container-test-run-certificates
checks.aarch64-linux.certificates
· build #538
· raw
1Machine state will be reset. To keep it, pass --keep-machine-state2start all VLans3(finished: start all VLans, in 0.00 seconds)45Test will time out and terminate in 3600.0 seconds6run the VM test script7additionally exposed symbols:8 ca, client, server,9 vlan1,10 start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh11start all VMs12ca: systemd-nspawn running (pid 53)13client: systemd-nspawn running (pid 54)14server: systemd-nspawn running (pid 55)15ca: Waiting for journal at /build/vm-state-ca/var/log/journal...16client: Waiting for journal at /build/vm-state-client/var/log/journal...17server: Waiting for journal at /build/vm-state-server/var/log/journal...18(finished: start all VMs, in 0.00 seconds)19nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE20nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.21nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE22nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.23nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE24nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.25Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.26░ Spawning container client on /build/vm-state-client.27Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.28░ Spawning container ca on /build/vm-state-ca.29Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.30░ Spawning container server on /build/vm-state-server.31ca # [7209088.604692] ca systemd-journald[78]: Journal started32ca # [7209088.604743] ca systemd-journald[78]: Runtime Journal (/run/log/journal/fcb1c85cc452424487393e035476900c) is 8M, max 2.5G, 2.4G free.33ca # [7209088.606203] ca systemd[1]: Finished Apply Kernel Variables.34ca # [7209088.615057] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully.35client # [7209088.599819] client systemd-journald[69]: Journal started36ca # [7209088.625247] ca systemd[1]: Starting Flush Journal to Persistent Storage...37client # [7209088.599873] client systemd-journald[69]: Runtime Journal (/run/log/journal/c0ee19277c7742e091e327ae74797dc2) is 8M, max 2.5G, 2.4G free.38ca # [7209088.626047] ca systemd[1]: Starting Network Name Resolution...39client # [7209088.605796] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully.40ca # [7209088.626715] ca systemd[1]: Starting Create Static Device Nodes in /dev...41client # [7209088.614772] client systemd[1]: Starting Flush Journal to Persistent Storage...42ca # [7209088.634466] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/fcb1c85cc452424487393e035476900c is 1.726ms for 7 entries.43client # [7209088.615953] client systemd[1]: Starting Network Name Resolution...44ca # [7209088.634466] ca systemd-journald[78]: System Journal (/var/log/journal/fcb1c85cc452424487393e035476900c) is 8M, max 4G, 3.9G free.45client # [7209088.616790] client systemd[1]: Starting Create Static Device Nodes in /dev...46ca # [7209088.640354] ca systemd[1]: Finished Create Static Device Nodes in /dev.47client # [7209088.624170] client systemd-journald[69]: Time spent on flushing to /var/log/journal/c0ee19277c7742e091e327ae74797dc2 is 1.455ms for 6 entries.48ca # [7209088.640620] ca systemd[1]: Reached target Preparation for Local File Systems.49client # [7209088.624170] client systemd-journald[69]: System Journal (/var/log/journal/c0ee19277c7742e091e327ae74797dc2) is 8M, max 4G, 3.9G free.50ca # [7209088.640711] ca systemd[1]: Reached target Local File Systems.51client # [7209088.635748] client systemd[1]: Finished Create Static Device Nodes in /dev.52ca # [7209088.641475] ca systemd[1]: Listening on Boot Loader Control Service Socket.53client # [7209088.636487] client systemd[1]: Reached target Preparation for Local File Systems.54ca # [7209088.641554] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container55client # [7209088.636611] client systemd[1]: Reached target Local File Systems.56ca # [7209088.642444] ca systemd[1]: Starting Save Transient machine-id to Disk...57client # [7209088.637454] client systemd[1]: Listening on Boot Loader Control Service Socket.58ca # [7209088.642485] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys59client # [7209088.637501] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container60ca # [7209088.662308] ca systemd[1]: Finished Flush Journal to Persistent Storage.61client # [7209088.638453] client systemd[1]: Starting Save Transient machine-id to Disk...62ca # [7209088.664205] ca systemd[1]: Starting Create System Files and Directories...63client # [7209088.638491] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys64client # [7209088.662824] client systemd[1]: Finished Flush Journal to Persistent Storage.65client # [7209088.664626] client systemd[1]: Starting Create System Files and Directories...66server # [7209088.610036] server systemd-journald[69]: Journal started67server # [7209088.610087] server systemd-journald[69]: Runtime Journal (/run/log/journal/26718a380989430cb7bd570fb8b1c422) is 8M, max 2.5G, 2.4G free.68server # [7209088.611929] server systemd[1]: Finished Apply Kernel Variables.69server # [7209088.624625] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully.70server # [7209088.637315] server systemd[1]: Starting Flush Journal to Persistent Storage...71server # [7209088.638219] server systemd[1]: Starting Network Name Resolution...72server # [7209088.638923] server systemd[1]: Starting Create Static Device Nodes in /dev...73server # [7209088.647200] server systemd-journald[69]: Time spent on flushing to /var/log/journal/26718a380989430cb7bd570fb8b1c422 is 1.570ms for 7 entries.74client # [7209088.679190] client systemd-tmpfiles[128]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted75server # [7209088.647200] server systemd-journald[69]: System Journal (/var/log/journal/26718a380989430cb7bd570fb8b1c422) is 8M, max 4G, 3.9G free.76server # [7209088.659252] server systemd[1]: Finished Create Static Device Nodes in /dev.77server # [7209088.659964] server systemd[1]: Reached target Preparation for Local File Systems.78server # [7209088.660119] server systemd[1]: Reached target Local File Systems.79server # [7209088.661340] server systemd[1]: Listening on Boot Loader Control Service Socket.80server # [7209088.661402] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container81server # [7209088.662385] server systemd[1]: Starting Save Transient machine-id to Disk...82server # [7209088.662425] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys83server # [7209088.675404] server systemd[1]: Finished Flush Journal to Persistent Storage.84server # [7209088.676969] server systemd[1]: Starting Create System Files and Directories...85server # [7209088.693601] server systemd-tmpfiles[126]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted86server # [7209088.693809] server systemd-tmpfiles[126]: fchmod() of /var/log/journal failed: Operation not permitted87server # [7209088.693948] server systemd-tmpfiles[126]: fchmod() of /var/log/journal/26718a380989430cb7bd570fb8b1c422 failed: Operation not permitted88server # [7209088.694163] server systemd-tmpfiles[126]: fchmod() of /run/log/journal failed: Operation not permitted89client # [7209088.679752] client systemd-tmpfiles[128]: fchmod() of /var/log/journal failed: Operation not permitted90client # [7209088.679890] client systemd-tmpfiles[128]: fchmod() of /var/log/journal/c0ee19277c7742e091e327ae74797dc2 failed: Operation not permitted91client # [7209088.680105] client systemd-tmpfiles[128]: fchmod() of /run/log/journal failed: Operation not permitted92client # [7209088.682668] client systemd[1]: Finished Create System Files and Directories.93client # [7209088.683938] client systemd[1]: Starting Rebuild Journal Catalog...94client # [7209088.684845] client systemd[1]: Starting Record System Boot/Shutdown in UTMP...95client # [7209088.696448] client systemd[1]: Finished Record System Boot/Shutdown in UTMP.96client # [7209088.703900] client systemd[1]: Finished Rebuild Journal Catalog.97client # [7209088.705061] client systemd[1]: Starting Update is Completed...98client # [7209088.715164] client systemd[1]: Finished Update is Completed.99client # [7209088.743483] client systemd[1]: Finished Firewall.100client # [7209088.744153] client systemd[1]: Reached target Preparation for Network.101client # [7209088.744466] client systemd[1]: Listening on Network Management Resolve Hook Socket.102client # [7209088.745635] client systemd[1]: Starting Network Management...103ca # [7209088.679189] ca systemd-tmpfiles[135]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted104ca # [7209088.679393] ca systemd-tmpfiles[135]: fchmod() of /var/log/journal failed: Operation not permitted105ca # [7209088.679513] ca systemd-tmpfiles[135]: fchmod() of /var/log/journal/fcb1c85cc452424487393e035476900c failed: Operation not permitted106ca # [7209088.679704] ca systemd-tmpfiles[135]: fchmod() of /run/log/journal failed: Operation not permitted107ca # [7209088.682668] ca systemd[1]: Finished Create System Files and Directories.108ca # [7209088.683929] ca systemd[1]: Starting Rebuild Journal Catalog...109ca # [7209088.684828] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP...110ca # [7209088.696304] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP.111ca # [7209088.704220] ca systemd[1]: Finished Rebuild Journal Catalog.112ca # [7209088.705256] ca systemd[1]: Starting Update is Completed...113ca # [7209088.715150] ca systemd[1]: Finished Update is Completed.114ca # [7209088.756401] ca systemd[1]: Finished Firewall.115ca # [7209088.756557] ca systemd[1]: Reached target Preparation for Network.116ca # [7209088.756782] ca systemd[1]: Listening on Network Management Resolve Hook Socket.117ca # [7209088.757792] ca systemd[1]: Starting Network Management...118server # [7209088.695701] server systemd[1]: Finished Create System Files and Directories.119server # [7209088.696824] server systemd[1]: Starting Rebuild Journal Catalog...120server # [7209088.697614] server systemd[1]: Starting Record System Boot/Shutdown in UTMP...121server # [7209088.708883] server systemd[1]: Finished Record System Boot/Shutdown in UTMP.122server # [7209088.716120] server systemd[1]: Finished Rebuild Journal Catalog.123server # [7209088.717283] server systemd[1]: Starting Update is Completed...124server # [7209088.727857] server systemd[1]: Finished Update is Completed.125server # [7209088.766690] server systemd[1]: Finished Firewall.126server # [7209088.766841] server systemd[1]: Reached target Preparation for Network.127server # [7209088.767071] server systemd[1]: Listening on Network Management Resolve Hook Socket.128server # [7209088.768102] server systemd[1]: Starting Network Management...129server # [7209088.886588] server systemd[1]: Finished Save Transient machine-id to Disk.130ca # [7209088.887502] ca systemd[1]: Finished Save Transient machine-id to Disk.131client # [7209088.886586] client systemd[1]: Finished Save Transient machine-id to Disk.132client # [7209089.213818] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted133client # [7209089.213933] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted134client # [7209089.222115] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.135client # [7209089.222281] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.136client # [7209089.222448] client systemd-networkd[182]: lo: Link UP137client # [7209089.222453] client systemd-networkd[182]: lo: Gained carrier138client # [7209089.222667] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network.139client # [7209089.223082] client systemd[1]: Started Network Management.140client # [7209089.223195] client systemd-networkd[182]: eth1: Link UP141client # [7209089.223476] client systemd-networkd[182]: eth1: Gained carrier142client # [7209089.224702] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd...143client # [7209089.254057] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd.144ca # [7209089.227523] ca systemd-networkd[195]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted145ca # [7209089.227618] ca systemd-networkd[195]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted146ca # [7209089.236233] ca systemd-networkd[195]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.147ca # [7209089.236406] ca systemd-networkd[195]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.148ca # [7209089.236812] ca systemd-networkd[195]: lo: Link UP149ca # [7209089.236820] ca systemd-networkd[195]: lo: Gained carrier150ca # [7209089.237232] ca systemd-networkd[195]: eth1: Configuring with /etc/systemd/network/40-eth1.network.151ca # [7209089.237753] ca systemd-networkd[195]: eth1: Link UP152ca # [7209089.238146] ca systemd[1]: Started Network Management.153ca # [7209089.239150] ca systemd-networkd[195]: eth1: Gained carrier154ca # [7209089.239834] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd...155ca # [7209089.290157] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd.156server # [7209089.238490] server systemd-networkd[186]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted157server # [7209089.238582] server systemd-networkd[186]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted158server # [7209089.251324] server systemd-networkd[186]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.159server # [7209089.251487] server systemd-networkd[186]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.160server # [7209089.251657] server systemd-networkd[186]: lo: Link UP161server # [7209089.251661] server systemd-networkd[186]: lo: Gained carrier162server # [7209089.251848] server systemd-networkd[186]: eth1: Configuring with /etc/systemd/network/40-eth1.network.163server # [7209089.252276] server systemd[1]: Started Network Management.164server # [7209089.252527] server systemd-networkd[186]: eth1: Link UP165server # [7209089.252718] server systemd-networkd[186]: eth1: Gained carrier166server # [7209089.253347] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd...167server # [7209089.290161] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd.168ca # [7209089.501872] ca systemd-resolved[107]: Positive Trust Anchors:169server # [7209089.519599] server systemd-resolved[101]: Positive Trust Anchors:170ca # [7209089.501894] ca systemd-resolved[107]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d171server # [7209089.519613] server systemd-resolved[101]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d172client # [7209089.529146] client systemd-resolved[96]: Positive Trust Anchors:173server # [7209089.519616] server systemd-resolved[101]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16174client # [7209089.529157] client systemd-resolved[96]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d175server # [7209089.519650] server systemd-resolved[101]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test176client # [7209089.529161] client systemd-resolved[96]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16177server # [7209089.542553] server systemd-resolved[101]: Using system hostname 'server'.178client # [7209089.529196] client systemd-resolved[96]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test179ca # [7209089.501898] ca systemd-resolved[107]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16180server # [7209089.544084] server systemd[1]: Started Network Name Resolution.181server # [7209089.544230] server systemd[1]: Reached target Network.182client # [7209089.551746] client systemd-resolved[96]: Using system hostname 'client'.183client # [7209089.553188] client systemd[1]: Started Network Name Resolution.184client # [7209089.553270] client systemd[1]: Reached target Network.185ca # [7209089.501931] ca systemd-resolved[107]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test186ca # [7209089.525491] ca systemd-resolved[107]: Using system hostname 'ca'.187client # [7209089.553338] client systemd[1]: Reached target System Initialization.188ca # [7209089.527238] ca systemd[1]: Started Network Name Resolution.189client # [7209089.553387] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container190ca # [7209089.527330] ca systemd[1]: Reached target Network.191server # [7209089.544340] server systemd[1]: Reached target Network is Online.192client # [7209089.553414] client systemd[1]: Started Daily Cleanup of Temporary Directories.193server # [7209089.544446] server systemd[1]: Reached target System Initialization.194client # [7209089.553430] client systemd[1]: Reached target Timer Units.195server # [7209089.544832] server systemd[1]: Started Renew ACME Certificate for test.foo.196client # [7209089.553558] client systemd[1]: Listening on D-Bus System Message Bus Socket.197server # [7209089.544890] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container198server # [7209089.544938] server systemd[1]: Started Daily Cleanup of Temporary Directories.199client # [7209089.553666] client systemd[1]: Listening on Nix Daemon Socket.200ca # [7209089.527380] ca systemd[1]: Reached target Network is Online.201ca # [7209089.527424] ca systemd[1]: Reached target System Initialization.202ca # [7209089.527641] ca systemd[1]: Started Renew ACME Certificate for ca.foo.203ca # [7209089.527670] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container204server # [7209089.544980] server systemd[1]: Reached target Timer Units.205server # [7209089.545208] server systemd[1]: Listening on D-Bus System Message Bus Socket.206client # [7209089.553773] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.207server # [7209089.546212] server systemd[1]: Listening on Nix Daemon Socket.208ca # [7209089.527691] ca systemd[1]: Started Daily Cleanup of Temporary Directories.209ca # [7209089.527707] ca systemd[1]: Reached target Timer Units.210client # [7209089.553793] client systemd[1]: Reached target Socket Units.211server # [7209089.546471] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.212ca # [7209089.527826] ca systemd[1]: Listening on D-Bus System Message Bus Socket.213server # [7209089.546524] server systemd[1]: Reached target Socket Units.214client # [7209089.553830] client systemd[1]: Reached target Basic System.215ca # [7209089.527928] ca systemd[1]: Listening on Nix Daemon Socket.216client # [7209089.555019] client systemd[1]: Starting Import lastlog data into lastlog2 database...217server # [7209089.546617] server systemd[1]: Reached target Basic System.218client # [7209089.555835] client systemd[1]: Starting Name Service Cache Daemon (nsncd)...219server # [7209089.548767] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure...220client # [7209089.557028] client systemd[1]: Starting D-Bus System Message Bus...221server # [7209089.550087] server systemd[1]: Starting Import lastlog data into lastlog2 database...222client # [7209089.572154] client systemd[1]: Finished Import lastlog data into lastlog2 database.223server # [7209089.550161] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem224client # [7209089.633350] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully.225server # [7209089.551643] server systemd[1]: Starting Name Service Cache Daemon (nsncd)...226ca # [7209089.528047] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.227server # [7209089.553862] server systemd[1]: Starting D-Bus System Message Bus...228ca # [7209089.528068] ca systemd[1]: Reached target Socket Units.229server # [7209089.567545] server systemd[1]: Finished Import lastlog data into lastlog2 database.230ca # [7209089.528112] ca systemd[1]: Reached target Basic System.231server # [7209089.631805] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully.232ca # [7209089.536950] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure...233ca # [7209089.537789] ca systemd[1]: Starting Import lastlog data into lastlog2 database...234ca # [7209089.537830] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem235ca # [7209089.538803] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)...236ca # [7209089.539700] ca systemd[1]: Starting step-ca service...237ca # [7209089.540947] ca systemd[1]: Starting D-Bus System Message Bus...238ca # [7209089.555991] ca systemd[1]: Finished Import lastlog data into lastlog2 database.239ca # [7209089.639640] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully.240ca # [7209089.827241] ca acme-setup-privileged[201]: + set -euo pipefail241ca # [7209089.827241] ca acme-setup-privileged[201]: + cd /var/lib/acme242ca # [7209089.827676] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts243ca # [7209089.828868] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts244ca # [7209089.831998] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo245ca # [7209089.831998] ca acme-setup-privileged[201]: + '[' -d ca.foo ']'246ca # [7209089.831998] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo247ca # [7209089.832120] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']'248ca # [7209089.859111] ca nsncd[203]: Aug 31 09:55:15.912 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"249ca # [7209089.864618] ca systemd[1]: Started Name Service Cache Daemon (nsncd).250ca # [7209089.864765] ca systemd[1]: Reached target Host and Network Name Lookups.251ca # [7209089.864817] ca systemd[1]: Reached target User and Group Name Lookups.252ca # [7209089.865952] ca systemd[1]: Starting User Login Management...253ca # [7209089.866748] ca systemd[1]: Starting Permit User Sessions...254ca # [7209089.875593] ca systemd[1]: Finished Permit User Sessions.255ca # [7209089.876639] ca systemd[1]: Started Console Getty.256ca # [7209089.876686] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0257ca # [7209089.876704] ca systemd[1]: Reached target Login Prompts.258ca # [7209090.075820] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'...259ca # [7209090.076422] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync'260ca # [7209090.076422] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/nrvy3kisslkv7qydv3v2ib6szfdky5q3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"261ca # [7209090.077041] ca systemd[1]: Started D-Bus System Message Bus.262server # [7209089.806328] server acme-setup-privileged[192]: + set -euo pipefail263server # [7209089.806328] server acme-setup-privileged[192]: + cd /var/lib/acme264server # [7209089.806800] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts265server # [7209089.807915] server acme-setup-privileged[192]: + chown -R acme .lego/accounts266server # [7209089.809463] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo267server # [7209089.809463] server acme-setup-privileged[192]: + '[' -d test.foo ']'268server # [7209089.809589] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo269server # [7209089.809589] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']'270server # [7209089.835312] server nsncd[194]: Aug 31 09:55:15.888 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"271server # [7209089.835428] server systemd[1]: Started Name Service Cache Daemon (nsncd).272server # [7209089.835498] server systemd[1]: Reached target Host and Network Name Lookups.273server # [7209089.835559] server systemd[1]: Reached target User and Group Name Lookups.274server # [7209089.864920] server systemd[1]: Starting User Login Management...275server # [7209089.865735] server systemd[1]: Starting Permit User Sessions...276server # [7209089.875094] server systemd[1]: Finished Permit User Sessions.277server # [7209089.876212] server systemd[1]: Started Console Getty.278server # [7209089.876252] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0279server # [7209089.876271] server systemd[1]: Reached target Login Prompts.280server # [7209090.036889] server dbus-broker-launch[196]: Looking up NSS user entry for 'systemd-timesync'...281server # [7209090.038025] server dbus-broker-launch[196]: NSS returned no entry for 'systemd-timesync'282server # [7209090.038025] server dbus-broker-launch[196]: Invalid user-name in /nix/store/aszr859gd9lnmlsj2dls188ya32g6xf8-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"283server # [7209090.038738] server systemd[1]: Started D-Bus System Message Bus.284server # [7209090.045535] server dbus-broker-launch[196]: Ready285client # [7209089.837236] client nsncd[189]: Aug 31 09:55:15.890 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"286client # [7209089.837430] client systemd[1]: Started Name Service Cache Daemon (nsncd).287client # [7209089.837532] client systemd[1]: Reached target Host and Network Name Lookups.288client # [7209089.837633] client systemd[1]: Reached target User and Group Name Lookups.289client # [7209089.865356] client systemd[1]: Starting User Login Management...290client # [7209089.866247] client systemd[1]: Starting Permit User Sessions...291client # [7209089.883862] client systemd[1]: Finished Permit User Sessions.292client # [7209089.884864] client systemd[1]: Started Console Getty.293client # [7209089.884903] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0294client # [7209089.884921] client systemd[1]: Reached target Login Prompts.295client # [7209090.054977] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'...296client # [7209090.055855] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync'297client # [7209090.055855] client dbus-broker-launch[190]: Invalid user-name in /nix/store/ssk8893k9jd7id6pd9yzim0h6prlbdma-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"298client # [7209090.056389] client systemd[1]: Started D-Bus System Message Bus.299client # [7209090.063426] client dbus-broker-launch[190]: Ready300ca # [7209090.084705] ca dbus-broker-launch[205]: Ready301ca # [7209090.340267] ca systemd-networkd[195]: eth1: Gained IPv6LL302ca: must succeed: systemctl restart acme-order-renew-ca.foo.service 303server # [7209090.500161] server systemd-networkd[186]: eth1: Gained IPv6LL304server # [7209090.590614] server systemd-logind[220]: New seat seat0.305server # [7209090.590869] server systemd[1]: Started User Login Management.306server # [7209090.625144] server systemd[1]: Starting linger-users.service...307server # [7209090.636828] server systemd[1]: linger-users.service: Deactivated successfully.308server # [7209090.637016] server systemd[1]: Finished linger-users.service.309server # [7209090.645284] server acme-setup-start[208]: + set -euo pipefail310server # [7209090.645533] server acme-setup-start[208]: + test -e ca/key.pem311server # [7209090.645533] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local312server # [7209090.666682] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure.313server # [7209090.668323] server systemd[1]: Starting Ensure certificate for test.foo...314ca # [7209090.599757] ca systemd-logind[230]: New seat seat0.315ca # [7209090.600270] ca systemd[1]: Started User Login Management.316ca # [7209090.625139] ca systemd[1]: Starting linger-users.service...317ca # [7209090.636754] ca systemd[1]: linger-users.service: Deactivated successfully.318ca # [7209090.637007] ca systemd[1]: Finished linger-users.service.319ca # [7209090.704827] ca acme-setup-start[219]: + set -euo pipefail320ca # [7209090.704827] ca acme-setup-start[219]: + test -e ca/key.pem321ca # [7209090.705434] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local322ca # [7209090.721123] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure.323ca # [7209090.722607] ca systemd[1]: Starting Ensure certificate for ca.foo...324client # [7209090.599601] client systemd-logind[205]: New seat seat0.325client # [7209090.599858] client systemd[1]: Started User Login Management.326client # [7209090.625595] client systemd[1]: Starting linger-users.service...327client # [7209090.636846] client systemd[1]: linger-users.service: Deactivated successfully.328client # [7209090.637023] client systemd[1]: Finished linger-users.service.329client # [7209090.637390] client systemd[1]: Reached target Multi-User System.330client # [7209090.660189] client systemd[1]: Startup finished in 2.542s.331ca # [7209090.937334] ca step-ca[204]: badger 2026/08/31 09:55:16 INFO: All 0 tables opened in 0s332ca # [7209090.941366] ca step-ca[204]: 2026/08/31 09:55:16 Building new tls configuration using step-ca x509 Signer Interface333ca # [7209090.945062] ca step-ca[204]: 2026/08/31 09:55:16 Starting Smallstep CA/0.30.2 (linux/arm64)334ca # [7209090.945062] ca step-ca[204]: 2026/08/31 09:55:16 Documentation: https://u.step.sm/docs/ca335ca # [7209090.945062] ca step-ca[204]: 2026/08/31 09:55:16 Community Discord: https://u.step.sm/discord336ca # [7209090.945062] ca step-ca[204]: 2026/08/31 09:55:16 Config file: /etc/smallstep/ca.json337ca # [7209090.945062] ca step-ca[204]: 2026/08/31 09:55:16 The primary server URL is https://ca.foo:1443338ca # [7209090.945062] ca step-ca[204]: 2026/08/31 09:55:16 Root certificates are available at https://ca.foo:1443/roots.pem339ca # [7209090.945062] ca step-ca[204]: 2026/08/31 09:55:16 X.509 Root Fingerprint: d8313f02428bf1dbd1c3ac697d9dbdb634b8b2133fa80e84a29326a25d92a16f340ca # [7209090.945835] ca systemd[1]: Started step-ca service.341ca # [7209090.946202] ca step-ca[204]: 2026/08/31 09:55:16 Serving HTTPS on 0.0.0.0:1443 ...342client # [7209091.076204] client systemd-networkd[182]: eth1: Gained IPv6LL343server # [7209091.608787] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/344server # [7209091.612103] server acme-test.foo-start[245]: + '[' -e out/acme-success ']'345server # [7209091.612103] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=346server # [7209091.623584] server acme-test.foo-start[255]: + cd test.foo347server # [7209091.623984] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem348server # [7209091.625100] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem'349server # [7209091.625330] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem350server # [7209091.626551] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem'351server # [7209091.626788] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem352server # [7209091.628602] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem353server # [7209091.630191] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem354server # [7209091.631732] server acme-test.foo-start[245]: + for fixpath in out certificates355server # [7209091.631757] server acme-test.foo-start[245]: + '[' -d out ']'356server # [7209091.631757] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out357server # [7209091.633515] server acme-test.foo-start[245]: + chown -R acme:nginx out358server # [7209091.636623] server acme-test.foo-start[245]: + for fixpath in out certificates359server # [7209091.636662] server acme-test.foo-start[245]: + '[' -d certificates ']'360server # [7209091.640474] server systemd[1]: Finished Ensure certificate for test.foo.361server # [7209091.643137] server systemd[1]: Starting Nginx Web Server...362ca # [7209091.852978] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/363ca # [7209091.856292] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']'364ca # [7209091.856398] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses=365ca # [7209091.868471] ca acme-ca.foo-start[291]: + cd ca.foo366ca # [7209091.869124] ca acme-ca.foo-start[291]: + cp -vp cert.pem ../out/cert.pem367ca # [7209091.870901] ca acme-ca.foo-start[292]: 'cert.pem' -> '../out/cert.pem'368ca # [7209091.871190] ca acme-ca.foo-start[291]: + cp -vp key.pem ../out/key.pem369ca # [7209091.872511] ca acme-ca.foo-start[291]: 'key.pem' -> '../out/key.pem'370ca # [7209091.872869] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem371ca # [7209091.874759] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem372ca # [7209091.876536] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem373ca # [7209091.878335] ca acme-ca.foo-start[256]: + for fixpath in out certificates374ca # [7209091.878382] ca acme-ca.foo-start[256]: + '[' -d out ']'375ca # [7209091.878382] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out376ca # [7209091.880142] ca acme-ca.foo-start[256]: + chown -R acme:nginx out377ca # [7209091.883099] ca acme-ca.foo-start[256]: + for fixpath in out certificates378ca # [7209091.883309] ca acme-ca.foo-start[256]: + '[' -d certificates ']'379ca # [7209091.889286] ca systemd[1]: Finished Ensure certificate for ca.foo.380ca # [7209091.892110] ca systemd[1]: Starting Nginx Web Server...381ca # [7209092.641245] ca nginx-pre-start[303]: nginx: the configuration file /nix/store/qvq6qxlf6qym8p85q6ss08zqvgy8h812-nginx.conf syntax is ok382ca # [7209092.641832] ca nginx-pre-start[303]: nginx: configuration file /nix/store/qvq6qxlf6qym8p85q6ss08zqvgy8h812-nginx.conf test is successful383ca # [7209092.648501] ca systemd[1]: Started Nginx Web Server.384ca # [7209092.649284] ca systemd[1]: Reached target Multi-User System.385ca # [7209092.651511] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...386server # [7209092.529357] server nginx-pre-start[267]: nginx: the configuration file /nix/store/jz7kmd1pqz9d3z4szhmwj70infw1zqg3-nginx.conf syntax is ok387server # [7209092.529720] server nginx-pre-start[267]: nginx: configuration file /nix/store/jz7kmd1pqz9d3z4szhmwj70infw1zqg3-nginx.conf test is successful388server # [7209092.552492] server systemd[1]: Started Nginx Web Server.389server # [7209092.553494] server systemd[1]: Reached target Multi-User System.390server # [7209092.555860] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...391server # [7209093.163734] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/392server # [7209093.166558] server acme-order-renew-test.foo-start[270]: + set -euo pipefail393server # [7209093.166635] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108394server # [7209093.166747] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt395server # [7209093.167840] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run396server # [7209093.191181] server acme-order-renew-test.foo-start[281]: 2026/08/31 09:55:19 No key found for account none@none.tld. Generating a P256 key.397server # [7209093.191532] server acme-order-renew-test.foo-start[281]: 2026/08/31 09:55:19 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key398ca # [7209093.281237] ca acme-order-renew-ca.foo-start[306]: Waiting to acquire lock in /run/acme/399ca # [7209093.283899] ca acme-order-renew-ca.foo-start[306]: + set -euo pipefail400ca # [7209093.283974] ca acme-order-renew-ca.foo-start[306]: + echo 88dc4fc401a6091a1bd9401ca # [7209093.284122] ca acme-order-renew-ca.foo-start[306]: + cmp -s domainhash.txt certificates/domainhash.txt402ca # [7209093.285166] ca acme-order-renew-ca.foo-start[306]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run403ca # [7209093.302027] ca acme-order-renew-ca.foo-start[317]: 2026/08/31 09:55:19 No key found for account none@none.tld. Generating a P256 key.404ca # [7209093.302347] ca acme-order-renew-ca.foo-start[317]: 2026/08/31 09:55:19 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key405ca # [7209093.334086] ca step-ca[204]: time="2026-08-31T09:55:19Z" level=info duration="86.281µs" duration-ns=86281 fields.time="2026-08-31T09:55:19Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=4c716785-c5fd-4eba-bbe5-1e90eda8d1a7 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=406ca # [7209093.334505] ca acme-order-renew-ca.foo-start[317]: 2026/08/31 09:55:19 [INFO] acme: Registering account for none@none.tld407ca # [7209093.348252] ca step-ca[204]: time="2026-08-31T09:55:19Z" level=info duration=13.60947ms duration-ns=13609470 fields.time="2026-08-31T09:55:19Z" method=HEAD name=ca nonce=WnJaTFlQNTEwVlYxa2RCdkszNEp6a3YzT2tBNTBwclQ path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=d89e317b-d3f7-4bf4-9d7a-759edf1a8957 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=408ca # [7209093.350528] ca step-ca[204]: time="2026-08-31T09:55:19Z" level=info duration=1.687904ms duration-ns=1687904 fields.time="2026-08-31T09:55:19Z" method=POST name=ca nonce=U3NaUElISjVkd1Z5S1FGTEZVakozNnh1YzY2V3NxcU4 path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=9538706b-01b4-4615-bbf1-004893af0a91 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/VjyaOSdmBJVCtapaBmhKT5ItID8NzXbD/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=409ca # [7209093.350831] ca acme-order-renew-ca.foo-start[317]: !!!! HEADS UP !!!!410ca # [7209093.350831] ca acme-order-renew-ca.foo-start[317]: Your account credentials have been saved in your411ca # [7209093.350831] ca acme-order-renew-ca.foo-start[317]: configuration directory at "accounts".412ca # [7209093.350831] ca acme-order-renew-ca.foo-start[317]: You should make a secure backup of this folder now. This413ca # [7209093.350831] ca acme-order-renew-ca.foo-start[317]: configuration directory will also contain private keys414ca # [7209093.350831] ca acme-order-renew-ca.foo-start[317]: generated by lego and certificates obtained from the ACME415ca # [7209093.350831] ca acme-order-renew-ca.foo-start[317]: server. Making regular backups of this folder is ideal.416ca # [7209093.350966] ca acme-order-renew-ca.foo-start[317]: 2026/08/31 09:55:19 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate417ca # [7209093.353734] ca step-ca[204]: time="2026-08-31T09:55:19Z" level=info duration=2.431074ms duration-ns=2431074 fields.time="2026-08-31T09:55:19Z" method=POST name=ca nonce=cFFMcm1RSXRSb3FONXZ0UllGSlNOdDJ3TXMwaWV4UEg path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=4fa6813b-71d2-4ea4-a0f9-96f6e93bdbeb response="{\"id\":\"DIW4olTKuEMHxF0MP7IFgkLkD00P5Mm1\",\"status\":\"pending\",\"expires\":\"2026-09-01T09:55:19Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-31T09:54:19Z\",\"notAfter\":\"2026-11-29T09:55:19Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/o0PkL5SbGDSzjLJZZgr3IdsXArYmhEkn\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/DIW4olTKuEMHxF0MP7IFgkLkD00P5Mm1/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=418ca # [7209093.413090] ca step-ca[204]: time="2026-08-31T09:55:19Z" level=info duration=2.16459ms duration-ns=2164590 fields.time="2026-08-31T09:55:19Z" method=POST name=ca nonce=ck1IVXRIeHpjcHM3THo0YzU5ajJSNzUxbEVscWY0dWo path=/acme/acme/authz/o0PkL5SbGDSzjLJZZgr3IdsXArYmhEkn protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=73b243b1-5d53-4b30-87ff-44d842a04603 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"gecVV3ZW6KCPcrRJa2zydcxi50VEB8qC\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/o0PkL5SbGDSzjLJZZgr3IdsXArYmhEkn/0QJH5iGmkinbrQcPh5bnDlN7MmG75ikB\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"gecVV3ZW6KCPcrRJa2zydcxi50VEB8qC\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/o0PkL5SbGDSzjLJZZgr3IdsXArYmhEkn/7qUt8Pw7D2DFdNi4LPXNLiunPjzmxjGU\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"gecVV3ZW6KCPcrRJa2zydcxi50VEB8qC\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/o0PkL5SbGDSzjLJZZgr3IdsXArYmhEkn/ecb0HK4iHo0sFFBhQC3kcNGVW1iFZOrz\"}],\"wildcard\":false,\"expires\":\"2026-09-01T09:55:19Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=419ca # [7209093.413402] ca acme-order-renew-ca.foo-start[317]: 2026/08/31 09:55:19 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/o0PkL5SbGDSzjLJZZgr3IdsXArYmhEkn420ca # [7209093.413402] ca acme-order-renew-ca.foo-start[317]: 2026/08/31 09:55:19 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01421ca # [7209093.413402] ca acme-order-renew-ca.foo-start[317]: 2026/08/31 09:55:19 [INFO] [ca.foo] acme: use http-01 solver422ca # [7209093.413486] ca acme-order-renew-ca.foo-start[317]: 2026/08/31 09:55:19 [INFO] [ca.foo] acme: Trying to solve HTTP-01423ca # [7209093.418185] ca step-ca[204]: time="2026-08-31T09:55:19Z" level=info duration=4.28794ms duration-ns=4287940 fields.time="2026-08-31T09:55:19Z" method=POST name=ca nonce=N2F5ZkQ3UW9sVlNIM2hqVjRveVVjNHVTbHExNUJQUjM path=/acme/acme/challenge/o0PkL5SbGDSzjLJZZgr3IdsXArYmhEkn/7qUt8Pw7D2DFdNi4LPXNLiunPjzmxjGU protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=f78c6d11-bcb2-4fa5-a43a-feb86548e775 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"gecVV3ZW6KCPcrRJa2zydcxi50VEB8qC\",\"validated\":\"2026-08-31T09:55:19Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/o0PkL5SbGDSzjLJZZgr3IdsXArYmhEkn/7qUt8Pw7D2DFdNi4LPXNLiunPjzmxjGU\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=424ca # [7209093.418496] ca acme-order-renew-ca.foo-start[317]: 2026/08/31 09:55:19 [INFO] [ca.foo] The server validated our request425ca # [7209093.418588] ca acme-order-renew-ca.foo-start[317]: 2026/08/31 09:55:19 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates426ca # [7209093.426052] ca step-ca[204]: time="2026-08-31T09:55:19Z" level=info duration=6.021884ms duration-ns=6021884 fields.time="2026-08-31T09:55:19Z" method=POST name=ca nonce=TGFVYUZ0TnJrNVJGcEFQUUxjczV0RndNZmhTU3J2ZUs path=/acme/acme/order/DIW4olTKuEMHxF0MP7IFgkLkD00P5Mm1/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=eed50ed0-b0d6-47ba-8108-b8d59d5cab90 response="{\"id\":\"DIW4olTKuEMHxF0MP7IFgkLkD00P5Mm1\",\"status\":\"valid\",\"expires\":\"2026-09-01T09:55:19Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-31T09:54:19Z\",\"notAfter\":\"2026-11-29T09:55:19Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/o0PkL5SbGDSzjLJZZgr3IdsXArYmhEkn\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/DIW4olTKuEMHxF0MP7IFgkLkD00P5Mm1/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/8s0jCHdTRhHt8Cq7VxVmCJLB5SIZ7qsX\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=427ca # [7209093.428596] ca step-ca[204]: time="2026-08-31T09:55:19Z" level=info certificate="MIIB1DCCAXmgAwIBAgIQDm76MBppEuPVDPOhjxGZazAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MzEwOTU0MTlaFw0yNjExMjkwOTU1MTlaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABAsu2MXZdattXSk3ZyPdce0Ffe8NHtKqtZY0F4ZEDVO/adg3KA9dUudFn3hVYpfq2MmrBDd9wQHsHnsZtDb0zYKjgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUMntSW1XeiSdcpTb+kR0MWxGJPTswHwYDVR0jBBgwFoAUfhxJ9/ma1l0Dp91a/5v5pz7xYscwEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNJADBGAiEAuZpPYTmdwqgfHi+NmUD5cvGQEgjyPsezL0QyFr31/igCIQDhyhKXkYCdvyuVFKszs4Q//jLzbn6VlYVnIaIv3i3+Yg==" duration=1.674703ms duration-ns=1674703 fields.time="2026-08-31T09:55:19Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=bGRHbU44b25PT2NKY2M0dTlUQXFTSGlrb2VQWG9NVVA path=/acme/acme/certificate/8s0jCHdTRhHt8Cq7VxVmCJLB5SIZ7qsX protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=5a220237-c855-4fbb-9069-38e512e40cb6 sans="map[dns:[ca.foo]]" serial=19185419008954003533859862083955431787 size=1348 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-31T09:54:19Z" valid-to="2026-11-29T09:55:19Z"428ca # [7209093.428858] ca acme-order-renew-ca.foo-start[317]: 2026/08/31 09:55:19 [INFO] [ca.foo] Server responded with a certificate.429ca # [7209093.433958] ca acme-order-renew-ca.foo-start[306]: + mv domainhash.txt certificates/430ca # [7209093.435653] ca acme-order-renew-ca.foo-start[306]: + touch out/acme-success431ca # [7209093.437252] ca acme-order-renew-ca.foo-start[306]: + cmp -s certificates/ca.foo.crt out/fullchain.pem432ca # [7209093.438649] ca acme-order-renew-ca.foo-start[306]: + touch out/renewed433ca # [7209093.440300] ca acme-order-renew-ca.foo-start[306]: + echo Installing new certificate434ca # [7209093.440300] ca acme-order-renew-ca.foo-start[306]: Installing new certificate435ca # [7209093.440340] ca acme-order-renew-ca.foo-start[306]: + cp -vp certificates/ca.foo.crt out/fullchain.pem436ca # [7209093.442870] ca acme-order-renew-ca.foo-start[350]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem'437ca # [7209093.443219] ca acme-order-renew-ca.foo-start[306]: + cp -vp certificates/ca.foo.key out/key.pem438ca # [7209093.444748] ca acme-order-renew-ca.foo-start[351]: 'certificates/ca.foo.key' -> 'out/key.pem'439ca # [7209093.444970] ca acme-order-renew-ca.foo-start[306]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem440ca # [7209093.446550] ca acme-order-renew-ca.foo-start[352]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem'441ca # [7209093.446787] ca acme-order-renew-ca.foo-start[306]: + ln -sf fullchain.pem out/cert.pem442ca # [7209093.448201] ca acme-order-renew-ca.foo-start[306]: + cat out/key.pem out/fullchain.pem443ca # [7209093.451004] ca acme-order-renew-ca.foo-start[306]: + for fixpath in out certificates444ca # [7209093.451025] ca acme-order-renew-ca.foo-start[306]: + '[' -d out ']'445ca # [7209093.451025] ca acme-order-renew-ca.foo-start[306]: + chmod -R u=rwX,g=rX,o= out446ca # [7209093.452537] ca acme-order-renew-ca.foo-start[306]: + chown -R acme:nginx out447ca # [7209093.455328] ca acme-order-renew-ca.foo-start[306]: + for fixpath in out certificates448ca # [7209093.455356] ca acme-order-renew-ca.foo-start[306]: + '[' -d certificates ']'449ca # [7209093.455356] ca acme-order-renew-ca.foo-start[306]: + chmod -R u=rwX,g=rX,o= certificates450ca # [7209093.457665] ca acme-order-renew-ca.foo-start[306]: + chown -R acme:nginx certificates451ca # [7209093.460151] ca acme-order-renew-ca.foo-start[306]: + chmod -R u=rwX,g=,o= accounts/.452ca # [7209093.613111] ca systemd[1]: Reloading Nginx Web Server...453ca # [7209093.617383] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.454ca # [7209093.617600] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.455ca # [7209094.349113] ca nginx[368]: nginx: the configuration file /nix/store/qvq6qxlf6qym8p85q6ss08zqvgy8h812-nginx.conf syntax is ok456ca # [7209094.349871] ca nginx[368]: nginx: configuration file /nix/store/qvq6qxlf6qym8p85q6ss08zqvgy8h812-nginx.conf test is successful457server # [7209094.417857] server acme-order-renew-test.foo-start[281]: 2026/08/31 09:55:20 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 2 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority458server # [7209094.425275] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.459server # [7209094.425275] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.460server # [7209094.425275] server acme-order-renew-test.foo-start[270]: + exit 10461server # [7209094.429874] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a462server # [7209094.429981] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'.463server # [7209094.430247] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo.464server # [7209094.431004] server systemd[1]: Startup finished in 6.305s.465ca # [7209095.021284] ca systemd[1]: Reloaded Nginx Web Server.466ca # [7209095.021784] ca systemd[1]: Startup finished in 6.882s.467ca # [7209095.317061] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...468ca # [7209096.085144] ca acme-order-renew-ca.foo-start[383]: Waiting to acquire lock in /run/acme/469ca # [7209096.088636] ca acme-order-renew-ca.foo-start[383]: + set -euo pipefail470ca # [7209096.088714] ca acme-order-renew-ca.foo-start[383]: + echo 88dc4fc401a6091a1bd9471ca # [7209096.088833] ca acme-order-renew-ca.foo-start[383]: + cmp -s domainhash.txt certificates/domainhash.txt472ca # [7209096.089910] ca acme-order-renew-ca.foo-start[383]: + '[' -e certificates/ca.foo.key ']'473ca # [7209096.089935] ca acme-order-renew-ca.foo-start[383]: + '[' -e certificates/ca.foo.crt ']'474ca # [7209096.090480] ca acme-order-renew-ca.foo-start[391]: ++ find accounts -name none@none.tld.key475ca # [7209096.093363] ca acme-order-renew-ca.foo-start[383]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']'476ca # [7209096.093425] ca acme-order-renew-ca.foo-start[383]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic477ca # [7209096.142305] ca step-ca[204]: time="2026-08-31T09:55:22Z" level=info duration="60.921µs" duration-ns=60921 fields.time="2026-08-31T09:55:22Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=14b7a554-c6e7-40d5-8b19-25c8771194f5 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=478ca # [7209096.142746] ca acme-order-renew-ca.foo-start[392]: 2026/08/31 09:55:22 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint479ca # [7209096.142972] ca acme-order-renew-ca.foo-start[392]: 2026/08/31 09:55:22 [INFO] [ca.foo] The certificate expires at 2026-11-29T09:55:19Z, the renewal can be performed in 1439h59m36.804074598s: no renewal.480ca # [7209096.143487] ca acme-order-renew-ca.foo-start[383]: + mv domainhash.txt certificates/481ca # [7209096.145269] ca acme-order-renew-ca.foo-start[383]: + touch out/acme-success482ca # [7209096.147281] ca acme-order-renew-ca.foo-start[383]: + cmp -s certificates/ca.foo.crt out/fullchain.pem483ca # [7209096.148646] ca acme-order-renew-ca.foo-start[383]: + for fixpath in out certificates484ca # [7209096.148674] ca acme-order-renew-ca.foo-start[383]: + '[' -d out ']'485ca # [7209096.148674] ca acme-order-renew-ca.foo-start[383]: + chmod -R u=rwX,g=rX,o= out486ca # [7209096.150435] ca acme-order-renew-ca.foo-start[383]: + chown -R acme:nginx out487ca # [7209096.153617] ca acme-order-renew-ca.foo-start[383]: + for fixpath in out certificates488ca # [7209096.153638] ca acme-order-renew-ca.foo-start[383]: + '[' -d certificates ']'489ca # [7209096.153655] ca acme-order-renew-ca.foo-start[383]: + chmod -R u=rwX,g=rX,o= certificates490ca # [7209096.155482] ca acme-order-renew-ca.foo-start[383]: + chown -R acme:nginx certificates491ca # [7209096.158609] ca acme-order-renew-ca.foo-start[383]: + chmod -R u=rwX,g=,o= accounts/.492ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 5.70 seconds)493ca # [7209096.341229] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.494ca # [7209096.360288] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.495server: must succeed: systemctl restart acme-test.foo.service496server # [7209099.380955] server systemd[1]: acme-test.foo.service: Deactivated successfully.497server # [7209099.381157] server systemd[1]: Stopped Ensure certificate for test.foo.498server # [7209099.382005] server systemd[1]: Stopping Ensure certificate for test.foo...499server # [7209099.383761] server systemd[1]: Starting Ensure certificate for test.foo...500server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.65 seconds)501client: waiting for success: curl -v https://test.foo502* Host test.foo:443 was resolved.503* IPv6: 2001:db8:1::3504* IPv4: 192.168.1.3505* Trying [2001:db8:1::3]:443...506* ALPN: curl offers h2,http/1.1507} [5 bytes data]508* TLSv1.3 (OUT), TLS handshake, Client hello (1):509} [1552 bytes data]510* SSL Trust Anchors:511* OpenSSL default paths (fallback)512{ [5 bytes data]513* TLSv1.3 (IN), TLS handshake, Server hello (2):514{ [1210 bytes data]515* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):516{ [1 bytes data]517* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):518{ [19 bytes data]519* TLSv1.3 (IN), TLS handshake, Certificate (11):520{ [1010 bytes data]521* TLSv1.3 (IN), TLS handshake, CERT verify (15):522{ [110 bytes data]523* TLSv1.3 (IN), TLS handshake, Finished (20):524{ [52 bytes data]525* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):526} [1 bytes data]527* TLSv1.3 (OUT), TLS handshake, Finished (20):528} [52 bytes data]529* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey530* ALPN: server accepted h2531* Server certificate:532* subject: CN=test.foo533* start date: Aug 31 09:55:17 2026 GMT534* expire date: Sep 30 09:55:17 2028 GMT535* issuer: CN=minica root ca 5a0880536* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384537* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384538* subjectAltName: "test.foo" matches cert's "test.foo"539* OpenSSL verify result: 13540* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)541* closing connection #0542curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)543More details here: https://curl.se/docs/sslcerts.html544545curl failed to verify the legitimacy of the server and therefore could not546establish a secure connection to it. To learn more about this situation and547how to fix it, please visit the webpage mentioned above.548server # [7209099.989820] server acme-test.foo-start[315]: Waiting to acquire lock in /run/acme/549server # [7209099.992337] server acme-test.foo-start[315]: + '[' -e out/acme-success ']'550server # [7209099.992337] server acme-test.foo-start[315]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=551server # [7209100.003045] server acme-test.foo-start[325]: + cd test.foo552server # [7209100.003646] server acme-test.foo-start[325]: + cp -vp cert.pem ../out/cert.pem553server # [7209100.004870] server acme-test.foo-start[326]: 'cert.pem' -> '../out/cert.pem'554server # [7209100.005203] server acme-test.foo-start[325]: + cp -vp key.pem ../out/key.pem555server # [7209100.006900] server acme-test.foo-start[325]: 'key.pem' -> '../out/key.pem'556server # [7209100.007173] server acme-test.foo-start[315]: + cat out/cert.pem ca/cert.pem557server # [7209100.008712] server acme-test.foo-start[315]: + cp ca/cert.pem out/chain.pem558server # [7209100.010192] server acme-test.foo-start[315]: + cat out/key.pem out/fullchain.pem559server # [7209100.011676] server acme-test.foo-start[315]: + for fixpath in out certificates560server # [7209100.011676] server acme-test.foo-start[315]: + '[' -d out ']'561server # [7209100.011786] server acme-test.foo-start[315]: + chmod -R u=rwX,g=rX,o= out562server # [7209100.013080] server acme-test.foo-start[315]: + chown -R acme:nginx out563server # [7209100.015871] server acme-test.foo-start[315]: + for fixpath in out certificates564server # [7209100.015871] server acme-test.foo-start[315]: + '[' -d certificates ']'565server # [7209100.019784] server systemd[1]: Finished Ensure certificate for test.foo.566server # [7209100.024959] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...567server # [7209100.594815] server acme-order-renew-test.foo-start[333]: Waiting to acquire lock in /run/acme/568server # [7209100.597487] server acme-order-renew-test.foo-start[333]: + set -euo pipefail569server # [7209100.597562] server acme-order-renew-test.foo-start[333]: + echo ad12aa6741ce4bd2c108570server # [7209100.597674] server acme-order-renew-test.foo-start[333]: + cmp -s domainhash.txt certificates/domainhash.txt571server # [7209100.599123] server acme-order-renew-test.foo-start[333]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run572server # [7209100.648343] server acme-order-renew-test.foo-start[341]: 2026/08/31 09:55:26 [INFO] acme: Registering account for none@none.tld573server # [7209100.658703] server acme-order-renew-test.foo-start[341]: !!!! HEADS UP !!!!574server # [7209100.658703] server acme-order-renew-test.foo-start[341]: Your account credentials have been saved in your575server # [7209100.658703] server acme-order-renew-test.foo-start[341]: configuration directory at "accounts".576server # [7209100.658703] server acme-order-renew-test.foo-start[341]: You should make a secure backup of this folder now. This577server # [7209100.658703] server acme-order-renew-test.foo-start[341]: configuration directory will also contain private keys578server # [7209100.658703] server acme-order-renew-test.foo-start[341]: generated by lego and certificates obtained from the ACME579server # [7209100.658703] server acme-order-renew-test.foo-start[341]: server. Making regular backups of this folder is ideal.580server # [7209100.658886] server acme-order-renew-test.foo-start[341]: 2026/08/31 09:55:26 [INFO] [test.foo] acme: Obtaining bundled SAN certificate581server # [7209100.729077] server acme-order-renew-test.foo-start[341]: 2026/08/31 09:55:26 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/AOwtGYstzKtEhdaVOtBe1BCCywhHhj5r582server # [7209100.729077] server acme-order-renew-test.foo-start[341]: 2026/08/31 09:55:26 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01583server # [7209100.729077] server acme-order-renew-test.foo-start[341]: 2026/08/31 09:55:26 [INFO] [test.foo] acme: use http-01 solver584server # [7209100.729077] server acme-order-renew-test.foo-start[341]: 2026/08/31 09:55:26 [INFO] [test.foo] acme: Trying to solve HTTP-01585server # [7209100.737860] server acme-order-renew-test.foo-start[341]: 2026/08/31 09:55:26 [INFO] [test.foo] The server validated our request586server # [7209100.737946] server acme-order-renew-test.foo-start[341]: 2026/08/31 09:55:26 [INFO] [test.foo] acme: Validations succeeded; requesting certificates587server # [7209100.755525] server acme-order-renew-test.foo-start[341]: 2026/08/31 09:55:26 [INFO] [test.foo] Server responded with a certificate.588server # [7209100.760089] server acme-order-renew-test.foo-start[333]: + mv domainhash.txt certificates/589server # [7209100.762515] server acme-order-renew-test.foo-start[333]: + touch out/acme-success590server # [7209100.765026] server acme-order-renew-test.foo-start[333]: + cmp -s certificates/test.foo.crt out/fullchain.pem591server # [7209100.766286] server acme-order-renew-test.foo-start[333]: + touch out/renewed592server # [7209100.768009] server acme-order-renew-test.foo-start[333]: + echo Installing new certificate593server # [7209100.768042] server acme-order-renew-test.foo-start[333]: Installing new certificate594server # [7209100.768042] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.crt out/fullchain.pem595server # [7209100.769659] server acme-order-renew-test.foo-start[372]: 'certificates/test.foo.crt' -> 'out/fullchain.pem'596server # [7209100.769919] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.key out/key.pem597server # [7209100.771422] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.key' -> 'out/key.pem'598server # [7209100.771669] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem599server # [7209100.773188] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem'600server # [7209100.773437] server acme-order-renew-test.foo-start[333]: + ln -sf fullchain.pem out/cert.pem601server # [7209100.775241] server acme-order-renew-test.foo-start[333]: + cat out/key.pem out/fullchain.pem602server # [7209100.777120] server acme-order-renew-test.foo-start[333]: + for fixpath in out certificates603server # [7209100.777168] server acme-order-renew-test.foo-start[333]: + '[' -d out ']'604server # [7209100.777168] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=rX,o= out605server # [7209100.778914] server acme-order-renew-test.foo-start[333]: + chown -R acme:nginx out606server # [7209100.782319] server acme-order-renew-test.foo-start[333]: + for fixpath in out certificates607server # [7209100.782370] server acme-order-renew-test.foo-start[333]: + '[' -d certificates ']'608server # [7209100.782370] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=rX,o= certificates609server # [7209100.784163] server acme-order-renew-test.foo-start[333]: + chown -R acme:nginx certificates610server # [7209100.787075] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=,o= accounts/.611ca # [7209100.647800] ca step-ca[204]: time="2026-08-31T09:55:26Z" level=info duration="65.481µs" duration-ns=65481 fields.time="2026-08-31T09:55:26Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=677027c5-6fb0-41a6-9141-5974b59d5cc3 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=612ca # [7209100.652448] ca step-ca[204]: time="2026-08-31T09:55:26Z" level=info duration="568.368µs" duration-ns=568368 fields.time="2026-08-31T09:55:26Z" method=HEAD name=ca nonce=NjZmRXRDcmhiUXZFamxuTWtZQ0w1a3BOZFlhV0p5RzA path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=fcfdfafb-fe84-456d-b09b-57acd3db4a64 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=613ca # [7209100.657620] ca step-ca[204]: time="2026-08-31T09:55:26Z" level=info duration=2.480034ms duration-ns=2480034 fields.time="2026-08-31T09:55:26Z" method=POST name=ca nonce=RjlqMzhtaDlYZWV5SFlmMFNtaTRYQnZjWjhuaUhSMU0 path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=298e68b5-4907-414f-b097-0cfa43a829b7 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/fZ3F59ENbftE23Bo6hAb3HTkFr8dYOOc/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=614ca # [7209100.665533] ca step-ca[204]: time="2026-08-31T09:55:26Z" level=info duration=4.185738ms duration-ns=4185738 fields.time="2026-08-31T09:55:26Z" method=POST name=ca nonce=dHZ1QXZFRExhTmVwZ29EQ2ZnQnpzeWszbVJzMW1aczg path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=749c4434-2a60-4fe3-8821-b8aeedcaa51b response="{\"id\":\"AfWrZghlIib4gxrogpBAYCZE7h4vP9aC\",\"status\":\"pending\",\"expires\":\"2026-09-01T09:55:26Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-31T09:54:26Z\",\"notAfter\":\"2026-11-29T09:55:26Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/AOwtGYstzKtEhdaVOtBe1BCCywhHhj5r\"],\"finalize\":\"https://ca.foo/acme/acme/order/AfWrZghlIib4gxrogpBAYCZE7h4vP9aC/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=615ca # [7209100.728395] ca step-ca[204]: time="2026-08-31T09:55:26Z" level=info duration=3.846333ms duration-ns=3846333 fields.time="2026-08-31T09:55:26Z" method=POST name=ca nonce=YkhKb3BnMVgxWkVGY0NTMGxkSEZUY09WZWVva3VZcFc path=/acme/acme/authz/AOwtGYstzKtEhdaVOtBe1BCCywhHhj5r protocol=HTTP/1.1 referer= remote-address="::1" request-id=505d9644-3495-4697-aa08-8400743f3af2 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"fuO9HDMrFR7P6Li7ULZyXo4JVvD9UobG\",\"url\":\"https://ca.foo/acme/acme/challenge/AOwtGYstzKtEhdaVOtBe1BCCywhHhj5r/TNeLw0yrnhIWNWbU6FZbNk1yNnJ854Mp\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"fuO9HDMrFR7P6Li7ULZyXo4JVvD9UobG\",\"url\":\"https://ca.foo/acme/acme/challenge/AOwtGYstzKtEhdaVOtBe1BCCywhHhj5r/XtbMy3siRl22EGUNUkB1FLMFaCS63a6x\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"fuO9HDMrFR7P6Li7ULZyXo4JVvD9UobG\",\"url\":\"https://ca.foo/acme/acme/challenge/AOwtGYstzKtEhdaVOtBe1BCCywhHhj5r/EtkTJkhTpiKpdhVvr0D3VGMadXC2fYhg\"}],\"wildcard\":false,\"expires\":\"2026-09-01T09:55:26Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=616ca # [7209100.737035] ca step-ca[204]: time="2026-08-31T09:55:26Z" level=info duration=4.651585ms duration-ns=4651585 fields.time="2026-08-31T09:55:26Z" method=POST name=ca nonce=SWFNbHBkR2ZrQ216TTRBWVpScVE0dUczSGZ0dzA1MEk path=/acme/acme/challenge/AOwtGYstzKtEhdaVOtBe1BCCywhHhj5r/XtbMy3siRl22EGUNUkB1FLMFaCS63a6x protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=f107d1e7-54cf-43f0-9f80-84011c4842dd response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"fuO9HDMrFR7P6Li7ULZyXo4JVvD9UobG\",\"validated\":\"2026-08-31T09:55:26Z\",\"url\":\"https://ca.foo/acme/acme/challenge/AOwtGYstzKtEhdaVOtBe1BCCywhHhj5r/XtbMy3siRl22EGUNUkB1FLMFaCS63a6x\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=617ca # [7209100.749666] ca step-ca[204]: time="2026-08-31T09:55:26Z" level=info duration=8.129953ms duration-ns=8129953 fields.time="2026-08-31T09:55:26Z" method=POST name=ca nonce=Y3lUajNuZm10cEthbVhycHdWWWN1bHN1RXZNUVlIdnE path=/acme/acme/order/AfWrZghlIib4gxrogpBAYCZE7h4vP9aC/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=f9054ad1-f429-40e6-9469-e5d205a88865 response="{\"id\":\"AfWrZghlIib4gxrogpBAYCZE7h4vP9aC\",\"status\":\"valid\",\"expires\":\"2026-09-01T09:55:26Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-31T09:54:26Z\",\"notAfter\":\"2026-11-29T09:55:26Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/AOwtGYstzKtEhdaVOtBe1BCCywhHhj5r\"],\"finalize\":\"https://ca.foo/acme/acme/order/AfWrZghlIib4gxrogpBAYCZE7h4vP9aC/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/42ljmGCXaNCufkYL5brjlqyQhVFfHM4c\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=618ca # [7209100.755068] ca step-ca[204]: time="2026-08-31T09:55:26Z" level=info certificate="MIIB1zCCAX2gAwIBAgIQHOy1J9SYtH8fw6LONQFtHDAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MzEwOTU0MjZaFw0yNjExMjkwOTU1MjZaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAErH/aZfD5MJw2Ae+YBSQDAPk/uDBHk69X2bkdDZpZQiAY0Ku/sHOIYRI4zniRaVs1jnzelIqi4fGp3mQUNsp8OKOBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBRTHMU3LJSc8Rg6NZHZ6g3MTa/nIjAfBgNVHSMEGDAWgBR+HEn3+ZrWXQOn3Vr/m/mnPvFixzATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSAAwRQIgXa845wAgvyLRTfg/upms10et1g0WP3YwtxYOTBDd9TQCIQCnFJxJxU2WtrU01syVl+7F8eY4FIA/81B5F/Hc8dCv1w==" duration=2.090149ms duration-ns=2090149 fields.time="2026-08-31T09:55:26Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=Q2VZNFkxbUZTczhYQ253eHF0RG5wV3pqTzJCeG1GdFI path=/acme/acme/certificate/42ljmGCXaNCufkYL5brjlqyQhVFfHM4c protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=f6362510-92c4-4e6e-9305-3f0e60043f8c sans="map[dns:[test.foo]]" serial=38447440212423893947994539565873458460 size=1352 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-31T09:54:26Z" valid-to="2026-11-29T09:55:26Z"619* Host test.foo:443 was resolved.620* IPv6: 2001:db8:1::3621* IPv4: 192.168.1.3622* Trying [2001:db8:1::3]:443...623* ALPN: curl offers h2,http/1.1624} [5 bytes data]625* TLSv1.3 (OUT), TLS handshake, Client hello (1):626} [1552 bytes data]627* SSL Trust Anchors:628* OpenSSL default paths (fallback)629{ [5 bytes data]630* TLSv1.3 (IN), TLS handshake, Server hello (2):631{ [1210 bytes data]632* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):633{ [1 bytes data]634* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):635{ [19 bytes data]636* TLSv1.3 (IN), TLS handshake, Certificate (11):637{ [1010 bytes data]638* TLSv1.3 (IN), TLS handshake, CERT verify (15):639{ [111 bytes data]640* TLSv1.3 (IN), TLS handshake, Finished (20):641{ [52 bytes data]642* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):643} [1 bytes data]644* TLSv1.3 (OUT), TLS handshake, Finished (20):645} [52 bytes data]646* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey647* ALPN: server accepted h2648* Server certificate:649* subject: CN=test.foo650* start date: Aug 31 09:55:17 2026 GMT651* expire date: Sep 30 09:55:17 2028 GMT652* issuer: CN=minica root ca 5a0880653* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384654* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384655* subjectAltName: "test.foo" matches cert's "test.foo"656* OpenSSL verify result: 13657* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)658* closing connection #0659curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)660More details here: https://curl.se/docs/sslcerts.html661662curl failed to verify the legitimacy of the server and therefore could not663establish a secure connection to it. To learn more about this situation and664how to fix it, please visit the webpage mentioned above.665server # [7209100.985544] server systemd[1]: Reloading Nginx Web Server...666server # [7209100.989977] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully.667server # [7209100.990199] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo.668server # [7209101.544667] server nginx[390]: nginx: the configuration file /nix/store/jz7kmd1pqz9d3z4szhmwj70infw1zqg3-nginx.conf syntax is ok669server # [7209101.545256] server nginx[390]: nginx: configuration file /nix/store/jz7kmd1pqz9d3z4szhmwj70infw1zqg3-nginx.conf test is successful670* Host test.foo:443 was resolved.671* IPv6: 2001:db8:1::3672* IPv4: 192.168.1.3673* Trying [2001:db8:1::3]:443...674* ALPN: curl offers h2,http/1.1675} [5 bytes data]676* TLSv1.3 (OUT), TLS handshake, Client hello (1):677} [1552 bytes data]678* SSL Trust Anchors:679* OpenSSL default paths (fallback)680{ [5 bytes data]681* TLSv1.3 (IN), TLS handshake, Server hello (2):682{ [1210 bytes data]683* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):684{ [1 bytes data]685* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):686{ [19 bytes data]687* TLSv1.3 (IN), TLS handshake, Certificate (11):688{ [1010 bytes data]689* TLSv1.3 (IN), TLS handshake, CERT verify (15):690{ [110 bytes data]691* TLSv1.3 (IN), TLS handshake, Finished (20):692{ [52 bytes data]693* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):694} [1 bytes data]695* TLSv1.3 (OUT), TLS handshake, Finished (20):696} [52 bytes data]697* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey698* ALPN: server accepted h2699* Server certificate:700* subject: CN=test.foo701* start date: Aug 31 09:55:17 2026 GMT702* expire date: Sep 30 09:55:17 2028 GMT703* issuer: CN=minica root ca 5a0880704* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384705* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384706* subjectAltName: "test.foo" matches cert's "test.foo"707* OpenSSL verify result: 13708* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)709* closing connection #0710curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)711More details here: https://curl.se/docs/sslcerts.html712713curl failed to verify the legitimacy of the server and therefore could not714establish a secure connection to it. To learn more about this situation and715how to fix it, please visit the webpage mentioned above.716server # [7209102.160553] server systemd[1]: Reloaded Nginx Web Server.717* Host test.foo:443 was resolved.718* IPv6: 2001:db8:1::3719* IPv4: 192.168.1.3720* Trying [2001:db8:1::3]:443...721* ALPN: curl offers h2,http/1.1722} [5 bytes data]723* TLSv1.3 (OUT), TLS handshake, Client hello (1):724} [1552 bytes data]725* SSL Trust Anchors:726* OpenSSL default paths (fallback)727{ [5 bytes data]728* TLSv1.3 (IN), TLS handshake, Server hello (2):729{ [1210 bytes data]730* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):731{ [1 bytes data]732* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):733{ [19 bytes data]734* TLSv1.3 (IN), TLS handshake, Certificate (11):735{ [932 bytes data]736* TLSv1.3 (IN), TLS handshake, CERT verify (15):737{ [78 bytes data]738* TLSv1.3 (IN), TLS handshake, Finished (20):739{ [52 bytes data]740* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):741} [1 bytes data]742* TLSv1.3 (OUT), TLS handshake, Finished (20):743} [52 bytes data]744* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey745* ALPN: server accepted h2746* Server certificate:747* subject: CN=test.foo748* start date: Aug 31 09:54:26 2026 GMT749* expire date: Nov 29 09:55:26 2026 GMT750* issuer: CN=Clan Intermediate CA751* Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256752* Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256753* Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256754* subjectAltName: "test.foo" matches cert's "test.foo"755* OpenSSL verify result: 0756* SSL certificate verified via OpenSSL.757* Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 43398 758 % Total % Received % Xferd Average Speed Time Time Time Current759 Dload Upload Total Spent Left Speed760 0 0 0 0 0 0 0 0 0* using HTTP/2761* [HTTP/2] [1] OPENED stream for https://test.foo/762* [HTTP/2] [1] [:method: GET]763* [HTTP/2] [1] [:scheme: https]764* [HTTP/2] [1] [:authority: test.foo]765* [HTTP/2] [1] [:path: /]766* [HTTP/2] [1] [user-agent: curl/8.21.0]767* [HTTP/2] [1] [accept: */*]768} [5 bytes data]769770771772773774* Request completely sent off775{ [5 bytes data]776* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):777{ [265 bytes data]778* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):779{ [265 bytes data]780781782783784785786787{ [5 bytes data]788100 20 100 20 0 0 631 0 0789* Connection #0 to host test.foo:443 left intact790client: (finished: waiting for success: curl -v https://test.foo, in 3.21 seconds)791client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2792Certificate:793 Data:794 Version: 3 (0x2)795 Serial Number:796 1c:ec:b5:27:d4:98:b4:7f:1f:c3:a2:ce:35:01:6d:1c797 Signature Algorithm: ecdsa-with-SHA256798 Issuer: CN=Clan Intermediate CA799 Validity800 Not Before: Aug 31 09:54:26 2026 GMT801 Not After : Nov 29 09:55:26 2026 GMT802 Subject: CN=test.foo803 Subject Public Key Info:804 Public Key Algorithm: id-ecPublicKey805 Public-Key: (256 bit)806 pub:807 04:ac:7f:da:65:f0:f9:30:9c:36:01:ef:98:05:24:808 03:00:f9:3f:b8:30:47:93:af:57:d9:b9:1d:0d:9a:809 59:42:20:18:d0:ab:bf:b0:73:88:61:12:38:ce:78:810 91:69:5b:35:8e:7c:de:94:8a:a2:e1:f1:a9:de:64:811 14:36:ca:7c:38812 ASN1 OID: prime256v1813 NIST CURVE: P-256814 X509v3 extensions:815 X509v3 Key Usage: critical816 Digital Signature817 X509v3 Extended Key Usage: 818 TLS Web Server Authentication, TLS Web Client Authentication819 X509v3 Subject Key Identifier: 820 53:1C:C5:37:2C:94:9C:F1:18:3A:35:91:D9:EA:0D:CC:4D:AF:E7:22821 X509v3 Authority Key Identifier: 822 7E:1C:49:F7:F9:9A:D6:5D:03:A7:DD:5A:FF:9B:F9:A7:3E:F1:62:C7823 X509v3 Subject Alternative Name: 824 DNS:test.foo825 1.3.6.1.4.1.37476.9000.64.1: 826 0......acme..827 Signature Algorithm: ecdsa-with-SHA256828 Signature Value:829 30:45:02:20:5d:af:38:e7:00:20:bf:22:d1:4d:f8:3f:ba:99:830 ac:d7:47:ad:d6:0d:16:3f:76:30:b7:16:0e:4c:10:dd:f5:34:831 02:21:00:a7:14:9c:49:c5:4d:96:b6:b5:34:d6:cc:95:97:ee:832 c5:f1:e6:38:14:80:3f:f3:50:79:17:f1:dc:f1:d0:af:d7833client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2, in 0.17 seconds)834(finished: run the VM test script, in 15.74 seconds)835test script finished in 15.77s836cleanup837kill NspawnMachine (pid 53)838kill NspawnMachine (pid 54)839Container ca terminated by signal KILL.840kill NspawnMachine (pid 55)841Container client terminated by signal KILL.842Container server terminated by signal KILL.843(finished: cleanup, in 0.54 seconds)