File Systems.72server # [7204947.149651] server systemd[1]: Listening on Boot Loader Control Service Socket.73server # [7204947.149781] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container74server # [7204947.150887] server systemd[1]: Starting Save Transient machine-id to Disk...75server # [7204947.150930] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys76server # [7204947.153605] server systemd[1]: Finished Flush Journal to Persistent Storage.77server # [7204947.154914] server systemd[1]: Starting Create System Files and Directories...78server # [7204947.175111] server systemd-tmpfiles[109]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted79server # [7204947.175350] server systemd-tmpfiles[109]: fchmod() of /var/log/journal failed: Operation not permitted80server # [7204947.175514] server systemd-tmpfiles[109]: fchmod() of /var/log/journal/06e7d046303c4aeeb7494425408d899a failed: Operation not permitted81server # [7204947.175788] server systemd-tmpfiles[109]: fchmod() of /run/log/journal failed: Operation not permitted82server # [7204947.178437] server systemd[1]: Finished Create System Files and Directories.83server # [7204947.180367] server systemd[1]: Starting Rebuild Journal Catalog...84server # [7204947.181388] server systemd[1]: Starting Record System Boot/Shutdown in UTMP...85server # [7204947.195398] server systemd[1]: Finished Record System Boot/Shutdown in UTMP.86server # [7204947.204893] server systemd[1]: Finished Rebuild Journal Catalog.87server # [7204947.206181] server systemd[1]: Starting Update is Completed...88server # [7204947.219060] server systemd[1]: Finished Update is Completed.89client # [7204947.108565] client systemd-journald[69]: Journal started90client # [7204947.108642] client systemd-journald[69]: Runtime Journal (/run/log/journal/7d597fd5644f4ce5aa8e8e77a0bbb5b6) is 8M, max 2.5G, 2.4G free.91client # [7204947.109907] client systemd[1]: Finished Apply Kernel Variables.92client # [7204947.120797] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully.93client # [7204947.134668] client systemd[1]: Starting Flush Journal to Persistent Storage...94client # [7204947.136145] client systemd[1]: Starting Network Name Resolution...95client # [7204947.137145] client systemd[1]: Starting Create Static Device Nodes in /dev...96client # [7204947.146991] client systemd-journald[69]: Time spent on flushing to /var/log/journal/7d597fd5644f4ce5aa8e8e77a0bbb5b6 is 1.239ms for 7 entries.97client # [7204947.146991] client systemd-journald[69]: System Journal (/var/log/journal/7d597fd5644f4ce5aa8e8e77a0bbb5b6) is 8M, max 4G, 3.9G free.98client # [7204947.156128] client systemd[1]: Finished Create Static Device Nodes in /dev.99client # [7204947.157191] client systemd[1]: Reached target Preparation for Local File Systems.100client # [7204947.157436] client systemd[1]: Reached target Local File Systems.101client # [7204947.159038] client systemd[1]: Listening on Boot Loader Control Service Socket.102client # [7204947.159155] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container103client # [7204947.160301] client systemd[1]: Starting Save Transient machine-id to Disk...104client # [7204947.160379] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys105client # [7204947.169759] client systemd[1]: Finished Flush Journal to Persistent Storage.106client # [7204947.171929] client systemd[1]: Starting Create System Files and Directories...107client # [7204947.188836] client systemd-tmpfiles[117]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted108client # [7204947.189025] client systemd-tmpfiles[117]: fchmod() of /var/log/journal failed: Operation not permitted109client # [7204947.189160] client systemd-tmpfiles[117]: fchmod() of /var/log/journal/7d597fd5644f4ce5aa8e8e77a0bbb5b6 failed: Operation not permitted110client # [7204947.189360] client systemd-tmpfiles[117]: fchmod() of /run/log/journal failed: Operation not permitted111client # [7204947.191251] client systemd[1]: Finished Create System Files and Directories.112client # [7204947.192678] client systemd[1]: Starting Rebuild Journal Catalog...113client # [7204947.193450] client systemd[1]: Starting Record System Boot/Shutdown in UTMP...114client # [7204947.207382] client systemd[1]: Finished Record System Boot/Shutdown in UTMP.115client # [7204947.215745] client systemd[1]: Finished Rebuild Journal Catalog.116client # [7204947.217341] client systemd[1]: Starting Update is Completed...117client # [7204947.230072] client systemd[1]: Finished Update is Completed.118ca # [7204947.247967] ca systemd[1]: Finished Update is Completed.119ca # [7204947.273860] ca systemd[1]: Finished Save Transient machine-id to Disk.120ca # [7204947.352233] ca systemd[1]: Finished Firewall.121ca # [7204947.352413] ca systemd[1]: Reached target Preparation for Network.122ca # [7204947.352652] ca systemd[1]: Listening on Network Management Resolve Hook Socket.123ca # [7204947.353789] ca systemd[1]: Starting Network Management...124client # [7204947.271784] client systemd[1]: Finished Save Transient machine-id to Disk.125client # [7204947.304414] client systemd[1]: Finished Firewall.126client # [7204947.304623] client systemd[1]: Reached target Preparation for Network.127client # [7204947.304854] client systemd[1]: Listening on Network Management Resolve Hook Socket.128client # [7204947.306217] client systemd[1]: Starting Network Management...129server # [7204947.274697] server systemd[1]: Finished Save Transient machine-id to Disk.130server # [7204947.352236] server systemd[1]: Finished Firewall.131server # [7204947.352422] server systemd[1]: Reached target Preparation for Network.132server # [7204947.352660] server systemd[1]: Listening on Network Management Resolve Hook Socket.133server # [7204947.353897] server systemd[1]: Starting Network Management...134server # [7204947.754487] server systemd-networkd[187]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted135server # [7204947.754584] server systemd-networkd[187]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted136server # [7204947.761741] server systemd-networkd[187]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.137server # [7204947.761903] server systemd-networkd[187]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.138server # [7204947.762074] server systemd-networkd[187]: lo: Link UP139server # [7204947.762080] server systemd-networkd[187]: lo: Gained carrier140server # [7204947.762296] server systemd-networkd[187]: eth1: Configuring with /etc/systemd/network/40-eth1.network.141server # [7204947.762682] server systemd[1]: Started Network Management.142server # [7204947.762779] server systemd-networkd[187]: eth1: Link UP143server # [7204947.763087] server systemd-networkd[187]: eth1: Gained carrier144server # [7204947.763910] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd...145server # [7204947.822052] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd.146server # [7204947.862008] server systemd-resolved[92]: Positive Trust Anchors:147server # [7204947.862020] server systemd-resolved[92]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d148server # [7204947.862023] server systemd-resolved[92]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16149server # [7204947.862058] server systemd-resolved[92]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test150server # [7204947.884887] server systemd-resolved[92]: Using system hostname 'server'.151server # [7204947.886176] server systemd[1]: Started Network Name Resolution.152server # [7204947.886273] server systemd[1]: Reached target Network.153server # [7204947.886348] server systemd[1]: Reached target Network is Online.154server # [7204947.886403] server systemd[1]: Reached target System Initialization.155server # [7204947.886663] server systemd[1]: Started Renew ACME Certificate for test.foo.156server # [7204947.886697] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container157server # [7204947.886725] server systemd[1]: Started Daily Cleanup of Temporary Directories.158server # [7204947.886746] server systemd[1]: Reached target Timer Units.159server # [7204947.886888] server systemd[1]: Listening on D-Bus System Message Bus Socket.160server # [7204947.887094] server systemd[1]: Listening on Nix Daemon Socket.161server # [7204947.887245] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.162server # [7204947.887271] server systemd[1]: Reached target Socket Units.163server # [7204947.887315] server systemd[1]: Reached target Basic System.164server # [7204947.888942] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure...165server # [7204947.889835] server systemd[1]: Starting Import lastlog data into lastlog2 database...166server # [7204947.889880] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem167server # [7204947.890967] server systemd[1]: Starting Name Service Cache Daemon (nsncd)...168server # [7204947.892368] server systemd[1]: Starting D-Bus System Message Bus...169server # [7204947.945891] server systemd[1]: Finished Import lastlog data into lastlog2 database.170ca # [7204947.765589] ca systemd-networkd[195]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted171ca # [7204947.765676] ca systemd-networkd[195]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted172ca # [7204947.772669] ca systemd-networkd[195]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.173ca # [7204947.772892] ca systemd-networkd[195]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.174ca # [7204947.773036] ca systemd-networkd[195]: lo: Link UP175ca # [7204947.773040] ca systemd-networkd[195]: lo: Gained carrier176ca # [7204947.773226] ca systemd-networkd[195]: eth1: Configuring with /etc/systemd/network/40-eth1.network.177ca # [7204947.773580] ca systemd[1]: Started Network Management.178ca # [7204947.800611] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd...179ca # [7204947.800640] ca systemd-networkd[195]: eth1: Link UP180ca # [7204947.800954] ca systemd-networkd[195]: eth1: Gained carrier181ca # [7204947.846123] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd.182ca # [7204947.862467] ca systemd-resolved[106]: Positive Trust Anchors:183ca # [7204947.862477] ca systemd-resolved[106]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d184ca # [7204947.862481] ca systemd-resolved[106]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16185ca # [7204947.862515] ca systemd-resolved[106]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test186ca # [7204947.884234] ca systemd-resolved[106]: Using system hostname 'ca'.187ca # [7204947.885615] ca systemd[1]: Started Network Name Resolution.188ca # [7204947.885692] ca systemd[1]: Reached target Network.189ca # [7204947.885751] ca systemd[1]: Reached target Network is Online.190ca # [7204947.885791] ca systemd[1]: Reached target System Initialization.191ca # [7204947.885990] ca systemd[1]: Started Renew ACME Certificate for ca.foo.192ca # [7204947.886018] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container193ca # [7204947.886038] ca systemd[1]: Started Daily Cleanup of Temporary Directories.194ca # [7204947.886053] ca systemd[1]: Reached target Timer Units.195ca # [7204947.886161] ca systemd[1]: Listening on D-Bus System Message Bus Socket.196ca # [7204947.886265] ca systemd[1]: Listening on Nix Daemon Socket.197ca # [7204947.886371] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.198ca # [7204947.886392] ca systemd[1]: Reached target Socket Units.199ca # [7204947.886422] ca systemd[1]: Reached target Basic System.200ca # [7204947.887721] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure...201ca # [7204947.888721] ca systemd[1]: Starting Import lastlog data into lastlog2 database...202ca # [7204947.888759] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem203ca # [7204947.889514] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)...204ca # [7204947.890415] ca systemd[1]: Starting step-ca service...205ca # [7204947.891636] ca systemd[1]: Starting D-Bus System Message Bus...206ca # [7204947.945889] ca systemd[1]: Finished Import lastlog data into lastlog2 database.207ca # [7204948.036444] ca acme-setup-privileged[200]: + set -euo pipefail208ca # [7204948.036444] ca acme-setup-privileged[200]: + cd /var/lib/acme209ca # [7204948.036444] ca acme-setup-privileged[200]: + chmod -R u=rwX,g=,o= .lego/accounts210client # [7204947.765427] client systemd-networkd[183]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted211client # [7204947.765519] client systemd-networkd[183]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted212client # [7204947.772499] client systemd-networkd[183]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.213client # [7204947.772736] client systemd-networkd[183]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.214client # [7204947.772893] client systemd-networkd[183]: lo: Link UP215client # [7204947.772897] client systemd-networkd[183]: lo: Gained carrier216client # [7204947.773167] client systemd-networkd[183]: eth1: Configuring with /etc/systemd/network/40-eth1.network.217client # [7204947.773522] client systemd[1]: Started Network Management.218client # [7204947.800311] client systemd-networkd[183]: eth1: Link UP219client # [7204947.800686] client systemd-networkd[183]: eth1: Gained carrier220client # [7204947.800978] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd...221client # [7204947.858341] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd.222client # [7204947.865875] client systemd-resolved[97]: Positive Trust Anchors:223client # [7204947.865887] client systemd-resolved[97]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d224client # [7204947.865889] client systemd-resolved[97]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16225client # [7204947.865928] client systemd-resolved[97]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test226client # [7204947.887581] client systemd-resolved[97]: Using system hostname 'client'.227client # [7204947.888957] client systemd[1]: Started Network Name Resolution.228client # [7204947.889088] client systemd[1]: Reached target Network.229client # [7204947.889196] client systemd[1]: Reached target System Initialization.230client # [7204947.889304] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container231client # [7204947.889364] client systemd[1]: Started Daily Cleanup of Temporary Directories.232client # [7204947.889404] client systemd[1]: Reached target Timer Units.233client # [7204947.889620] client systemd[1]: Listening on D-Bus System Message Bus Socket.234client # [7204947.889843] client systemd[1]: Listening on Nix Daemon Socket.235client # [7204947.890058] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.236client # [7204947.890104] client systemd[1]: Reached target Socket Units.237client # [7204947.890180] client systemd[1]: Reached target Basic System.238client # [7204947.891954] client systemd[1]: Starting Import lastlog data into lastlog2 database...239client # [7204947.928522] client systemd[1]: Starting Name Service Cache Daemon (nsncd)...240client # [7204947.930904] client systemd[1]: Starting D-Bus System Message Bus...241client # [7204947.943719] client systemd[1]: Finished Import lastlog data into lastlog2 database.242ca # [7204948.038329] ca acme-setup-privileged[200]: + chown -R acme .lego/accounts243ca # [7204948.039838] ca acme-setup-privileged[200]: + for fixpath in ca.foo .lego/ca.foo244ca # [7204948.039894] ca acme-setup-privileged[200]: + '[' -d ca.foo ']'245ca # [7204948.039894] ca acme-setup-privileged[200]: + for fixpath in ca.foo .lego/ca.foo246ca # [7204948.039894] ca acme-setup-privileged[200]: + '[' -d .lego/ca.foo ']'247ca # [7204948.098533] ca nsncd[202]: Aug 31 08:46:14.151 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"248ca # [7204948.120827] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully.249ca # [7204948.121771] ca systemd[1]: Started Name Service Cache Daemon (nsncd).250ca # [7204948.121839] ca systemd[1]: Reached target Host and Network Name Lookups.251ca # [7204948.121916] ca systemd[1]: Reached target User and Group Name Lookups.252ca # [7204948.123416] ca systemd[1]: Starting User Login Management...253ca # [7204948.124290] ca systemd[1]: Starting Permit User Sessions...254ca # [7204948.134276] ca systemd[1]: Finished Permit User Sessions.255ca # [7204948.135853] ca systemd[1]: Started Console Getty.256ca # [7204948.135924] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0257ca # [7204948.135959] ca systemd[1]: Reached target Login Prompts.258client # [7204948.085718] client nsncd[189]: Aug 31 08:46:14.138 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"259client # [7204948.103543] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully.260client # [7204948.104367] client systemd[1]: Started Name Service Cache Daemon (nsncd).261client # [7204948.104418] client systemd[1]: Reached target Host and Network Name Lookups.262client # [7204948.104540] client systemd[1]: Reached target User and Group Name Lookups.263client # [7204948.105873] client systemd[1]: Starting User Login Management...264client # [7204948.106741] client systemd[1]: Starting Permit User Sessions...265client # [7204948.118104] client systemd[1]: Finished Permit User Sessions.266client # [7204948.119369] client systemd[1]: Started Console Getty.267client # [7204948.119419] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0268client # [7204948.119442] client systemd[1]: Reached target Login Prompts.269client # [7204948.234115] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'...270client # [7204948.235664] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync'271server # [7204948.040814] server acme-setup-privileged[192]: + set -euo pipefail272server # [7204948.041258] server acme-setup-privileged[192]: + cd /var/lib/acme273server # [7204948.041258] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts274client # [7204948.235664] client dbus-broker-launch[190]: Invalid user-name in /nix/store/ssk8893k9jd7id6pd9yzim0h6prlbdma-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"275client # [7204948.236132] client systemd[1]: Started D-Bus System Message Bus.276server # [7204948.042549] server acme-setup-privileged[192]: + chown -R acme .lego/accounts277server # [7204948.044323] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo278server # [7204948.044361] server acme-setup-privileged[192]: + '[' -d test.foo ']'279server # [7204948.044361] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo280client # [7204948.245057] client dbus-broker-launch[190]: Ready281server # [7204948.044361] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']'282server # [7204948.090287] server nsncd[194]: Aug 31 08:46:14.143 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"283server # [7204948.122762] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully.284server # [7204948.124236] server systemd[1]: Started Name Service Cache Daemon (nsncd).285server # [7204948.124425] server systemd[1]: Reached target Host and Network Name Lookups.286server # [7204948.124531] server systemd[1]: Reached target User and Group Name Lookups.287server # [7204948.126656] server systemd[1]: Starting User Login Management...288server # [7204948.127834] server systemd[1]: Starting Permit User Sessions...289server # [7204948.137888] server systemd[1]: Finished Permit User Sessions.290server # [7204948.139554] server systemd[1]: Started Console Getty.291server # [7204948.139637] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0292server # [7204948.139674] server systemd[1]: Reached target Login Prompts.293server # [7204948.282154] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'...294server # [7204948.282949] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync'295server # [7204948.282949] server dbus-broker-launch[195]: Invalid user-name in /nix/store/aszr859gd9lnmlsj2dls188ya32g6xf8-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"296server # [7204948.283327] server systemd[1]: Started D-Bus System Message Bus.297server # [7204948.290323] server dbus-broker-launch[195]: Ready298ca # [7204948.319570] ca dbus-broker-launch[204]: Looking up NSS user entry for 'systemd-timesync'...299ca # [7204948.320666] ca dbus-broker-launch[204]: NSS returned no entry for 'systemd-timesync'300ca # [7204948.320666] ca dbus-broker-launch[204]: Invalid user-name in /nix/store/nrvy3kisslkv7qydv3v2ib6szfdky5q3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"301ca # [7204948.321065] ca systemd[1]: Started D-Bus System Message Bus.302ca # [7204948.329063] ca dbus-broker-launch[204]: Ready303ca # [7204948.664792] ca systemd-logind[234]: New seat seat0.304ca # [7204948.665096] ca systemd[1]: Started User Login Management.305ca # [7204948.679709] ca acme-setup-start[218]: + set -euo pipefail306ca # [7204948.679709] ca acme-setup-start[218]: + test -e ca/key.pem307ca # [7204948.680335] ca acme-setup-start[218]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local308ca # [7204948.681011] ca systemd[1]: Starting linger-users.service...309ca # [7204948.693775] ca systemd[1]: linger-users.service: Deactivated successfully.310ca # [7204948.693836] ca systemd[1]: Finished linger-users.service.311ca # [7204948.701528] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure.312ca # [7204948.703280] ca systemd[1]: Starting Ensure certificate for ca.foo...313ca # [7204948.885448] ca step-ca[203]: badger 2026/08/31 08:46:14 INFO: All 0 tables opened in 0s314ca # [7204948.890623] ca step-ca[203]: 2026/08/31 08:46:14 Building new tls configuration using step-ca x509 Signer Interface315ca # [7204948.897477] ca step-ca[203]: 2026/08/31 08:46:14 Starting Smallstep CA/0.30.2 (linux/arm64)316ca # [7204948.897477] ca step-ca[203]: 2026/08/31 08:46:14 Documentation: https://u.step.sm/docs/ca317ca # [7204948.897477] ca step-ca[203]: 2026/08/31 08:46:14 Community Discord: https://u.step.sm/discord318ca # [7204948.897477] ca step-ca[203]: 2026/08/31 08:46:14 Config file: /etc/smallstep/ca.json319ca # [7204948.897477] ca step-ca[203]: 2026/08/31 08:46:14 The primary server URL is https://ca.foo:1443320ca # [7204948.897742] ca step-ca[203]: 2026/08/31 08:46:14 Root certificates are available at https://ca.foo:1443/roots.pem321ca # [7204948.897742] ca step-ca[203]: 2026/08/31 08:46:14 X.509 Root Fingerprint: d8313f02428bf1dbd1c3ac697d9dbdb634b8b2133fa80e84a29326a25d92a16f322ca # [7204948.898176] ca systemd[1]: Started step-ca service.323ca # [7204948.898768] ca step-ca[203]: 2026/08/31 08:46:14 Serving HTTPS on 0.0.0.0:1443 ...324client # [7204948.633071] client systemd-logind[205]: New seat seat0.325client # [7204948.633305] client systemd[1]: Started User Login Management.326client # [7204948.635428] client systemd[1]: Starting linger-users.service...327client # [7204948.690132] client systemd[1]: linger-users.service: Deactivated successfully.328client # [7204948.690529] client systemd[1]: Finished linger-users.service.329client # [7204948.691732] client systemd[1]: Reached target Multi-User System.330server # [7204948.641997] server systemd-logind[224]: New seat seat0.331client # [7204948.692375] client systemd[1]: Startup finished in 2.002s.332server # [7204948.642225] server systemd[1]: Started User Login Management.333server # [7204948.680635] server systemd[1]: Starting linger-users.service...334server # [7204948.692971] server systemd[1]: linger-users.service: Deactivated successfully.335server # [7204948.693181] server systemd[1]: Finished linger-users.service.336server # [7204948.704897] server acme-setup-start[208]: + set -euo pipefail337server # [7204948.705153] server acme-setup-start[208]: + test -e ca/key.pem338server # [7204948.705153] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local339server # [7204948.725798] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure.340server # [7204948.728390] server systemd[1]: Starting Ensure certificate for test.foo...341server # [7204948.800207] server systemd-networkd[187]: eth1: Gained IPv6LL342ca: must succeed: systemctl restart acme-order-renew-ca.foo.service 343ca # [7204949.156133] ca systemd-networkd[195]: eth1: Gained IPv6LL344ca # [7204949.207114] ca acme-ca.foo-start[254]: Waiting to acquire lock in /run/acme/345ca # [7204949.210476] ca acme-ca.foo-start[254]: + '[' -e out/acme-success ']'346ca # [7204949.210476] ca acme-ca.foo-start[254]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses=347ca # [7204949.226412] ca acme-ca.foo-start[290]: + cd ca.foo348ca # [7204949.227016] ca acme-ca.foo-start[290]: + cp -vp cert.pem ../out/cert.pem349ca # [7204949.228423] ca acme-ca.foo-start[291]: 'cert.pem' -> '../out/cert.pem'350ca # [7204949.228795] ca acme-ca.foo-start[290]: + cp -vp key.pem ../out/key.pem351ca # [7204949.230030] ca acme-ca.foo-start[290]: 'key.pem' -> '../out/key.pem'352ca # [7204949.230265] ca acme-ca.foo-start[254]: + cat out/cert.pem ca/cert.pem353ca # [7204949.231983] ca acme-ca.foo-start[254]: + cp ca/cert.pem out/chain.pem354ca # [7204949.233855] ca acme-ca.foo-start[254]: + cat out/key.pem out/fullchain.pem355ca # [7204949.235365] ca acme-ca.foo-start[254]: + for fixpath in out certificates356ca # [7204949.235365] ca acme-ca.foo-start[254]: + '[' -d out ']'357ca # [7204949.235365] ca acme-ca.foo-start[254]: + chmod -R u=rwX,g=rX,o= out358ca # [7204949.237343] ca acme-ca.foo-start[254]: + chown -R acme:nginx out359ca # [7204949.241293] ca acme-ca.foo-start[254]: + for fixpath in out certificates360ca # [7204949.241293] ca acme-ca.foo-start[254]: + '[' -d certificates ']'361ca # [7204949.245882] ca systemd[1]: Finished Ensure certificate for ca.foo.362ca # [7204949.249924] ca systemd[1]: Starting Nginx Web Server...363server # [7204949.214703] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/364server # [7204949.218166] server acme-test.foo-start[245]: + '[' -e out/acme-success ']'365server # [7204949.218166] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=366server # [7204949.233814] server acme-test.foo-start[254]: + cd test.foo367server # [7204949.234426] server acme-test.foo-start[254]: + cp -vp cert.pem ../out/cert.pem368server # [7204949.235433] server acme-test.foo-start[255]: 'cert.pem' -> '../out/cert.pem'369server # [7204949.235738] server acme-test.foo-start[254]: + cp -vp key.pem ../out/key.pem370server # [7204949.237332] server acme-test.foo-start[254]: 'key.pem' -> '../out/key.pem'371server # [7204949.237621] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem372server # [7204949.239455] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem373server # [7204949.241340] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem374server # [7204949.243294] server acme-test.foo-start[245]: + for fixpath in out certificates375server # [7204949.243344] server acme-test.foo-start[245]: + '[' -d out ']'376server # [7204949.243344] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out377server # [7204949.245143] server acme-test.foo-start[245]: + chown -R acme:nginx out378server # [7204949.248738] server acme-test.foo-start[245]: + for fixpath in out certificates379server # [7204949.248785] server acme-test.foo-start[245]: + '[' -d certificates ']'380server # [7204949.252386] server systemd[1]: Finished Ensure certificate for test.foo.381server # [7204949.254786] server systemd[1]: Starting Nginx Web Server...382client # [7204949.444184] client systemd-networkd[183]: eth1: Gained IPv6LL383server # [7204949.826407] server nginx-pre-start[266]: nginx: the configuration file /nix/store/jz7kmd1pqz9d3z4szhmwj70infw1zqg3-nginx.conf syntax is ok384server # [7204949.827045] server nginx-pre-start[266]: nginx: configuration file /nix/store/jz7kmd1pqz9d3z4szhmwj70infw1zqg3-nginx.conf test is successful385server # [7204949.834346] server systemd[1]: Started Nginx Web Server.386server # [7204949.835093] server systemd[1]: Reached target Multi-User System.387server # [7204949.837436] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...388ca # [7204949.897625] ca nginx-pre-start[302]: nginx: the configuration file /nix/store/qvq6qxlf6qym8p85q6ss08zqvgy8h812-nginx.conf syntax is ok389ca # [7204949.898244] ca nginx-pre-start[302]: nginx: configuration file /nix/store/qvq6qxlf6qym8p85q6ss08zqvgy8h812-nginx.conf test is successful390ca # [7204949.903238] ca systemd[1]: Started Nginx Web Server.391ca # [7204949.903986] ca systemd[1]: Reached target Multi-User System.392ca # [7204949.906186] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...393server # [7204950.414496] server acme-order-renew-test.foo-start[269]: Waiting to acquire lock in /run/acme/394server # [7204950.417835] server acme-order-renew-test.foo-start[269]: + set -euo pipefail395server # [7204950.417921] server acme-order-renew-test.foo-start[269]: + echo ad12aa6741ce4bd2c108396server # [7204950.418483] server acme-order-renew-test.foo-start[269]: + cmp -s domainhash.txt certificates/domainhash.txt397server # [7204950.419107] server acme-order-renew-test.foo-start[269]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run398server # [7204950.433992] server acme-order-renew-test.foo-start[280]: 2026/08/31 08:46:16 No key found for account none@none.tld. Generating a P256 key.399server # [7204950.434566] server acme-order-renew-test.foo-start[280]: 2026/08/31 08:46:16 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key400ca # [7204950.615624] ca acme-order-renew-ca.foo-start[305]: Waiting to acquire lock in /run/acme/401ca # [7204950.619065] ca acme-order-renew-ca.foo-start[305]: + set -euo pipefail402ca # [7204950.619140] ca acme-order-renew-ca.foo-start[305]: + echo 88dc4fc401a6091a1bd9403ca # [7204950.619256] ca acme-order-renew-ca.foo-start[305]: + cmp -s domainhash.txt certificates/domainhash.txt404ca # [7204950.620429] ca acme-order-renew-ca.foo-start[305]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run405ca # [7204950.639006] ca acme-order-renew-ca.foo-start[316]: 2026/08/31 08:46:16 No key found for account none@none.tld. Generating a P256 key.406ca # [7204950.639353] ca acme-order-renew-ca.foo-start[316]: 2026/08/31 08:46:16 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key407ca # [7204950.671885] ca step-ca[203]: time="2026-08-31T08:46:16Z" level=info duration="194.043µs" duration-ns=194043 fields.time="2026-08-31T08:46:16Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=9d1a4c66-3f78-4b3a-b863-10ce714dcd5b response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=408ca # [7204950.672277] ca acme-order-renew-ca.foo-start[316]: 2026/08/31 08:46:16 [INFO] acme: Registering account for none@none.tld409ca # [7204950.679378] ca step-ca[203]: time="2026-08-31T08:46:16Z" level=info duration=6.913617ms duration-ns=6913617 fields.time="2026-08-31T08:46:16Z" method=HEAD name=ca nonce=TDZjaEVDRWVEdGZwQkJXekxFWHhScmFFQk1ieUF6WlE path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=a8de396f-209c-4133-af46-721cf527e005 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=410ca # [7204950.683022] ca step-ca[203]: time="2026-08-31T08:46:16Z" level=info duration=2.640557ms duration-ns=2640557 fields.time="2026-08-31T08:46:16Z" method=POST name=ca nonce=TXlCbUhWTFBSdEx0NjV4RWtWMTFZNVZiWmVaZExtRUE path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=b730ada2-5074-4a0d-9ef2-e735f9312a68 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/39qO4XED32CWgnVVVz3MtQHwtndM3We5/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=411ca # [7204950.683359] ca acme-order-renew-ca.foo-start[316]: !!!! HEADS UP !!!!412ca # [7204950.683359] ca acme-order-renew-ca.foo-start[316]: Your account credentials have been saved in your413ca # [7204950.683359] ca acme-order-renew-ca.foo-start[316]: configuration directory at "accounts".414ca # [7204950.683359] ca acme-order-renew-ca.foo-start[316]: You should make a secure backup of this folder now. This415ca # [7204950.683359] ca acme-order-renew-ca.foo-start[316]: configuration directory will also contain private keys416ca # [7204950.683359] ca acme-order-renew-ca.foo-start[316]: generated by lego and certificates obtained from the ACME417ca # [7204950.683359] ca acme-order-renew-ca.foo-start[316]: server. Making regular backups of this folder is ideal.418ca # [7204950.683479] ca acme-order-renew-ca.foo-start[316]: 2026/08/31 08:46:16 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate419ca # [7204950.688202] ca step-ca[203]: time="2026-08-31T08:46:16Z" level=info duration=4.247379ms duration-ns=4247379 fields.time="2026-08-31T08:46:16Z" method=POST name=ca nonce=cnJXRlV5dDdKUGpFTFdpM3VvVzlWN1FJZFN1aXVJRUo path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=f07fe413-2be9-47be-b093-62b94dff306a response="{\"id\":\"FF6r2INWaEpvhNXpaRvtEJ0RsHK83RZh\",\"status\":\"pending\",\"expires\":\"2026-09-01T08:46:16Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-31T08:45:16Z\",\"notAfter\":\"2026-11-29T08:46:16Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/bizuCP5dYpa7DsLoxji9PplznBIOy6eh\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/FF6r2INWaEpvhNXpaRvtEJ0RsHK83RZh/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=420ca # [7204950.749312] ca step-ca[203]: time="2026-08-31T08:46:16Z" level=info duration=4.180018ms duration-ns=4180018 fields.time="2026-08-31T08:46:16Z" method=POST name=ca nonce=eGZGc2xPcHdvZ0J2cDRiRFV2QzVMcjdaMlRjcThBSVU path=/acme/acme/authz/bizuCP5dYpa7DsLoxji9PplznBIOy6eh protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=d4a27fda-35bf-47b9-bcca-2d78b734239c response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"3Xorfdt7pKmLElAKPrertWkBgQ4gu7er\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/bizuCP5dYpa7DsLoxji9PplznBIOy6eh/EiqmLTtmlKtomeUVo4bxZO9KLNgBkKqF\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"3Xorfdt7pKmLElAKPrertWkBgQ4gu7er\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/bizuCP5dYpa7DsLoxji9PplznBIOy6eh/WiAeHTIEOrMAXGxQ0Jom4Ooy20W90dlL\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"3Xorfdt7pKmLElAKPrertWkBgQ4gu7er\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/bizuCP5dYpa7DsLoxji9PplznBIOy6eh/rFpKTz0VV2FvTur7TZGa3huks8XxHA2J\"}],\"wildcard\":false,\"expires\":\"2026-09-01T08:46:16Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=421ca # [7204950.749691] ca acme-order-renew-ca.foo-start[316]: 2026/08/31 08:46:16 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/bizuCP5dYpa7DsLoxji9PplznBIOy6eh422ca # [7204950.749691] ca acme-order-renew-ca.foo-start[316]: 2026/08/31 08:46:16 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01423ca # [7204950.749691] ca acme-order-renew-ca.foo-start[316]: 2026/08/31 08:46:16 [INFO] [ca.foo] acme: use http-01 solver424ca # [7204950.749691] ca acme-order-renew-ca.foo-start[316]: 2026/08/31 08:46:16 [INFO] [ca.foo] acme: Trying to solve HTTP-01425ca # [7204950.756388] ca step-ca[203]: time="2026-08-31T08:46:16Z" level=info duration=5.945923ms duration-ns=5945923 fields.time="2026-08-31T08:46:16Z" method=POST name=ca nonce=UDd1WWpIOWYwNzdqczdmN3lJUmhuYmc2MThlSTl3YTY path=/acme/acme/challenge/bizuCP5dYpa7DsLoxji9PplznBIOy6eh/WiAeHTIEOrMAXGxQ0Jom4Ooy20W90dlL protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=9e4ffbf9-25fd-442e-85bd-33efa557a5f0 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"3Xorfdt7pKmLElAKPrertWkBgQ4gu7er\",\"validated\":\"2026-08-31T08:46:16Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/bizuCP5dYpa7DsLoxji9PplznBIOy6eh/WiAeHTIEOrMAXGxQ0Jom4Ooy20W90dlL\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=426ca # [7204950.756968] ca acme-order-renew-ca.foo-start[316]: 2026/08/31 08:46:16 [INFO] [ca.foo] The server validated our request427ca # [7204950.757033] ca acme-order-renew-ca.foo-start[316]: 2026/08/31 08:46:16 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates428ca # [7204950.768856] ca step-ca[203]: time="2026-08-31T08:46:16Z" level=info duration=10.07198ms duration-ns=10071980 fields.time="2026-08-31T08:46:16Z" method=POST name=ca nonce=RDFpT0JaNFdvUGcyTTQ2VXRzTHpVOHdYSVBoWFR6Rjk path=/acme/acme/order/FF6r2INWaEpvhNXpaRvtEJ0RsHK83RZh/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=87ee5daa-ad69-4ea4-97f4-eb68f5822fe4 response="{\"id\":\"FF6r2INWaEpvhNXpaRvtEJ0RsHK83RZh\",\"status\":\"valid\",\"expires\":\"2026-09-01T08:46:16Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-31T08:45:16Z\",\"notAfter\":\"2026-11-29T08:46:16Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/bizuCP5dYpa7DsLoxji9PplznBIOy6eh\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/FF6r2INWaEpvhNXpaRvtEJ0RsHK83RZh/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/8xm5LQq4cOm5Y3pemGFapMTqXxN87gCX\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=429ca # [7204950.772144] ca step-ca[203]: time="2026-08-31T08:46:16Z" level=info certificate="MIIB0jCCAXmgAwIBAgIQARE9axcqmCKhVzr/WPWfTzAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MzEwODQ1MTZaFw0yNjExMjkwODQ2MTZaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABDJPX2+5HPoERgEdfUj8uw/YeSNHmVuxxsERRrcd5jRJu1bzsN8MBcCnBf5IvDm4NNU51OBJcUmcT3Kf/y+QCiCjgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUcTRvrq972T8s3bK3IMzuH1swgUYwHwYDVR0jBBgwFoAUfhxJ9/ma1l0Dp91a/5v5pz7xYscwEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNHADBEAiAREIxyrVSEIP/78yn88zOGLL+bfo+qEWFE8DOEKpLrywIgMk7Z1SB0WE9wzImClz2EchYl90tzXTlxXTn0YnDTFis=" duration=2.044629ms duration-ns=2044629 fields.time="2026-08-31T08:46:16Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=SmZmZWN4UHdpYkJJOENaakxDNmRNWXNMNzRDeUlhNHQ path=/acme/acme/certificate/8xm5LQq4cOm5Y3pemGFapMTqXxN87gCX protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=4cb40225-26b8-4a39-8950-460e587f1eaf sans="map[dns:[ca.foo]]" serial=1418742753948868269604080319076867919 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-31T08:45:16Z" valid-to="2026-11-29T08:46:16Z"430ca # [7204950.772418] ca acme-order-renew-ca.foo-start[316]: 2026/08/31 08:46:16 [INFO] [ca.foo] Server responded with a certificate.431ca # [7204950.777670] ca acme-order-renew-ca.foo-start[305]: + mv domainhash.txt certificates/432ca # [7204950.779762] ca acme-order-renew-ca.foo-start[305]: + touch out/acme-success433ca # [7204950.781466] ca acme-order-renew-ca.foo-start[305]: + cmp -s certificates/ca.foo.crt out/fullchain.pem434ca # [7204950.782931] ca acme-order-renew-ca.foo-start[305]: + touch out/renewed435ca # [7204950.784623] ca acme-order-renew-ca.foo-start[305]: + echo Installing new certificate436ca # [7204950.784623] ca acme-order-renew-ca.foo-start[305]: Installing new certificate437ca # [7204950.784623] ca acme-order-renew-ca.foo-start[305]: + cp -vp certificates/ca.foo.crt out/fullchain.pem438ca # [7204950.786263] ca acme-order-renew-ca.foo-start[348]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem'439ca # [7204950.786618] ca acme-order-renew-ca.foo-start[305]: + cp -vp certificates/ca.foo.key out/key.pem440ca # [7204950.788117] ca acme-order-renew-ca.foo-start[349]: 'certificates/ca.foo.key' -> 'out/key.pem'441ca # [7204950.788427] ca acme-order-renew-ca.foo-start[305]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem442ca # [7204950.790205] ca acme-order-renew-ca.foo-start[350]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem'443ca # [7204950.790513] ca acme-order-renew-ca.foo-start[305]: + ln -sf fullchain.pem out/cert.pem444ca # [7204950.792970] ca acme-order-renew-ca.foo-start[305]: + cat out/key.pem out/fullchain.pem445ca # [7204950.794904] ca acme-order-renew-ca.foo-start[305]: + for fixpath in out certificates446ca # [7204950.794904] ca acme-order-renew-ca.foo-start[305]: + '[' -d out ']'447ca # [7204950.794904] ca acme-order-renew-ca.foo-start[305]: + chmod -R u=rwX,g=rX,o= out448ca # [7204950.796585] ca acme-order-renew-ca.foo-start[305]: + chown -R acme:nginx out449ca # [7204950.799182] ca acme-order-renew-ca.foo-start[305]: + for fixpath in out certificates450ca # [7204950.799182] ca acme-order-renew-ca.foo-start[305]: + '[' -d certificates ']'451ca # [7204950.799275] ca acme-order-renew-ca.foo-start[305]: + chmod -R u=rwX,g=rX,o= certificates452ca # [7204950.800838] ca acme-order-renew-ca.foo-start[305]: + chown -R acme:nginx certificates453ca # [7204950.803741] ca acme-order-renew-ca.foo-start[305]: + chmod -R u=rwX,g=,o= accounts/.454ca # [7204950.925392] ca systemd[1]: Reloading Nginx Web Server...455ca # [7204950.930037] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.456ca # [7204950.930226] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.457server # [7204951.488023] server acme-order-renew-test.foo-start[280]: 2026/08/31 08:46:17 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 2 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority458server # [7204951.491647] server acme-order-renew-test.foo-start[269]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.459server # [7204951.491647] server acme-order-renew-test.foo-start[269]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.460server # [7204951.491647] server acme-order-renew-test.foo-start[269]: + exit 10461server # [7204951.495315] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a462server # [7204951.495410] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'.463server # [7204951.495643] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo.464server # [7204951.495972] server systemd[1]: Startup finished in 4.817s.465ca # [7204951.614382] ca nginx[366]: nginx: the configuration file /nix/store/qvq6qxlf6qym8p85q6ss08zqvgy8h812-nginx.conf syntax is ok466ca # [7204951.614994] ca nginx[366]: nginx: configuration file /nix/store/qvq6qxlf6qym8p85q6ss08zqvgy8h812-nginx.conf test is successful467ca # [7204952.114330] ca systemd[1]: Reloaded Nginx Web Server.468ca # [7204952.114701] ca systemd[1]: Startup finished in 5.430s.469ca # [7204952.396605] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...470ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 3.88 seconds)471ca # [7204952.870118] ca acme-order-renew-ca.foo-start[381]: Waiting to acquire lock in /run/acme/472ca # [7204952.872938] ca acme-order-renew-ca.foo-start[381]: + set -euo pipefail473ca # [7204952.873024] ca acme-order-renew-ca.foo-start[381]: + echo 88dc4fc401a6091a1bd9474ca # [7204952.873127] ca acme-order-renew-ca.foo-start[381]: + cmp -s domainhash.txt certificates/domainhash.txt475ca # [7204952.874372] ca acme-order-renew-ca.foo-start[381]: + '[' -e certificates/ca.foo.key ']'476ca # [7204952.874372] ca acme-order-renew-ca.foo-start[381]: + '[' -e certificates/ca.foo.crt ']'477ca # [7204952.874823] ca acme-order-renew-ca.foo-start[389]: ++ find accounts -name none@none.tld.key478ca # [7204952.878120] ca acme-order-renew-ca.foo-start[381]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']'479ca # [7204952.878232] ca acme-order-renew-ca.foo-start[381]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic480ca # [7204952.920632] ca step-ca[203]: time="2026-08-31T08:46:18Z" level=info duration="69.121µs" duration-ns=69121 fields.time="2026-08-31T08:46:18Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=fe8530af-6aaf-45a8-9859-61815d88917e response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=481ca # [7204952.921321] ca acme-order-renew-ca.foo-start[390]: 2026/08/31 08:46:18 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint482ca # [7204952.921321] ca acme-order-renew-ca.foo-start[390]: 2026/08/31 08:46:18 [INFO] [ca.foo] The certificate expires at 2026-11-29T08:46:16Z, the renewal can be performed in 1439h59m37.025907697s: no renewal.483ca # [7204952.921594] ca acme-order-renew-ca.foo-start[381]: + mv domainhash.txt certificates/484ca # [7204952.923466] ca acme-order-renew-ca.foo-start[381]: + touch out/acme-success485ca # [7204952.925516] ca acme-order-renew-ca.foo-start[381]: + cmp -s certificates/ca.foo.crt out/fullchain.pem486ca # [7204952.926881] ca acme-order-renew-ca.foo-start[381]: + for fixpath in out certificates487ca # [7204952.926881] ca acme-order-renew-ca.foo-start[381]: + '[' -d out ']'488ca # [7204952.926975] ca acme-order-renew-ca.foo-start[381]: + chmod -R u=rwX,g=rX,o= out489ca # [7204952.928986] ca acme-order-renew-ca.foo-start[381]: + chown -R acme:nginx out490ca # [7204952.932404] ca acme-order-renew-ca.foo-start[381]: + for fixpath in out certificates491ca # [7204952.932404] ca acme-order-renew-ca.foo-start[381]: + '[' -d certificates ']'492ca # [7204952.932498] ca acme-order-renew-ca.foo-start[381]: + chmod -R u=rwX,g=rX,o= certificates493ca # [7204952.933818] ca acme-order-renew-ca.foo-start[381]: + chown -R acme:nginx certificates494ca # [7204952.936547] ca acme-order-renew-ca.foo-start[381]: + chmod -R u=rwX,g=,o= accounts/.495ca # [7204953.103228] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.496ca # [7204953.103411] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.497server: must succeed: systemctl restart acme-test.foo.service498server # [7204956.133787] server systemd[1]: acme-test.foo.service: Deactivated successfully.499server # [7204956.133966] server systemd[1]: Stopped Ensure certificate for test.foo.500server # [7204956.134815] server systemd[1]: Stopping Ensure certificate for test.foo...501server # [7204956.136361] server systemd[1]: Starting Ensure certificate for test.foo...502server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.59 seconds)503client: waiting for success: curl -v https://test.foo504* Host test.foo:443 was resolved.505* IPv6: 2001:db8:1::3506* IPv4: 192.168.1.3507* Trying [2001:db8:1::3]:443...508* ALPN: curl offers h2,http/1.1509} [5 bytes data]510* TLSv1.3 (OUT), TLS handshake, Client hello (1):511} [1552 bytes data]512* SSL Trust Anchors:513* OpenSSL default paths (fallback)514{ [5 bytes data]515* TLSv1.3 (IN), TLS handshake, Server hello (2):516{ [1210 bytes data]517* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):518{ [1 bytes data]519* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):520{ [19 bytes data]521* TLSv1.3 (IN), TLS handshake, Certificate (11):522{ [1010 bytes data]523* TLSv1.3 (IN), TLS handshake, CERT verify (15):524{ [111 bytes data]525* TLSv1.3 (IN), TLS handshake, Finished (20):526{ [52 bytes data]527* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):528} [1 bytes data]529* TLSv1.3 (OUT), TLS handshake, Finished (20):530} [52 bytes data]531* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey532* ALPN: server accepted h2533* Server certificate:534* subject: CN=test.foo535* start date: Aug 31 08:46:15 2026 GMT536* expire date: Sep 30 08:46:15 2028 GMT537* issuer: CN=minica root ca 71baab538* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384539* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384540* subjectAltName: "test.foo" matches cert's "test.foo"541* OpenSSL verify result: 13542* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)543* closing connection #0544curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)545More details here: https://curl.se/docs/sslcerts.html546547curl failed to verify the legitimacy of the server and therefore could not548establish a secure connection to it. To learn more about this situation and549how to fix it, please visit the webpage mentioned above.550server # [7204956.668191] server acme-test.foo-start[315]: Waiting to acquire lock in /run/acme/551server # [7204956.671501] server acme-test.foo-start[315]: + '[' -e out/acme-success ']'552server # [7204956.671501] server acme-test.foo-start[315]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=553server # [7204956.686986] server acme-test.foo-start[325]: + cd test.foo554server # [7204956.687434] server acme-test.foo-start[325]: + cp -vp cert.pem ../out/cert.pem555server # [7204956.688963] server acme-test.foo-start[326]: 'cert.pem' -> '../out/cert.pem'556server # [7204956.689283] server acme-test.foo-start[325]: + cp -vp key.pem ../out/key.pem557server # [7204956.690640] server acme-test.foo-start[325]: 'key.pem' -> '../out/key.pem'558server # [7204956.690887] server acme-test.foo-start[315]: + cat out/cert.pem ca/cert.pem559server # [7204956.692722] server acme-test.foo-start[315]: + cp ca/cert.pem out/chain.pem560server # [7204956.694107] server acme-test.foo-start[315]: + cat out/key.pem out/fullchain.pem561server # [7204956.695850] server acme-test.foo-start[315]: + for fixpath in out certificates562server # [7204956.695850] server acme-test.foo-start[315]: + '[' -d out ']'563server # [7204956.695946] server acme-test.foo-start[315]: + chmod -R u=rwX,g=rX,o= out564server # [7204956.697802] server acme-test.foo-start[315]: + chown -R acme:nginx out565server # [7204956.701220] server acme-test.foo-start[315]: + for fixpath in out certificates566server # [7204956.701220] server acme-test.foo-start[315]: + '[' -d certificates ']'567server # [7204956.705344] server systemd[1]: Finished Ensure certificate for test.foo.568server # [7204956.710080] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...569server # [7204957.228179] server acme-order-renew-test.foo-start[333]: Waiting to acquire lock in /run/acme/570server # [7204957.230627] server acme-order-renew-test.foo-start[333]: + set -euo pipefail571server # [7204957.230699] server acme-order-renew-test.foo-start[333]: + echo ad12aa6741ce4bd2c108572server # [7204957.230810] server acme-order-renew-test.foo-start[333]: + cmp -s domainhash.txt certificates/domainhash.txt573server # [7204957.231873] server acme-order-renew-test.foo-start[333]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run574server # [7204957.293808] server acme-order-renew-test.foo-start[341]: 2026/08/31 08:46:23 [INFO] acme: Registering account for none@none.tld575server # [7204957.304446] server acme-order-renew-test.foo-start[341]: !!!! HEADS UP !!!!576server # [7204957.304446] server acme-order-renew-test.foo-start[341]: Your account credentials have been saved in your577server # [7204957.304446] server acme-order-renew-test.foo-start[341]: configuration directory at "accounts".578server # [7204957.304446] server acme-order-renew-test.foo-start[341]: You should make a secure backup of this folder now. This579server # [7204957.304446] server acme-order-renew-test.foo-start[341]: configuration directory will also contain private keys580server # [7204957.304446] server acme-order-renew-test.foo-start[341]: generated by lego and certificates obtained from the ACME581server # [7204957.304446] server acme-order-renew-test.foo-start[341]: server. Making regular backups of this folder is ideal.582server # [7204957.304824] server acme-order-renew-test.foo-start[341]: 2026/08/31 08:46:23 [INFO] [test.foo] acme: Obtaining bundled SAN certificate583server # [7204957.369500] server acme-order-renew-test.foo-start[341]: 2026/08/31 08:46:23 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/rMhU2P43gGO9njkGwQDVshoie4jiQbJt584server # [7204957.369500] server acme-order-renew-test.foo-start[341]: 2026/08/31 08:46:23 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01585server # [7204957.369500] server acme-order-renew-test.foo-start[341]: 2026/08/31 08:46:23 [INFO] [test.foo] acme: use http-01 solver586server # [7204957.369500] server acme-order-renew-test.foo-start[341]: 2026/08/31 08:46:23 [INFO] [test.foo] acme: Trying to solve HTTP-01587server # [7204957.377428] server acme-order-renew-test.foo-start[341]: 2026/08/31 08:46:23 [INFO] [test.foo] The server validated our request588server # [7204957.377549] server acme-order-renew-test.foo-start[341]: 2026/08/31 08:46:23 [INFO] [test.foo] acme: Validations succeeded; requesting certificates589server # [7204957.396133] server acme-order-renew-test.foo-start[341]: 2026/08/31 08:46:23 [INFO] [test.foo] Server responded with a certificate.590server # [7204957.400931] server acme-order-renew-test.foo-start[333]: + mv domainhash.txt certificates/591server # [7204957.402984] server acme-order-renew-test.foo-start[333]: + touch out/acme-success592server # [7204957.404695] server acme-order-renew-test.foo-start[333]: + cmp -s certificates/test.foo.crt out/fullchain.pem593server # [7204957.405800] server acme-order-renew-test.foo-start[333]: + touch out/renewed594server # [7204957.408301] server acme-order-renew-test.foo-start[333]: + echo Installing new certificate595server # [7204957.408301] server acme-order-renew-test.foo-start[333]: Installing new certificate596server # [7204957.408301] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.crt out/fullchain.pem597server # [7204957.409890] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.crt' -> 'out/fullchain.pem'598server # [7204957.410263] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.key out/key.pem599server # [7204957.412427] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.key' -> 'out/key.pem'600server # [7204957.412782] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem601server # [7204957.414477] server acme-order-renew-test.foo-start[375]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem'602server # [7204957.414778] server acme-order-renew-test.foo-start[333]: + ln -sf fullchain.pem out/cert.pem603server # [7204957.416337] server acme-order-renew-test.foo-start[333]: + cat out/key.pem out/fullchain.pem604server # [7204957.418994] server acme-order-renew-test.foo-start[333]: + for fixpath in out certificates605server # [7204957.418994] server acme-order-renew-test.foo-start[333]: + '[' -d out ']'606server # [7204957.419087] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=rX,o= out607server # [7204957.420924] server acme-order-renew-test.foo-start[333]: + chown -R acme:nginx out608server # [7204957.423735] server acme-order-renew-test.foo-start[333]: + for fixpath in out certificates609server # [7204957.423735] server acme-order-renew-test.foo-start[333]: + '[' -d certificates ']'610server # [7204957.423825] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=rX,o= certificates611server # [7204957.426266] server acme-order-renew-test.foo-start[333]: + chown -R acme:nginx certificates612server # [7204957.429572] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=,o= accounts/.613ca # [7204957.293208] ca step-ca[203]: time="2026-08-31T08:46:23Z" level=info duration="40.521µs" duration-ns=40521 fields.time="2026-08-31T08:46:23Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=a595ad73-ca67-493e-9a3e-2856be22fc6d response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=614ca # [7204957.299538] ca step-ca[203]: time="2026-08-31T08:46:23Z" level=info duration="624.249µs" duration-ns=624249 fields.time="2026-08-31T08:46:23Z" method=HEAD name=ca nonce=dG5BWm5ZWU16TGhxdlZlWnhZb1Jjc1VJbGJ5SGNuSkI path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=e958b198-7054-4e68-b4bf-123f412f269c size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=615ca # [7204957.303963] ca step-ca[203]: time="2026-08-31T08:46:23Z" level=info duration=1.530382ms duration-ns=1530382 fields.time="2026-08-31T08:46:23Z" method=POST name=ca nonce=dlRSUHlIc29BSnIyTDRETmt2eHdnbnJVMFBGcllFNnc path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=f5fb2d9b-bcaa-4bea-8d77-cb80c5615268 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/aV53msxzL0VlCXtkg0rUT4OBR1zKOOAi/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=616ca # [7204957.308778] ca step-ca[203]: time="2026-08-31T08:46:23Z" level=info duration=2.566116ms duration-ns=2566116 fields.time="2026-08-31T08:46:23Z" method=POST name=ca nonce=UnY5dzB2NmpSc0M0M2FaT2JtaXVqcEtoVERRYmV2R0M path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=bb251fbb-a325-4b05-b6cb-dd75dba38ba9 response="{\"id\":\"6IrdUk6OEK4ox0FiYJ0iVhxe8OIgUgHo\",\"status\":\"pending\",\"expires\":\"2026-09-01T08:46:23Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-31T08:45:23Z\",\"notAfter\":\"2026-11-29T08:46:23Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/rMhU2P43gGO9njkGwQDVshoie4jiQbJt\"],\"finalize\":\"https://ca.foo/acme/acme/order/6IrdUk6OEK4ox0FiYJ0iVhxe8OIgUgHo/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=617ca # [7204957.369022] ca step-ca[203]: time="2026-08-31T08:46:23Z" level=info duration=1.564782ms duration-ns=1564782 fields.time="2026-08-31T08:46:23Z" method=POST name=ca nonce=UmtSVzJvaXIyOWxGUXB4ZmZab2x2MEVYVTN0ZklGMUU path=/acme/acme/authz/rMhU2P43gGO9njkGwQDVshoie4jiQbJt protocol=HTTP/1.1 referer= remote-address="::1" request-id=8496ce17-069a-43e7-bfd4-c7ef028ee674 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"4XQWfiXJxXoU3qXME7fgsI5R9kPYDeDF\",\"url\":\"https://ca.foo/acme/acme/challenge/rMhU2P43gGO9njkGwQDVshoie4jiQbJt/SroyjWd2j4cNfGvuHAKD2nFPeOyyh5z6\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"4XQWfiXJxXoU3qXME7fgsI5R9kPYDeDF\",\"url\":\"https://ca.foo/acme/acme/challenge/rMhU2P43gGO9njkGwQDVshoie4jiQbJt/aCXJnpjJkEN4ln5gkR9hSTJBOzk1OAOc\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"4XQWfiXJxXoU3qXME7fgsI5R9kPYDeDF\",\"url\":\"https://ca.foo/acme/acme/challenge/rMhU2P43gGO9njkGwQDVshoie4jiQbJt/K9nEs5ThnzairThNsYVsfNvfpi1T1grN\"}],\"wildcard\":false,\"expires\":\"2026-09-01T08:46:23Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=618ca # [7204957.376964] ca step-ca[203]: time="2026-08-31T08:46:23Z" level=info duration=4.573943ms duration-ns=4573943 fields.time="2026-08-31T08:46:23Z" method=POST name=ca nonce=MFlvWVZWa0pocVNJV0pyZVNnblFXdkxvdkE0NEhNTkU path=/acme/acme/challenge/rMhU2P43gGO9njkGwQDVshoie4jiQbJt/aCXJnpjJkEN4ln5gkR9hSTJBOzk1OAOc protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=e9d97fb5-8f8f-4e4d-98f1-acdb77c2c06d response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"4XQWfiXJxXoU3qXME7fgsI5R9kPYDeDF\",\"validated\":\"2026-08-31T08:46:23Z\",\"url\":\"https://ca.foo/acme/acme/challenge/rMhU2P43gGO9njkGwQDVshoie4jiQbJt/aCXJnpjJkEN4ln5gkR9hSTJBOzk1OAOc\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=619ca # [7204957.389460] ca step-ca[203]: time="2026-08-31T08:46:23Z" level=info duration=8.779682ms duration-ns=8779682 fields.time="2026-08-31T08:46:23Z" method=POST name=ca nonce=aVlPV1FIRTFpam1YTjJ0bDgzNmZnQnp6S2h2R0htRlU path=/acme/acme/order/6IrdUk6OEK4ox0FiYJ0iVhxe8OIgUgHo/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=4ecc8c9c-ccd6-4353-8c30-1b9ca38603e8 response="{\"id\":\"6IrdUk6OEK4ox0FiYJ0iVhxe8OIgUgHo\",\"status\":\"valid\",\"expires\":\"2026-09-01T08:46:23Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-31T08:45:23Z\",\"notAfter\":\"2026-11-29T08:46:23Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/rMhU2P43gGO9njkGwQDVshoie4jiQbJt\"],\"finalize\":\"https://ca.foo/acme/acme/order/6IrdUk6OEK4ox0FiYJ0iVhxe8OIgUgHo/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/YfQp6NBzz4dt5NA4ts8vfmdnSL9plgYT\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=620ca # [7204957.395340] ca step-ca[203]: time="2026-08-31T08:46:23Z" level=info certificate=MIIB2TCCAX6gAwIBAgIRALT/mV3wiD0Zt5O4txeuS8QwCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODMxMDg0NTIzWhcNMjYxMTI5MDg0NjIzWjATMREwDwYDVQQDEwh0ZXN0LmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABOYe44ATqGBVZhE7wEKFQfN9fUgKVT4a46Zt+Hd6s0OmAJ535sONxAomxHTnv8IjXuPhZTP9+V+MHlr3B8DnvlujgaYwgaMwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUn0sPbpxamdqIb1fpqggaULLSxlMwHwYDVR0jBBgwFoAUfhxJ9/ma1l0Dp91a/5v5pz7xYscwEwYDVR0RBAwwCoIIdGVzdC5mb28wHQYMKwYBBAGCpGTGKEABBA0wCwIBBgQEYWNtZQQAMAoGCCqGSM49BAMCA0kAMEYCIQDKvHue2P0BCEeQz+KggKryGtIZL+WhSvqqi9La3P5CMAIhALocJMazlA/4smUM2JcW2YEXHbmuatZBRxSneZb4bQjh duration=1.981027ms duration-ns=1981027 fields.time="2026-08-31T08:46:23Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=dlJmZG9Fc3AwVHY4ZzFQbFppUDhJNzROVFREZzA0aXQ path=/acme/acme/certificate/YfQp6NBzz4dt5NA4ts8vfmdnSL9plgYT protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=863c009d-bfc6-40f8-8a6a-a24d180c7ca9 sans="map[dns:[test.foo]]" serial=240588185591540815507461390123284712388 size=1352 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-31T08:45:23Z" valid-to="2026-11-29T08:46:23Z"621* Trying [2001:db8:1::3]:443...622* Host test.foo:443 was resolved.623* IPv6: 2001:db8:1::3624* IPv4: 192.168.1.3625* ALPN: curl offers h2,http/1.1626} [5 bytes data]627* TLSv1.3 (OUT), TLS handshake, Client hello (1):628} [1552 bytes data]629* SSL Trust Anchors:630* OpenSSL default paths (fallback)631{ [5 bytes data]632* TLSv1.3 (IN), TLS handshake, Server hello (2):633{ [1210 bytes data]634* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):635{ [1 bytes data]636* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):637{ [19 bytes data]638* TLSv1.3 (IN), TLS handshake, Certificate (11):639{ [1010 bytes data]640* TLSv1.3 (IN), TLS handshake, CERT verify (15):641{ [111 bytes data]642* TLSv1.3 (IN), TLS handshake, Finished (20):643{ [52 bytes data]644* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):645} [1 bytes data]646* TLSv1.3 (OUT), TLS handshake, Finished (20):647} [52 bytes data]648* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey649* ALPN: server accepted h2650* Server certificate:651* subject: CN=test.foo652* start date: Aug 31 08:46:15 2026 GMT653* expire date: Sep 30 08:46:15 2028 GMT654* issuer: CN=minica root ca 71baab655* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384656* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384657* subjectAltName: "test.foo" matches cert's "test.foo"658* OpenSSL verify result: 13659* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)660* closing connection #0661curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)662More details here: https://curl.se/docs/sslcerts.html663664curl failed to verify the legitimacy of the server and therefore could not665establish a secure connection to it. To learn more about this situation and666how to fix it, please visit the webpage mentioned above.667server # [7204957.607930] server systemd[1]: Reloading Nginx Web Server...668server # [7204957.613265] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully.669server # [7204957.613566] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo.670server # [7204958.194934] server nginx[391]: nginx: the configuration file /nix/store/jz7kmd1pqz9d3z4szhmwj70infw1zqg3-nginx.conf syntax is ok671server # [7204958.195327] server nginx[391]: nginx: configuration file /nix/store/jz7kmd1pqz9d3z4szhmwj70infw1zqg3-nginx.conf test is successful672* Host test.foo:443 was resolved.673* IPv6: 2001:db8:1::3674* IPv4: 192.168.1.3675* Trying [2001:db8:1::3]:443...676* ALPN: curl offers h2,http/1.1677} [5 bytes data]678* TLSv1.3 (OUT), TLS handshake, Client hello (1):679} [1552 bytes data]680* SSL Trust Anchors:681* OpenSSL default paths (fallback)682{ [5 bytes data]683* TLSv1.3 (IN), TLS handshake, Server hello (2):684{ [1210 bytes data]685* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):686{ [1 bytes data]687* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):688{ [19 bytes data]689* TLSv1.3 (IN), TLS handshake, Certificate (11):690{ [934 bytes data]691* TLSv1.3 (IN), TLS handshake, CERT verify (15):692{ [80 bytes data]693* TLSv1.3 (IN), TLS handshake, Finished (20):694{ [52 bytes data]695* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):696} [1 bytes data]697* TLSv1.3 (OUT), TLS handshake, Finished (20):698} [52 bytes data]699* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey700* ALPN: server accepted h2701* Server certificate:702* subject: CN=test.foo703* start date: Aug 31 08:45:23 2026 GMT704* expire date: Nov 29 08:46:23 2026 GMT705* issuer: CN=Clan Intermediate CA706* Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256707* Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256708* Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256709* subjectAltName: "test.foo" matches cert's "test.foo"710* OpenSSL verify result: 0711* SSL certificate verified via OpenSSL.712* Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 43386 713 % Total % Received % Xferd Average Speed Time Time Time Current714 Dload Upload Total Spent Left Speed715 0 0 0 0 0 0 0 0 0* using HTTP/2716* [HTTP/2] [1] OPENED stream for https://test.foo/717* [HTTP/2] [1] [:method: GET]718* [HTTP/2] [1] [:scheme: https]719* [HTTP/2] [1] [:authority: test.foo]720* [HTTP/2] [1] [:path: /]721* [HTTP/2] [1] [user-agent: curl/8.21.0]722* [HTTP/2] [1] [accept: */*]723} [5 bytes data]724725726727728729* Request completely sent off730{ [5 bytes data]731* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):732{ [265 bytes data]733* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):734{ [265 bytes data]735736737738739740741742{ [5 bytes data]743100 20 100 20 0 0 708 0 0744* Connection #0 to host test.foo:443 left intact745client: (finished: waiting for success: curl -v https://test.foo, in 2.15 seconds)746client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2747Certificate:748 Data:749 Version: 3 (0x2)750 Serial Number:751 b4:ff:99:5d:f0:88:3d:19:b7:93:b8:b7:17:ae:4b:c4752 Signature Algorithm: ecdsa-with-SHA256753 Issuer: CN=Clan Intermediate CA754 Validity755 Not Before: Aug 31 08:45:23 2026 GMT756 Not After : Nov 29 08:46:23 2026 GMT757 Subject: CN=test.foo758 Subject Public Key Info:759 Public Key Algorithm: id-ecPublicKey760 Public-Key: (256 bit)761 pub:762 04:e6:1e:e3:80:13:a8:60:55:66:11:3b:c0:42:85:763 41:f3:7d:7d:48:0a:55:3e:1a:e3:a6:6d:f8:77:7a:764 b3:43:a6:00:9e:77:e6:c3:8d:c4:0a:26:c4:74:e7:765 bf:c2:23:5e:e3:e1:65:33:fd:f9:5f:8c:1e:5a:f7:766 07:c0:e7:be:5b767 ASN1 OID: prime256v1768 NIST CURVE: P-256769 X509v3 extensions:770 X509v3 Key Usage: critical771 Digital Signature772 X509v3 Extended Key Usage: 773 TLS Web Server Authentication, TLS Web Client Authentication774 X509v3 Subject Key Identifier: 775 9F:4B:0F:6E:9C:5A:99:DA:88:6F:57:E9:AA:08:1A:50:B2:D2:C6:53776 X509v3 Authority Key Identifier: 777 7E:1C:49:F7:F9:9A:D6:5D:03:A7:DD:5A:FF:9B:F9:A7:3E:F1:62:C7778 X509v3 Subject Alternative Name: 779 DNS:test.foo780 1.3.6.1.4.1.37476.9000.64.1: 781 0......acme..782 Signature Algorithm: ecdsa-with-SHA256783 Signature Value:784 30:46:02:21:00:ca:bc:7b:9e:d8:fd:01:08:47:90:cf:e2:a0:785 80:aa:f2:1a:d2:19:2f:e5:a1:4a:fa:aa:8b:d2:da:dc:fe:42:786 30:02:21:00:ba:1c:24:c6:b3:94:0f:f8:b2:65:0c:d8:97:16:787 d9:81:17:1d:b9:ae:6a:d6:41:47:14:a7:79:96:f8:6d:08:e1788client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2, in 0.05 seconds)789(finished: run the VM test script, in 12.66 seconds)790server # [7204958.705562] server systemd[1]: Reloaded Nginx Web Server.791test script finished in 13.63s792cleanup793kill NspawnMachine (pid 53)794kill NspawnMachine (pid 54)795kill NspawnMachine (pid 55)796Container ca terminated by signal KILL.797Container client terminated by signal KILL.798Container server terminated by signal KILL.799(finished: cleanup, in 0.54 seconds)