container-test-run-certificates
checks.aarch64-linux.certificates
· build #549
· raw
1Machine state will be reset. To keep it, pass --keep-machine-state2start all VLans3(finished: start all VLans, in 0.00 seconds)45Test will time out and terminate in 3600.0 seconds6run the VM test script7additionally exposed symbols:8 ca, client, server,9 vlan1,10 start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh11start all VMs12client: systemd-nspawn running (pid 54)13ca: systemd-nspawn running (pid 53)14server: systemd-nspawn running (pid 55)15client: Waiting for journal at /build/vm-state-client/var/log/journal...16ca: Waiting for journal at /build/vm-state-ca/var/log/journal...17server: Waiting for journal at /build/vm-state-server/var/log/journal...18(finished: start all VMs, in 0.00 seconds)19nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE20nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.21nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE22nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.23nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE24nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.25Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.26Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.27Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.28░ Spawning container server on /build/vm-state-server.29░ Spawning container client on /build/vm-state-client.30░ Spawning container ca on /build/vm-state-ca.31ca # [7346534.949225] ca systemd-journald[78]: Journal started32ca # [7346534.949284] ca systemd-journald[78]: Runtime Journal (/run/log/journal/be580ce3434e4396b1d36119bc9d5f8a) is 8M, max 2.5G, 2.4G free.33ca # [7346534.953666] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully.34ca # [7346534.961918] ca systemd[1]: Starting Flush Journal to Persistent Storage...35client # [7346534.953143] client systemd-journald[69]: Journal started36ca # [7346534.962754] ca systemd[1]: Starting Network Name Resolution...37client # [7346534.953210] client systemd-journald[69]: Runtime Journal (/run/log/journal/84e730bf37bf4b09b31ba71b4ba571fa) is 8M, max 2.5G, 2.4G free.38ca # [7346534.963545] ca systemd[1]: Starting Create Static Device Nodes in /dev...39client # [7346534.962063] client systemd[1]: Starting Flush Journal to Persistent Storage...40ca # [7346534.972038] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/be580ce3434e4396b1d36119bc9d5f8a is 1.761ms for 6 entries.41client # [7346534.962793] client systemd[1]: Starting Network Name Resolution...42ca # [7346534.972038] ca systemd-journald[78]: System Journal (/var/log/journal/be580ce3434e4396b1d36119bc9d5f8a) is 8M, max 4G, 3.9G free.43client # [7346534.963560] client systemd[1]: Starting Create Static Device Nodes in /dev...44ca # [7346534.985827] ca systemd[1]: Finished Create Static Device Nodes in /dev.45client # [7346534.973145] client systemd-journald[69]: Time spent on flushing to /var/log/journal/84e730bf37bf4b09b31ba71b4ba571fa is 1.785ms for 5 entries.46ca # [7346534.986493] ca systemd[1]: Reached target Preparation for Local File Systems.47client # [7346534.973145] client systemd-journald[69]: System Journal (/var/log/journal/84e730bf37bf4b09b31ba71b4ba571fa) is 8M, max 4G, 3.9G free.48ca # [7346534.986613] ca systemd[1]: Reached target Local File Systems.49client # [7346534.985801] client systemd[1]: Finished Create Static Device Nodes in /dev.50ca # [7346534.987392] ca systemd[1]: Listening on Boot Loader Control Service Socket.51client # [7346534.986484] client systemd[1]: Reached target Preparation for Local File Systems.52ca # [7346534.987435] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container53client # [7346534.986611] client systemd[1]: Reached target Local File Systems.54ca # [7346534.988341] ca systemd[1]: Starting Save Transient machine-id to Disk...55client # [7346534.987409] client systemd[1]: Listening on Boot Loader Control Service Socket.56ca # [7346534.988377] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys57client # [7346534.987449] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container58ca # [7346534.990465] ca systemd[1]: Finished Flush Journal to Persistent Storage.59client # [7346534.988354] client systemd[1]: Starting Save Transient machine-id to Disk...60ca # [7346534.991250] ca systemd[1]: Starting Create System Files and Directories...61client # [7346534.988387] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys62ca # [7346535.017382] ca systemd-tmpfiles[123]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted63client # [7346534.990355] client systemd[1]: Finished Flush Journal to Persistent Storage.64ca # [7346535.017608] ca systemd-tmpfiles[123]: fchmod() of /var/log/journal failed: Operation not permitted65ca # [7346535.017756] ca systemd-tmpfiles[123]: fchmod() of /var/log/journal/be580ce3434e4396b1d36119bc9d5f8a failed: Operation not permitted66ca # [7346535.017983] ca systemd-tmpfiles[123]: fchmod() of /run/log/journal failed: Operation not permitted67ca # [7346535.019471] ca systemd[1]: Finished Create System Files and Directories.68ca # [7346535.020590] ca systemd[1]: Starting Rebuild Journal Catalog...69ca # [7346535.021369] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP...70ca # [7346535.032803] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP.71ca # [7346535.038840] ca systemd[1]: Finished Rebuild Journal Catalog.72ca # [7346535.039940] ca systemd[1]: Starting Update is Completed...73ca # [7346535.050393] ca systemd[1]: Finished Update is Completed.74server # [7346534.953717] server systemd-journald[69]: Journal started75client # [7346534.991250] client systemd[1]: Starting Create System Files and Directories...76server # [7346534.953772] server systemd-journald[69]: Runtime Journal (/run/log/journal/645c30cb6e2149b88c5ce73ef9aaf8b5) is 8M, max 2.5G, 2.4G free.77client # [7346535.016814] client systemd-tmpfiles[112]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted78client # [7346535.017009] client systemd-tmpfiles[112]: fchmod() of /var/log/journal failed: Operation not permitted79server # [7346534.959136] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully.80client # [7346535.017139] client systemd-tmpfiles[112]: fchmod() of /var/log/journal/84e730bf37bf4b09b31ba71b4ba571fa failed: Operation not permitted81client # [7346535.017338] client systemd-tmpfiles[112]: fchmod() of /run/log/journal failed: Operation not permitted82client # [7346535.018836] client systemd[1]: Finished Create System Files and Directories.83client # [7346535.019969] client systemd[1]: Starting Rebuild Journal Catalog...84client # [7346535.020790] client systemd[1]: Starting Record System Boot/Shutdown in UTMP...85client # [7346535.033279] client systemd[1]: Finished Record System Boot/Shutdown in UTMP.86client # [7346535.039364] client systemd[1]: Finished Rebuild Journal Catalog.87client # [7346535.040840] client systemd[1]: Starting Update is Completed...88server # [7346534.969194] server systemd[1]: Starting Flush Journal to Persistent Storage...89client # [7346535.050026] client systemd[1]: Finished Update is Completed.90server # [7346534.970054] server systemd[1]: Starting Network Name Resolution...91server # [7346534.970707] server systemd[1]: Starting Create Static Device Nodes in /dev...92server # [7346534.978067] server systemd-journald[69]: Time spent on flushing to /var/log/journal/645c30cb6e2149b88c5ce73ef9aaf8b5 is 1.515ms for 6 entries.93server # [7346534.978067] server systemd-journald[69]: System Journal (/var/log/journal/645c30cb6e2149b88c5ce73ef9aaf8b5) is 8M, max 4G, 3.9G free.94server # [7346534.992449] server systemd[1]: Finished Flush Journal to Persistent Storage.95server # [7346534.993898] server systemd[1]: Finished Create Static Device Nodes in /dev.96server # [7346534.995279] server systemd[1]: Reached target Preparation for Local File Systems.97server # [7346534.995414] server systemd[1]: Reached target Local File Systems.98server # [7346534.996250] server systemd[1]: Listening on Boot Loader Control Service Socket.99server # [7346534.996305] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container100server # [7346534.997205] server systemd[1]: Starting Save Transient machine-id to Disk...101server # [7346534.998019] server systemd[1]: Starting Create System Files and Directories...102server # [7346534.998053] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys103server # [7346535.016953] server systemd-tmpfiles[116]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted104server # [7346535.017147] server systemd-tmpfiles[116]: fchmod() of /var/log/journal failed: Operation not permitted105server # [7346535.017275] server systemd-tmpfiles[116]: fchmod() of /var/log/journal/645c30cb6e2149b88c5ce73ef9aaf8b5 failed: Operation not permitted106server # [7346535.017472] server systemd-tmpfiles[116]: fchmod() of /run/log/journal failed: Operation not permitted107server # [7346535.018946] server systemd[1]: Finished Create System Files and Directories.108server # [7346535.019970] server systemd[1]: Starting Rebuild Journal Catalog...109server # [7346535.020791] server systemd[1]: Starting Record System Boot/Shutdown in UTMP...110server # [7346535.033111] server systemd[1]: Finished Record System Boot/Shutdown in UTMP.111server # [7346535.039030] server systemd[1]: Finished Rebuild Journal Catalog.112server # [7346535.040041] server systemd[1]: Starting Update is Completed...113server # [7346535.049806] server systemd[1]: Finished Update is Completed.114ca # [7346535.109345] ca systemd[1]: Finished Firewall.115ca # [7346535.109496] ca systemd[1]: Reached target Preparation for Network.116ca # [7346535.109703] ca systemd[1]: Listening on Network Management Resolve Hook Socket.117ca # [7346535.110687] ca systemd[1]: Starting Network Management...118client # [7346535.102011] client systemd[1]: Finished Firewall.119client # [7346535.102627] client systemd[1]: Reached target Preparation for Network.120client # [7346535.102911] client systemd[1]: Listening on Network Management Resolve Hook Socket.121client # [7346535.103993] client systemd[1]: Starting Network Management...122server # [7346535.107185] server systemd[1]: Finished Firewall.123server # [7346535.107272] server systemd[1]: Reached target Preparation for Network.124server # [7346535.107490] server systemd[1]: Listening on Network Management Resolve Hook Socket.125server # [7346535.108467] server systemd[1]: Starting Network Management...126client # [7346535.542734] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted127client # [7346535.542825] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted128client # [7346535.552180] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.129client # [7346535.552349] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.130client # [7346535.552503] client systemd-networkd[182]: lo: Link UP131client # [7346535.552507] client systemd-networkd[182]: lo: Gained carrier132client # [7346535.552675] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network.133client # [7346535.553088] client systemd[1]: Started Network Management.134client # [7346535.553151] client systemd-networkd[182]: eth1: Link UP135client # [7346535.553446] client systemd-networkd[182]: eth1: Gained carrier136client # [7346535.554114] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd...137client # [7346535.601541] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd.138client # [7346535.709733] client systemd-resolved[91]: Positive Trust Anchors:139client # [7346535.709745] client systemd-resolved[91]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d140client # [7346535.709749] client systemd-resolved[91]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16141client # [7346535.709783] client systemd-resolved[91]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test142client # [7346535.732309] client systemd-resolved[91]: Using system hostname 'client'.143client # [7346535.733669] client systemd[1]: Started Network Name Resolution.144client # [7346535.733749] client systemd[1]: Reached target Network.145client # [7346535.733820] client systemd[1]: Reached target System Initialization.146client # [7346535.733872] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container147client # [7346535.733907] client systemd[1]: Started Daily Cleanup of Temporary Directories.148client # [7346535.733924] client systemd[1]: Reached target Timer Units.149client # [7346535.734054] client systemd[1]: Listening on D-Bus System Message Bus Socket.150client # [7346535.734171] client systemd[1]: Listening on Nix Daemon Socket.151client # [7346535.734283] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.152client # [7346535.734306] client systemd[1]: Reached target Socket Units.153client # [7346535.734343] client systemd[1]: Reached target Basic System.154client # [7346535.735423] client systemd[1]: Starting Import lastlog data into lastlog2 database...155client # [7346535.736323] client systemd[1]: Starting Name Service Cache Daemon (nsncd)...156client # [7346535.737698] client systemd[1]: Starting D-Bus System Message Bus...157server # [7346535.541116] server systemd-networkd[186]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted158server # [7346535.541209] server systemd-networkd[186]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted159server # [7346535.550084] server systemd-networkd[186]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.160server # [7346535.550266] server systemd-networkd[186]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.161server # [7346535.550432] server systemd-networkd[186]: lo: Link UP162server # [7346535.550436] server systemd-networkd[186]: lo: Gained carrier163server # [7346535.550609] server systemd-networkd[186]: eth1: Configuring with /etc/systemd/network/40-eth1.network.164server # [7346535.551010] server systemd[1]: Started Network Management.165server # [7346535.551092] server systemd-networkd[186]: eth1: Link UP166server # [7346535.551341] server systemd-networkd[186]: eth1: Gained carrier167server # [7346535.552055] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd...168server # [7346535.600776] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd.169server # [7346535.717183] server systemd-resolved[94]: Positive Trust Anchors:170server # [7346535.717193] server systemd-resolved[94]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d171server # [7346535.717196] server systemd-resolved[94]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16172server # [7346535.717231] server systemd-resolved[94]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test173server # [7346535.739560] server systemd-resolved[94]: Using system hostname 'server'.174server # [7346535.740972] server systemd[1]: Started Network Name Resolution.175server # [7346535.741052] server systemd[1]: Reached target Network.176server # [7346535.741113] server systemd[1]: Reached target Network is Online.177server # [7346535.741161] server systemd[1]: Reached target System Initialization.178server # [7346535.741397] server systemd[1]: Started Renew ACME Certificate for test.foo.179server # [7346535.741429] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container180server # [7346535.741451] server systemd[1]: Started Daily Cleanup of Temporary Directories.181server # [7346535.741472] server systemd[1]: Reached target Timer Units.182server # [7346535.741593] server systemd[1]: Listening on D-Bus System Message Bus Socket.183server # [7346535.741696] server systemd[1]: Listening on Nix Daemon Socket.184server # [7346535.741809] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.185server # [7346535.741832] server systemd[1]: Reached target Socket Units.186server # [7346535.741870] server systemd[1]: Reached target Basic System.187server # [7346535.873121] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure...188ca # [7346535.554864] ca systemd-networkd[195]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted189ca # [7346535.554954] ca systemd-networkd[195]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted190ca # [7346535.561967] ca systemd-networkd[195]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.191ca # [7346535.562130] ca systemd-networkd[195]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.192ca # [7346535.562288] ca systemd-networkd[195]: lo: Link UP193ca # [7346535.562292] ca systemd-networkd[195]: lo: Gained carrier194ca # [7346535.562477] ca systemd-networkd[195]: eth1: Configuring with /etc/systemd/network/40-eth1.network.195ca # [7346535.562864] ca systemd[1]: Started Network Management.196ca # [7346535.592336] ca systemd-networkd[195]: eth1: Link UP197ca # [7346535.592420] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd...198ca # [7346535.592591] ca systemd-networkd[195]: eth1: Gained carrier199ca # [7346535.641385] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd.200ca # [7346535.736789] ca systemd-resolved[100]: Positive Trust Anchors:201ca # [7346535.736801] ca systemd-resolved[100]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d202ca # [7346535.736804] ca systemd-resolved[100]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16203ca # [7346535.736839] ca systemd-resolved[100]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test204ca # [7346535.759015] ca systemd-resolved[100]: Using system hostname 'ca'.205ca # [7346535.760397] ca systemd[1]: Started Network Name Resolution.206ca # [7346535.760494] ca systemd[1]: Reached target Network.207ca # [7346535.760561] ca systemd[1]: Reached target Network is Online.208ca # [7346535.760613] ca systemd[1]: Reached target System Initialization.209ca # [7346535.760860] ca systemd[1]: Started Renew ACME Certificate for ca.foo.210ca # [7346535.760901] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container211ca # [7346535.760930] ca systemd[1]: Started Daily Cleanup of Temporary Directories.212ca # [7346535.760952] ca systemd[1]: Reached target Timer Units.213ca # [7346535.761090] ca systemd[1]: Listening on D-Bus System Message Bus Socket.214ca # [7346535.761201] ca systemd[1]: Listening on Nix Daemon Socket.215ca # [7346535.761331] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.216ca # [7346535.761363] ca systemd[1]: Reached target Socket Units.217ca # [7346535.761411] ca systemd[1]: Reached target Basic System.218ca # [7346535.873151] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure...219ca # [7346535.874141] ca systemd[1]: Starting Import lastlog data into lastlog2 database...220ca # [7346535.874187] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem221server # [7346535.874299] server systemd[1]: Starting Import lastlog data into lastlog2 database...222ca # [7346535.875145] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)...223server # [7346535.874341] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem224ca # [7346535.876280] ca systemd[1]: Starting step-ca service...225server # [7346535.875314] server systemd[1]: Starting Name Service Cache Daemon (nsncd)...226ca # [7346535.877723] ca systemd[1]: Starting D-Bus System Message Bus...227server # [7346535.876655] server systemd[1]: Starting D-Bus System Message Bus...228ca # [7346535.894078] ca systemd[1]: Finished Import lastlog data into lastlog2 database.229server # [7346535.894368] server systemd[1]: Finished Import lastlog data into lastlog2 database.230ca # [7346535.976596] ca acme-setup-privileged[200]: + set -euo pipefail231server # [7346535.981280] server acme-setup-privileged[191]: + set -euo pipefail232ca # [7346535.976596] ca acme-setup-privileged[200]: + cd /var/lib/acme233server # [7346535.981280] server acme-setup-privileged[191]: + cd /var/lib/acme234ca # [7346535.977324] ca acme-setup-privileged[200]: + chmod -R u=rwX,g=,o= .lego/accounts235server # [7346535.981591] server acme-setup-privileged[191]: + chmod -R u=rwX,g=,o= .lego/accounts236ca # [7346535.978320] ca acme-setup-privileged[200]: + chown -R acme .lego/accounts237server # [7346535.983056] server acme-setup-privileged[191]: + chown -R acme .lego/accounts238ca # [7346535.980364] ca acme-setup-privileged[200]: + for fixpath in ca.foo .lego/ca.foo239server # [7346535.984874] server acme-setup-privileged[191]: + for fixpath in test.foo .lego/test.foo240ca # [7346535.980364] ca acme-setup-privileged[200]: + '[' -d ca.foo ']'241server # [7346535.984901] server acme-setup-privileged[191]: + '[' -d test.foo ']'242ca # [7346535.980478] ca acme-setup-privileged[200]: + for fixpath in ca.foo .lego/ca.foo243server # [7346535.984901] server acme-setup-privileged[191]: + for fixpath in test.foo .lego/test.foo244ca # [7346535.980478] ca acme-setup-privileged[200]: + '[' -d .lego/ca.foo ']'245server # [7346535.984901] server acme-setup-privileged[191]: + '[' -d .lego/test.foo ']'246ca # [7346536.000956] ca nsncd[202]: Sep 02 00:06:02.054 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"247ca # [7346536.001147] ca systemd[1]: Started Name Service Cache Daemon (nsncd).248ca # [7346536.001231] ca systemd[1]: Reached target Host and Network Name Lookups.249ca # [7346536.001356] ca systemd[1]: Reached target User and Group Name Lookups.250ca # [7346536.037279] ca systemd[1]: Starting User Login Management...251ca # [7346536.038245] ca systemd[1]: Starting Permit User Sessions...252ca # [7346536.049922] ca systemd[1]: Finished Permit User Sessions.253ca # [7346536.051087] ca systemd[1]: Started Console Getty.254server # [7346536.006209] server nsncd[193]: Sep 02 00:06:02.059 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"255server # [7346536.006225] server systemd[1]: Started Name Service Cache Daemon (nsncd).256ca # [7346536.051139] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0257server # [7346536.006336] server systemd[1]: Reached target Host and Network Name Lookups.258ca # [7346536.051162] ca systemd[1]: Reached target Login Prompts.259server # [7346536.006448] server systemd[1]: Reached target User and Group Name Lookups.260server # [7346536.037533] server systemd[1]: Starting User Login Management...261server # [7346536.038778] server systemd[1]: Starting Permit User Sessions...262server # [7346536.050133] server systemd[1]: Finished Permit User Sessions.263server # [7346536.051418] server systemd[1]: Started Console Getty.264server # [7346536.051462] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0265server # [7346536.051478] server systemd[1]: Reached target Login Prompts.266server # [7346536.113026] server dbus-broker-launch[194]: Looking up NSS user entry for 'systemd-timesync'...267server # [7346536.113739] server dbus-broker-launch[194]: NSS returned no entry for 'systemd-timesync'268server # [7346536.113739] server dbus-broker-launch[194]: Invalid user-name in /nix/store/aszr859gd9lnmlsj2dls188ya32g6xf8-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"269server # [7346536.114180] server systemd[1]: Started D-Bus System Message Bus.270server # [7346536.122442] server dbus-broker-launch[194]: Ready271client # [7346535.890140] client systemd[1]: Finished Import lastlog data into lastlog2 database.272client # [7346536.004661] client systemd[1]: Started Name Service Cache Daemon (nsncd).273client # [7346536.004732] client systemd[1]: Reached target Host and Network Name Lookups.274client # [7346536.004796] client systemd[1]: Reached target User and Group Name Lookups.275client # [7346536.005558] client nsncd[188]: Sep 02 00:06:02.058 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"276client # [7346536.037420] client systemd[1]: Starting User Login Management...277client # [7346536.038353] client systemd[1]: Starting Permit User Sessions...278client # [7346536.048639] client systemd[1]: Finished Permit User Sessions.279client # [7346536.049823] client systemd[1]: Started Console Getty.280client # [7346536.049865] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0281client # [7346536.049887] client systemd[1]: Reached target Login Prompts.282ca # [7346536.145463] ca dbus-broker-launch[204]: Looking up NSS user entry for 'systemd-timesync'...283ca # [7346536.146401] ca dbus-broker-launch[204]: NSS returned no entry for 'systemd-timesync'284ca # [7346536.146401] ca dbus-broker-launch[204]: Invalid user-name in /nix/store/nrvy3kisslkv7qydv3v2ib6szfdky5q3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"285ca # [7346536.146876] ca systemd[1]: Started D-Bus System Message Bus.286ca # [7346536.155354] ca dbus-broker-launch[204]: Ready287client # [7346536.216733] client dbus-broker-launch[189]: Looking up NSS user entry for 'systemd-timesync'...288client # [7346536.217877] client dbus-broker-launch[189]: NSS returned no entry for 'systemd-timesync'289client # [7346536.217877] client dbus-broker-launch[189]: Invalid user-name in /nix/store/ssk8893k9jd7id6pd9yzim0h6prlbdma-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"290client # [7346536.218271] client systemd[1]: Started D-Bus System Message Bus.291client # [7346536.225817] client dbus-broker-launch[189]: Ready292client # [7346536.607475] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully.293client # [7346536.608519] client systemd[1]: Finished Save Transient machine-id to Disk.294client # [7346536.622299] client systemd-logind[204]: New seat seat0.295client # [7346536.622466] client systemd[1]: Started User Login Management.296client # [7346536.660561] client systemd[1]: Starting linger-users.service...297client # [7346536.673969] client systemd[1]: linger-users.service: Deactivated successfully.298client # [7346536.674110] client systemd[1]: Finished linger-users.service.299client # [7346536.674915] client systemd[1]: Reached target Multi-User System.300client # [7346536.675259] client systemd[1]: Startup finished in 2.125s.301ca # [7346536.607277] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully.302ca # [7346536.608374] ca systemd[1]: Finished Save Transient machine-id to Disk.303ca # [7346536.644543] ca systemd-logind[230]: New seat seat0.304ca # [7346536.644673] ca systemd[1]: Started User Login Management.305ca # [7346536.661535] ca systemd[1]: Starting linger-users.service...306ca # [7346536.673439] ca systemd[1]: linger-users.service: Deactivated successfully.307ca # [7346536.673560] ca systemd[1]: Finished linger-users.service.308ca # [7346536.704037] ca acme-setup-start[218]: + set -euo pipefail309ca # [7346536.704037] ca acme-setup-start[218]: + test -e ca/key.pem310ca # [7346536.704650] ca acme-setup-start[218]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local311ca # [7346536.725757] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure.312ca # [7346536.727278] ca systemd[1]: Starting Ensure certificate for ca.foo...313ca # [7346536.778060] ca step-ca[203]: badger 2026/09/02 00:06:02 INFO: All 0 tables opened in 0s314ca # [7346536.781639] ca step-ca[203]: 2026/09/02 00:06:02 Building new tls configuration using step-ca x509 Signer Interface315ca # [7346536.786234] ca step-ca[203]: 2026/09/02 00:06:02 Starting Smallstep CA/0.30.2 (linux/arm64)316ca # [7346536.786234] ca step-ca[203]: 2026/09/02 00:06:02 Documentation: https://u.step.sm/docs/ca317ca # [7346536.786234] ca step-ca[203]: 2026/09/02 00:06:02 Community Discord: https://u.step.sm/discord318ca # [7346536.786234] ca step-ca[203]: 2026/09/02 00:06:02 Config file: /etc/smallstep/ca.json319ca # [7346536.786318] ca step-ca[203]: 2026/09/02 00:06:02 The primary server URL is https://ca.foo:1443320ca # [7346536.786318] ca step-ca[203]: 2026/09/02 00:06:02 Root certificates are available at https://ca.foo:1443/roots.pem321ca # [7346536.786318] ca step-ca[203]: 2026/09/02 00:06:02 X.509 Root Fingerprint: e402915422ebb43c74b1cff0df0c2da9405790353a17b701af328fc37ae165a4322ca # [7346536.786849] ca systemd[1]: Started step-ca service.323ca # [7346536.787184] ca step-ca[203]: 2026/09/02 00:06:02 Serving HTTPS on 0.0.0.0:1443 ...324ca # [7346536.960279] ca systemd-networkd[195]: eth1: Gained IPv6LL325server # [7346536.609524] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully.326server # [7346536.610527] server systemd[1]: Finished Save Transient machine-id to Disk.327server # [7346536.611239] server systemd-logind[219]: New seat seat0.328server # [7346536.611513] server systemd[1]: Started User Login Management.329server # [7346536.612872] server systemd[1]: Starting linger-users.service...330server # [7346536.670637] server systemd[1]: linger-users.service: Deactivated successfully.331server # [7346536.670811] server systemd[1]: Finished linger-users.service.332server # [7346536.706842] server acme-setup-start[207]: + set -euo pipefail333server # [7346536.706842] server acme-setup-start[207]: + test -e ca/key.pem334server # [7346536.707472] server acme-setup-start[207]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local335server # [7346536.727824] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure.336server # [7346536.729533] server systemd[1]: Starting Ensure certificate for test.foo...337ca: must succeed: systemctl restart acme-order-renew-ca.foo.service 338ca # [7346537.206359] ca acme-ca.foo-start[260]: Waiting to acquire lock in /run/acme/339ca # [7346537.208958] ca acme-ca.foo-start[260]: + '[' -e out/acme-success ']'340ca # [7346537.209056] ca acme-ca.foo-start[260]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses=341ca # [7346537.223858] ca acme-ca.foo-start[293]: + cd ca.foo342ca # [7346537.223858] ca acme-ca.foo-start[293]: + cp -vp cert.pem ../out/cert.pem343client # [7346536.864230] client systemd-networkd[182]: eth1: Gained IPv6LL344ca # [7346537.225692] ca acme-ca.foo-start[294]: 'cert.pem' -> '../out/cert.pem'345ca # [7346537.225977] ca acme-ca.foo-start[293]: + cp -vp key.pem ../out/key.pem346ca # [7346537.227359] ca acme-ca.foo-start[293]: 'key.pem' -> '../out/key.pem'347ca # [7346537.227617] ca acme-ca.foo-start[260]: + cat out/cert.pem ca/cert.pem348ca # [7346537.229409] ca acme-ca.foo-start[260]: + cp ca/cert.pem out/chain.pem349ca # [7346537.230776] ca acme-ca.foo-start[260]: + cat out/key.pem out/fullchain.pem350ca # [7346537.232649] ca acme-ca.foo-start[260]: + for fixpath in out certificates351ca # [7346537.232649] ca acme-ca.foo-start[260]: + '[' -d out ']'352ca # [7346537.232709] ca acme-ca.foo-start[260]: + chmod -R u=rwX,g=rX,o= out353ca # [7346537.234360] ca acme-ca.foo-start[260]: + chown -R acme:nginx out354ca # [7346537.238017] ca acme-ca.foo-start[260]: + for fixpath in out certificates355ca # [7346537.238047] ca acme-ca.foo-start[260]: + '[' -d certificates ']'356ca # [7346537.241209] ca systemd[1]: Finished Ensure certificate for ca.foo.357ca # [7346537.276563] ca systemd[1]: Starting Nginx Web Server...358server # [7346537.199558] server acme-test.foo-start[244]: Waiting to acquire lock in /run/acme/359server # [7346537.202699] server acme-test.foo-start[244]: + '[' -e out/acme-success ']'360server # [7346537.202780] server acme-test.foo-start[244]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=361server # [7346537.217684] server acme-test.foo-start[254]: + cd test.foo362server # [7346537.218261] server acme-test.foo-start[254]: + cp -vp cert.pem ../out/cert.pem363server # [7346537.219446] server acme-test.foo-start[255]: 'cert.pem' -> '../out/cert.pem'364server # [7346537.219772] server acme-test.foo-start[254]: + cp -vp key.pem ../out/key.pem365server # [7346537.221103] server acme-test.foo-start[254]: 'key.pem' -> '../out/key.pem'366server # [7346537.221354] server acme-test.foo-start[244]: + cat out/cert.pem ca/cert.pem367server # [7346537.223247] server acme-test.foo-start[244]: + cp ca/cert.pem out/chain.pem368server # [7346537.224961] server acme-test.foo-start[244]: + cat out/key.pem out/fullchain.pem369server # [7346537.226376] server acme-test.foo-start[244]: + for fixpath in out certificates370server # [7346537.226376] server acme-test.foo-start[244]: + '[' -d out ']'371server # [7346537.226481] server acme-test.foo-start[244]: + chmod -R u=rwX,g=rX,o= out372server # [7346537.227740] server acme-test.foo-start[244]: + chown -R acme:nginx out373server # [7346537.230564] server acme-test.foo-start[244]: + for fixpath in out certificates374server # [7346537.230564] server acme-test.foo-start[244]: + '[' -d certificates ']'375server # [7346537.233782] server systemd[1]: Finished Ensure certificate for test.foo.376server # [7346537.235386] server systemd[1]: Starting Nginx Web Server...377server # [7346537.572214] server systemd-networkd[186]: eth1: Gained IPv6LL378server # [7346537.766990] server nginx-pre-start[266]: nginx: the configuration file /nix/store/ldafm91pv9vld74irca8avm5fh9l2p2m-nginx.conf syntax is ok379server # [7346537.767289] server nginx-pre-start[266]: nginx: configuration file /nix/store/ldafm91pv9vld74irca8avm5fh9l2p2m-nginx.conf test is successful380server # [7346537.774733] server systemd[1]: Started Nginx Web Server.381server # [7346537.775122] server systemd[1]: Reached target Multi-User System.382server # [7346537.776629] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...383ca # [7346537.772147] ca nginx-pre-start[305]: nginx: the configuration file /nix/store/x7nyri68sw69z98vv03jd76l8kyd8frn-nginx.conf syntax is ok384ca # [7346537.772759] ca nginx-pre-start[305]: nginx: configuration file /nix/store/x7nyri68sw69z98vv03jd76l8kyd8frn-nginx.conf test is successful385ca # [7346537.777144] ca systemd[1]: Started Nginx Web Server.386ca # [7346537.777614] ca systemd[1]: Reached target Multi-User System.387ca # [7346537.779080] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...388ca # [7346538.316302] ca acme-order-renew-ca.foo-start[308]: Waiting to acquire lock in /run/acme/389ca # [7346538.320315] ca acme-order-renew-ca.foo-start[308]: + set -euo pipefail390ca # [7346538.320445] ca acme-order-renew-ca.foo-start[308]: + echo 88dc4fc401a6091a1bd9391ca # [7346538.320499] ca acme-order-renew-ca.foo-start[308]: + cmp -s domainhash.txt certificates/domainhash.txt392ca # [7346538.321954] ca acme-order-renew-ca.foo-start[308]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run393ca # [7346538.350458] ca acme-order-renew-ca.foo-start[319]: 2026/09/02 00:06:04 No key found for account none@none.tld. Generating a P256 key.394ca # [7346538.350802] ca acme-order-renew-ca.foo-start[319]: 2026/09/02 00:06:04 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key395ca # [7346538.378294] ca step-ca[203]: time="2026-09-02T00:06:04Z" level=info duration="96.762µs" duration-ns=96762 fields.time="2026-09-02T00:06:04Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=8bce0408-f432-406b-aea5-4b15398525c7 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=396ca # [7346538.378672] ca acme-order-renew-ca.foo-start[319]: 2026/09/02 00:06:04 [INFO] acme: Registering account for none@none.tld397ca # [7346538.454289] ca step-ca[203]: time="2026-09-02T00:06:04Z" level=info duration=75.381702ms duration-ns=75381702 fields.time="2026-09-02T00:06:04Z" method=HEAD name=ca nonce=eUtJWmwwMnhxTWdvZHBtcmt1cE1YR0FUSEI2ZjJpd2E path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=5ac7ef45-c1d4-4bf5-9cc8-b06d3e5a8f4b size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=398ca # [7346538.468767] ca step-ca[203]: time="2026-09-02T00:06:04Z" level=info duration=13.23854ms duration-ns=13238540 fields.time="2026-09-02T00:06:04Z" method=POST name=ca nonce=ZE1uVXJOSjZ0ZUx1c2psdUZmSm14d1JsWVFNQ3ZVa1g path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=747baaca-cc47-44a7-a0bc-06369abe108e response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/0vD8GSLQs4Z9Otl6XL6sZaaIVfW66TCx/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=399ca # [7346538.469254] ca acme-order-renew-ca.foo-start[319]: !!!! HEADS UP !!!!400ca # [7346538.469254] ca acme-order-renew-ca.foo-start[319]: Your account credentials have been saved in your401ca # [7346538.469254] ca acme-order-renew-ca.foo-start[319]: configuration directory at "accounts".402ca # [7346538.469254] ca acme-order-renew-ca.foo-start[319]: You should make a secure backup of this folder now. This403ca # [7346538.469254] ca acme-order-renew-ca.foo-start[319]: configuration directory will also contain private keys404ca # [7346538.469254] ca acme-order-renew-ca.foo-start[319]: generated by lego and certificates obtained from the ACME405ca # [7346538.469254] ca acme-order-renew-ca.foo-start[319]: server. Making regular backups of this folder is ideal.406ca # [7346538.469254] ca acme-order-renew-ca.foo-start[319]: 2026/09/02 00:06:04 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate407ca # [7346538.474455] ca step-ca[203]: time="2026-09-02T00:06:04Z" level=info duration=4.528501ms duration-ns=4528501 fields.time="2026-09-02T00:06:04Z" method=POST name=ca nonce=SVd2WjdiU0V6dTc1R2pWdEpIMUJSWjNlZ3dlVG5MYjk path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=4f1f286f-3620-451e-8500-f3a438a4f23c response="{\"id\":\"nA5h9glUeTLGtiCCWzfuyJyoMngL00j5\",\"status\":\"pending\",\"expires\":\"2026-09-03T00:06:04Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-09-02T00:05:04Z\",\"notAfter\":\"2026-12-01T00:06:04Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/MgxCUsNJgmiFHJfOTpqYjWAOUUrR0SfV\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/nA5h9glUeTLGtiCCWzfuyJyoMngL00j5/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=408ca # [7346538.543619] ca step-ca[203]: time="2026-09-02T00:06:04Z" level=info duration=12.179045ms duration-ns=12179045 fields.time="2026-09-02T00:06:04Z" method=POST name=ca nonce=ZHJUQ2FvUVZIMkpWQTlkY3lsQkN4RE5TUTU1eGNkZGE path=/acme/acme/authz/MgxCUsNJgmiFHJfOTpqYjWAOUUrR0SfV protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=153dcf88-664d-4694-bf19-40688011145b response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"trooQbS05nb4XIauXPUgFHwlMI5MH8z3\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/MgxCUsNJgmiFHJfOTpqYjWAOUUrR0SfV/5uIBDdzi8i8l2lfjdzuu7j2GskgXOyoI\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"trooQbS05nb4XIauXPUgFHwlMI5MH8z3\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/MgxCUsNJgmiFHJfOTpqYjWAOUUrR0SfV/1nwf4LB9c0JGXTTYtbb3d8Y6RXxhYf7e\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"trooQbS05nb4XIauXPUgFHwlMI5MH8z3\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/MgxCUsNJgmiFHJfOTpqYjWAOUUrR0SfV/mRy8T2J1N6lwvWFj2ZbKOnJk8EA2o8S6\"}],\"wildcard\":false,\"expires\":\"2026-09-03T00:06:04Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=409ca # [7346538.543901] ca acme-order-renew-ca.foo-start[319]: 2026/09/02 00:06:04 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/MgxCUsNJgmiFHJfOTpqYjWAOUUrR0SfV410ca # [7346538.543901] ca acme-order-renew-ca.foo-start[319]: 2026/09/02 00:06:04 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01411ca # [7346538.543901] ca acme-order-renew-ca.foo-start[319]: 2026/09/02 00:06:04 [INFO] [ca.foo] acme: use http-01 solver412ca # [7346538.543901] ca acme-order-renew-ca.foo-start[319]: 2026/09/02 00:06:04 [INFO] [ca.foo] acme: Trying to solve HTTP-01413ca # [7346538.550317] ca step-ca[203]: time="2026-09-02T00:06:04Z" level=info duration=5.88292ms duration-ns=5882920 fields.time="2026-09-02T00:06:04Z" method=POST name=ca nonce=S3ZpSUhyWmxGWTVQRExFRjFJNndjM3FxaWcwR2ZiUUM path=/acme/acme/challenge/MgxCUsNJgmiFHJfOTpqYjWAOUUrR0SfV/1nwf4LB9c0JGXTTYtbb3d8Y6RXxhYf7e protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=f9309936-de3d-49fe-8d59-72a6af298e3d response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"trooQbS05nb4XIauXPUgFHwlMI5MH8z3\",\"validated\":\"2026-09-02T00:06:04Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/MgxCUsNJgmiFHJfOTpqYjWAOUUrR0SfV/1nwf4LB9c0JGXTTYtbb3d8Y6RXxhYf7e\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=414ca # [7346538.550687] ca acme-order-renew-ca.foo-start[319]: 2026/09/02 00:06:04 [INFO] [ca.foo] The server validated our request415ca # [7346538.550790] ca acme-order-renew-ca.foo-start[319]: 2026/09/02 00:06:04 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates416ca # [7346538.559213] ca step-ca[203]: time="2026-09-02T00:06:04Z" level=info duration=6.722611ms duration-ns=6722611 fields.time="2026-09-02T00:06:04Z" method=POST name=ca nonce=SER4MFpJNWlMa05ZVFRFMlk2ZzRSOUdjODg1c042d3k path=/acme/acme/order/nA5h9glUeTLGtiCCWzfuyJyoMngL00j5/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=f8793d5a-2593-4a39-97cc-14c1f34ef2a8 response="{\"id\":\"nA5h9glUeTLGtiCCWzfuyJyoMngL00j5\",\"status\":\"valid\",\"expires\":\"2026-09-03T00:06:04Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-09-02T00:05:04Z\",\"notAfter\":\"2026-12-01T00:06:04Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/MgxCUsNJgmiFHJfOTpqYjWAOUUrR0SfV\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/nA5h9glUeTLGtiCCWzfuyJyoMngL00j5/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/OBX5eZfs2nO85Sv3SYB2V1jRd54ALWxY\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=417ca # [7346538.561713] ca step-ca[203]: time="2026-09-02T00:06:04Z" level=info certificate="MIIB1DCCAXqgAwIBAgIRAKNHYche+epsysFdkb62AF4wCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwOTAyMDAwNTA0WhcNMjYxMjAxMDAwNjA0WjARMQ8wDQYDVQQDEwZjYS5mb28wWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAATH1vlwO2EgrPaGhYvfuKYNdD4Cark6M5++KK4P76ewMF9x93VFnM42WiWlcoQQzaIzaHhPV/04/+mEIHq+10A3o4GkMIGhMA4GA1UdDwEB/wQEAwIHgDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHQYDVR0OBBYEFA1NFk7jELgI7FXoLR7wX2R08uzbMB8GA1UdIwQYMBaAFNOFAvIJpoDKLK54jxPeLyxTMHJzMBEGA1UdEQQKMAiCBmNhLmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSAAwRQIhAOwE0pDq1VpjhxtPUeg8qItQkByC+j9XLPpj+oEa9T48AiBXFno4rRWjibMn0r34/KAH8YDxhoiHiOsKcq8yR0kMDw==" duration=1.659622ms duration-ns=1659622 fields.time="2026-09-02T00:06:04Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=cFVoUmlWbkplQnVONkc0NVpLajB6dzJINHlJRnpOVk0 path=/acme/acme/certificate/OBX5eZfs2nO85Sv3SYB2V1jRd54ALWxY protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=d51b42e3-4b90-4337-81c0-1d6ab708c0f8 sans="map[dns:[ca.foo]]" serial=217034799658655037602750749786196279390 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-09-02T00:05:04Z" valid-to="2026-12-01T00:06:04Z"418ca # [7346538.561918] ca acme-order-renew-ca.foo-start[319]: 2026/09/02 00:06:04 [INFO] [ca.foo] Server responded with a certificate.419ca # [7346538.569087] ca acme-order-renew-ca.foo-start[308]: + mv domainhash.txt certificates/420server # [7346538.323960] server acme-order-renew-test.foo-start[269]: Waiting to acquire lock in /run/acme/421server # [7346538.326828] server acme-order-renew-test.foo-start[269]: + set -euo pipefail422server # [7346538.326935] server acme-order-renew-test.foo-start[269]: + echo ad12aa6741ce4bd2c108423server # [7346538.327000] server acme-order-renew-test.foo-start[269]: + cmp -s domainhash.txt certificates/domainhash.txt424server # [7346538.328171] server acme-order-renew-test.foo-start[269]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run425server # [7346538.350594] server acme-order-renew-test.foo-start[281]: 2026/09/02 00:06:04 No key found for account none@none.tld. Generating a P256 key.426server # [7346538.350911] server acme-order-renew-test.foo-start[281]: 2026/09/02 00:06:04 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key427server # [7346538.382659] server acme-order-renew-test.foo-start[281]: 2026/09/02 00:06:04 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority428server # [7346538.383004] server acme-order-renew-test.foo-start[269]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.429server # [7346538.383004] server acme-order-renew-test.foo-start[269]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.430server # [7346538.383004] server acme-order-renew-test.foo-start[269]: + exit 10431server # [7346538.385946] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a432server # [7346538.386066] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'.433server # [7346538.386337] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo.434server # [7346538.392097] server systemd[1]: Startup finished in 3.841s.435ca # [7346538.571091] ca acme-order-renew-ca.foo-start[308]: + touch out/acme-success436ca # [7346538.572979] ca acme-order-renew-ca.foo-start[308]: + cmp -s certificates/ca.foo.crt out/fullchain.pem437ca # [7346538.574289] ca acme-order-renew-ca.foo-start[308]: + touch out/renewed438ca # [7346538.575898] ca acme-order-renew-ca.foo-start[308]: + echo Installing new certificate439ca # [7346538.575898] ca acme-order-renew-ca.foo-start[308]: Installing new certificate440ca # [7346538.575953] ca acme-order-renew-ca.foo-start[308]: + cp -vp certificates/ca.foo.crt out/fullchain.pem441ca # [7346538.577245] ca acme-order-renew-ca.foo-start[353]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem'442ca # [7346538.577459] ca acme-order-renew-ca.foo-start[308]: + cp -vp certificates/ca.foo.key out/key.pem443ca # [7346538.579070] ca acme-order-renew-ca.foo-start[354]: 'certificates/ca.foo.key' -> 'out/key.pem'444ca # [7346538.579343] ca acme-order-renew-ca.foo-start[308]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem445ca # [7346538.581136] ca acme-order-renew-ca.foo-start[355]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem'446ca # [7346538.581378] ca acme-order-renew-ca.foo-start[308]: + ln -sf fullchain.pem out/cert.pem447ca # [7346538.583200] ca acme-order-renew-ca.foo-start[308]: + cat out/key.pem out/fullchain.pem448ca # [7346538.584996] ca acme-order-renew-ca.foo-start[308]: + for fixpath in out certificates449ca # [7346538.585027] ca acme-order-renew-ca.foo-start[308]: + '[' -d out ']'450ca # [7346538.585027] ca acme-order-renew-ca.foo-start[308]: + chmod -R u=rwX,g=rX,o= out451ca # [7346538.586673] ca acme-order-renew-ca.foo-start[308]: + chown -R acme:nginx out452ca # [7346538.589627] ca acme-order-renew-ca.foo-start[308]: + for fixpath in out certificates453ca # [7346538.589657] ca acme-order-renew-ca.foo-start[308]: + '[' -d certificates ']'454ca # [7346538.589657] ca acme-order-renew-ca.foo-start[308]: + chmod -R u=rwX,g=rX,o= certificates455ca # [7346538.591297] ca acme-order-renew-ca.foo-start[308]: + chown -R acme:nginx certificates456ca # [7346538.593946] ca acme-order-renew-ca.foo-start[308]: + chmod -R u=rwX,g=,o= accounts/.457ca # [7346538.735327] ca systemd[1]: Reloading Nginx Web Server...458ca # [7346538.738764] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.459ca # [7346538.738925] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.460ca # [7346539.261842] ca nginx[371]: nginx: the configuration file /nix/store/x7nyri68sw69z98vv03jd76l8kyd8frn-nginx.conf syntax is ok461ca # [7346539.262309] ca nginx[371]: nginx: configuration file /nix/store/x7nyri68sw69z98vv03jd76l8kyd8frn-nginx.conf test is successful462ca # [7346539.777700] ca systemd[1]: Reloaded Nginx Web Server.463ca # [7346539.778128] ca systemd[1]: Startup finished in 5.217s.464ca # [7346540.253911] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...465ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 3.89 seconds)466ca # [7346540.741224] ca acme-order-renew-ca.foo-start[386]: Waiting to acquire lock in /run/acme/467ca # [7346540.743877] ca acme-order-renew-ca.foo-start[386]: + set -euo pipefail468ca # [7346540.743947] ca acme-order-renew-ca.foo-start[386]: + echo 88dc4fc401a6091a1bd9469ca # [7346540.744075] ca acme-order-renew-ca.foo-start[386]: + cmp -s domainhash.txt certificates/domainhash.txt470ca # [7346540.745264] ca acme-order-renew-ca.foo-start[386]: + '[' -e certificates/ca.foo.key ']'471ca # [7346540.745264] ca acme-order-renew-ca.foo-start[386]: + '[' -e certificates/ca.foo.crt ']'472ca # [7346540.745654] ca acme-order-renew-ca.foo-start[394]: ++ find accounts -name none@none.tld.key473ca # [7346540.748603] ca acme-order-renew-ca.foo-start[386]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']'474ca # [7346540.748678] ca acme-order-renew-ca.foo-start[386]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic475ca # [7346540.797343] ca step-ca[203]: time="2026-09-02T00:06:06Z" level=info duration="66.4µs" duration-ns=66400 fields.time="2026-09-02T00:06:06Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=6b51fdec-764d-455a-9af6-62c608f321fe response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=476ca # [7346540.797950] ca acme-order-renew-ca.foo-start[395]: 2026/09/02 00:06:06 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint477ca # [7346540.797950] ca acme-order-renew-ca.foo-start[395]: 2026/09/02 00:06:06 [INFO] [ca.foo] The certificate expires at 2026-12-01T00:06:04Z, the renewal can be performed in 1439h59m37.149129919s: no renewal.478ca # [7346540.798300] ca acme-order-renew-ca.foo-start[386]: + mv domainhash.txt certificates/479ca # [7346540.800258] ca acme-order-renew-ca.foo-start[386]: + touch out/acme-success480ca # [7346540.802037] ca acme-order-renew-ca.foo-start[386]: + cmp -s certificates/ca.foo.crt out/fullchain.pem481ca # [7346540.802997] ca acme-order-renew-ca.foo-start[386]: + for fixpath in out certificates482ca # [7346540.802997] ca acme-order-renew-ca.foo-start[386]: + '[' -d out ']'483ca # [7346540.803090] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=rX,o= out484ca # [7346540.804820] ca acme-order-renew-ca.foo-start[386]: + chown -R acme:nginx out485ca # [7346540.808132] ca acme-order-renew-ca.foo-start[386]: + for fixpath in out certificates486ca # [7346540.808132] ca acme-order-renew-ca.foo-start[386]: + '[' -d certificates ']'487ca # [7346540.808132] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=rX,o= certificates488ca # [7346540.809778] ca acme-order-renew-ca.foo-start[386]: + chown -R acme:nginx certificates489ca # [7346540.812729] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=,o= accounts/.490ca # [7346540.967103] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.491ca # [7346540.967322] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.492server: must succeed: systemctl restart acme-test.foo.service493server # [7346543.999934] server systemd[1]: acme-test.foo.service: Deactivated successfully.494server # [7346544.000335] server systemd[1]: Stopped Ensure certificate for test.foo.495server # [7346544.001668] server systemd[1]: Stopping Ensure certificate for test.foo...496server # [7346544.004159] server systemd[1]: Starting Ensure certificate for test.foo...497server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.58 seconds)498client: waiting for success: curl -v https://test.foo499* Trying [2001:db8:1::3]:443...500* Host test.foo:443 was resolved.501* IPv6: 2001:db8:1::3502* IPv4: 192.168.1.3503* ALPN: curl offers h2,http/1.1504} [5 bytes data]505* TLSv1.3 (OUT), TLS handshake, Client hello (1):506} [1552 bytes data]507* SSL Trust Anchors:508* OpenSSL default paths (fallback)509{ [5 bytes data]510* TLSv1.3 (IN), TLS handshake, Server hello (2):511{ [1210 bytes data]512* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):513{ [1 bytes data]514* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):515{ [19 bytes data]516* TLSv1.3 (IN), TLS handshake, Certificate (11):517{ [1009 bytes data]518* TLSv1.3 (IN), TLS handshake, CERT verify (15):519{ [111 bytes data]520* TLSv1.3 (IN), TLS handshake, Finished (20):521{ [52 bytes data]522* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):523} [1 bytes data]524* TLSv1.3 (OUT), TLS handshake, Finished (20):525} [52 bytes data]526* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey527* ALPN: server accepted h2528* Server certificate:529* subject: CN=test.foo530* start date: Sep 2 00:06:03 2026 GMT531* expire date: Oct 2 00:06:03 2028 GMT532* issuer: CN=minica root ca 0f5f39533* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384534* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384535* subjectAltName: "test.foo" matches cert's "test.foo"536* OpenSSL verify result: 13537* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)538* closing connection #0539curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)540More details here: https://curl.se/docs/sslcerts.html541542curl failed to verify the legitimacy of the server and therefore could not543establish a secure connection to it. To learn more about this situation and544how to fix it, please visit the webpage mentioned above.545server # [7346544.524864] server acme-test.foo-start[314]: Waiting to acquire lock in /run/acme/546server # [7346544.527920] server acme-test.foo-start[314]: + '[' -e out/acme-success ']'547server # [7346544.527920] server acme-test.foo-start[314]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=548server # [7346544.542965] server acme-test.foo-start[324]: + cd test.foo549server # [7346544.543485] server acme-test.foo-start[324]: + cp -vp cert.pem ../out/cert.pem550server # [7346544.544602] server acme-test.foo-start[325]: 'cert.pem' -> '../out/cert.pem'551server # [7346544.544906] server acme-test.foo-start[324]: + cp -vp key.pem ../out/key.pem552server # [7346544.545882] server acme-test.foo-start[324]: 'key.pem' -> '../out/key.pem'553server # [7346544.546073] server acme-test.foo-start[314]: + cat out/cert.pem ca/cert.pem554server # [7346544.547724] server acme-test.foo-start[314]: + cp ca/cert.pem out/chain.pem555server # [7346544.549492] server acme-test.foo-start[314]: + cat out/key.pem out/fullchain.pem556server # [7346544.551035] server acme-test.foo-start[314]: + for fixpath in out certificates557server # [7346544.551035] server acme-test.foo-start[314]: + '[' -d out ']'558server # [7346544.551125] server acme-test.foo-start[314]: + chmod -R u=rwX,g=rX,o= out559server # [7346544.553374] server acme-test.foo-start[314]: + chown -R acme:nginx out560server # [7346544.557007] server acme-test.foo-start[314]: + for fixpath in out certificates561server # [7346544.557063] server acme-test.foo-start[314]: + '[' -d certificates ']'562server # [7346544.560537] server systemd[1]: Finished Ensure certificate for test.foo.563server # [7346544.563966] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...564server # [7346545.113037] server acme-order-renew-test.foo-start[332]: Waiting to acquire lock in /run/acme/565server # [7346545.116024] server acme-order-renew-test.foo-start[332]: + set -euo pipefail566server # [7346545.116092] server acme-order-renew-test.foo-start[332]: + echo ad12aa6741ce4bd2c108567server # [7346545.116198] server acme-order-renew-test.foo-start[332]: + cmp -s domainhash.txt certificates/domainhash.txt568server # [7346545.117269] server acme-order-renew-test.foo-start[332]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run569server # [7346545.162984] server acme-order-renew-test.foo-start[340]: 2026/09/02 00:06:11 [INFO] acme: Registering account for none@none.tld570server # [7346545.390104] server acme-order-renew-test.foo-start[340]: !!!! HEADS UP !!!!571server # [7346545.390104] server acme-order-renew-test.foo-start[340]: Your account credentials have been saved in your572server # [7346545.390104] server acme-order-renew-test.foo-start[340]: configuration directory at "accounts".573server # [7346545.390104] server acme-order-renew-test.foo-start[340]: You should make a secure backup of this folder now. This574server # [7346545.390104] server acme-order-renew-test.foo-start[340]: configuration directory will also contain private keys575server # [7346545.390104] server acme-order-renew-test.foo-start[340]: generated by lego and certificates obtained from the ACME576ca # [7346545.162473] ca step-ca[203]: time="2026-09-02T00:06:11Z" level=info duration="43.56µs" duration-ns=43560 fields.time="2026-09-02T00:06:11Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=8c72811d-0ff3-4431-9722-1d4b44dce2db response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=577ca # [7346545.312776] ca step-ca[203]: time="2026-09-02T00:06:11Z" level=info duration=146.338984ms duration-ns=146338984 fields.time="2026-09-02T00:06:11Z" method=HEAD name=ca nonce=ZTFmRm1MQmVFbEVvUk10S2RybWM0SThjeWFYUmdySG8 path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=9e9a43e5-b377-4ee3-92e5-6194909fc3d3 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=578ca # [7346545.389209] ca step-ca[203]: time="2026-09-02T00:06:11Z" level=info duration=71.55669ms duration-ns=71556690 fields.time="2026-09-02T00:06:11Z" method=POST name=ca nonce=OXBmMG1qM0NRdVpIWW1TRUJ0MjNsc0tZNUZCaWhkNjI path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=50bef868-b8d6-478e-a86b-9ab029597cb7 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/HdqZr9FEojZKy54PADxSFGE1mg1eU8QO/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=579ca # [7346545.409817] ca step-ca[203]: time="2026-09-02T00:06:11Z" level=info duration=15.50249ms duration-ns=15502490 fields.time="2026-09-02T00:06:11Z" method=POST name=ca nonce=Y0I0WW9Na0JwT1NWZjhFRGJmckdlS2VxV2hjYmZOQjI path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=7a73c099-016b-40d3-925a-cf00bca6af36 response="{\"id\":\"caWR0Qu39Ipwt3OQV3RC3XvDT5kDQAMc\",\"status\":\"pending\",\"expires\":\"2026-09-03T00:06:11Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-09-02T00:05:11Z\",\"notAfter\":\"2026-12-01T00:06:11Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/716Gr9GT6dvum4Eavr2Yi8Sa9r8ZKkR0\"],\"finalize\":\"https://ca.foo/acme/acme/order/caWR0Qu39Ipwt3OQV3RC3XvDT5kDQAMc/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=580* Host test.foo:443 was resolved.581* IPv6: 2001:db8:1::3582* IPv4: 192.168.1.3583* Trying [2001:db8:1::3]:443...584* ALPN: curl offers h2,http/1.1585} [5 bytes data]586* TLSv1.3 (OUT), TLS handshake, Client hello (1):587} [1552 bytes data]588* SSL Trust Anchors:589* OpenSSL default paths (fallback)590{ [5 bytes data]591* TLSv1.3 (IN), TLS handshake, Server hello (2):592{ [1210 bytes data]593* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):594{ [1 bytes data]595* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):596{ [19 bytes data]597* TLSv1.3 (IN), TLS handshake, Certificate (11):598{ [1009 bytes data]599* TLSv1.3 (IN), TLS handshake, CERT verify (15):600{ [110 bytes data]601* TLSv1.3 (IN), TLS handshake, Finished (20):602{ [52 bytes data]603* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):604} [1 bytes data]605* TLSv1.3 (OUT), TLS handshake, Finished (20):606} [52 bytes data]607* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey608* ALPN: server accepted h2609* Server certificate:610* subject: CN=test.foo611* start date: Sep 2 00:06:03 2026 GMT612* expire date: Oct 2 00:06:03 2028 GMT613* issuer: CN=minica root ca 0f5f39614* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384615* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384616* subjectAltName: "test.foo" matches cert's "test.foo"617* OpenSSL verify result: 13618* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)619* closing connection #0620curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)621More details here: https://curl.se/docs/sslcerts.html622623curl failed to verify the legitimacy of the server and therefore could not624establish a secure connection to it. To learn more about this situation and625how to fix it, please visit the webpage mentioned above.626server # [7346545.390104] server acme-order-renew-test.foo-start[340]: server. Making regular backups of this folder is ideal.627server # [7346545.390104] server acme-order-renew-test.foo-start[340]: 2026/09/02 00:06:11 [INFO] [test.foo] acme: Obtaining bundled SAN certificate628server # [7346545.498463] server acme-order-renew-test.foo-start[340]: 2026/09/02 00:06:11 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/716Gr9GT6dvum4Eavr2Yi8Sa9r8ZKkR0629server # [7346545.498463] server acme-order-renew-test.foo-start[340]: 2026/09/02 00:06:11 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01630server # [7346545.498527] server acme-order-renew-test.foo-start[340]: 2026/09/02 00:06:11 [INFO] [test.foo] acme: use http-01 solver631server # [7346545.498527] server acme-order-renew-test.foo-start[340]: 2026/09/02 00:06:11 [INFO] [test.foo] acme: Trying to solve HTTP-01632server # [7346545.517314] server acme-order-renew-test.foo-start[340]: 2026/09/02 00:06:11 [INFO] [test.foo] The server validated our request633server # [7346545.518156] server acme-order-renew-test.foo-start[340]: 2026/09/02 00:06:11 [INFO] [test.foo] acme: Validations succeeded; requesting certificates634server # [7346545.542532] server acme-order-renew-test.foo-start[340]: 2026/09/02 00:06:11 [INFO] [test.foo] Server responded with a certificate.635server # [7346545.548100] server acme-order-renew-test.foo-start[332]: + mv domainhash.txt certificates/636server # [7346545.549956] server acme-order-renew-test.foo-start[332]: + touch out/acme-success637server # [7346545.551656] server acme-order-renew-test.foo-start[332]: + cmp -s certificates/test.foo.crt out/fullchain.pem638server # [7346545.552847] server acme-order-renew-test.foo-start[332]: + touch out/renewed639server # [7346545.554195] server acme-order-renew-test.foo-start[332]: + echo Installing new certificate640server # [7346545.554195] server acme-order-renew-test.foo-start[332]: Installing new certificate641server # [7346545.554235] server acme-order-renew-test.foo-start[332]: + cp -vp certificates/test.foo.crt out/fullchain.pem642server # [7346545.555747] server acme-order-renew-test.foo-start[372]: 'certificates/test.foo.crt' -> 'out/fullchain.pem'643server # [7346545.555991] server acme-order-renew-test.foo-start[332]: + cp -vp certificates/test.foo.key out/key.pem644server # [7346545.557542] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.key' -> 'out/key.pem'645server # [7346545.557777] server acme-order-renew-test.foo-start[332]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem646server # [7346545.559312] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem'647server # [7346545.559574] server acme-order-renew-test.foo-start[332]: + ln -sf fullchain.pem out/cert.pem648server # [7346545.561239] server acme-order-renew-test.foo-start[332]: + cat out/key.pem out/fullchain.pem649server # [7346545.563333] server acme-order-renew-test.foo-start[332]: + for fixpath in out certificates650server # [7346545.563360] server acme-order-renew-test.foo-start[332]: + '[' -d out ']'651server # [7346545.563360] server acme-order-renew-test.foo-start[332]: + chmod -R u=rwX,g=rX,o= out652server # [7346545.565063] server acme-order-renew-test.foo-start[332]: + chown -R acme:nginx out653server # [7346545.568182] server acme-order-renew-test.foo-start[332]: + for fixpath in out certificates654server # [7346545.568213] server acme-order-renew-test.foo-start[332]: + '[' -d certificates ']'655server # [7346545.568213] server acme-order-renew-test.foo-start[332]: + chmod -R u=rwX,g=rX,o= certificates656server # [7346545.569795] server acme-order-renew-test.foo-start[332]: + chown -R acme:nginx certificates657server # [7346545.572368] server acme-order-renew-test.foo-start[332]: + chmod -R u=rwX,g=,o= accounts/.658server # [7346545.674206] server systemd[1]: Reloading Nginx Web Server...659server # [7346545.679161] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully.660server # [7346545.679466] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo.661ca # [7346545.497756] ca step-ca[203]: time="2026-09-02T00:06:11Z" level=info duration=27.046007ms duration-ns=27046007 fields.time="2026-09-02T00:06:11Z" method=POST name=ca nonce=cXB4RVVuUVROdkgyekVyOERtQU9SeFVISlF6ZjVFaTM path=/acme/acme/authz/716Gr9GT6dvum4Eavr2Yi8Sa9r8ZKkR0 protocol=HTTP/1.1 referer= remote-address="::1" request-id=da600dfc-516e-44a7-84ae-882d89615e28 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"NAB60wH24W9lnIKaffulSBT3vwFQt9bc\",\"url\":\"https://ca.foo/acme/acme/challenge/716Gr9GT6dvum4Eavr2Yi8Sa9r8ZKkR0/pjD9vWCHnG1k4AFPhbwGWgo5LCQ0OJS3\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"NAB60wH24W9lnIKaffulSBT3vwFQt9bc\",\"url\":\"https://ca.foo/acme/acme/challenge/716Gr9GT6dvum4Eavr2Yi8Sa9r8ZKkR0/DyJsrWcdOMdjvU889X4WxaSDqXUbGO9r\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"NAB60wH24W9lnIKaffulSBT3vwFQt9bc\",\"url\":\"https://ca.foo/acme/acme/challenge/716Gr9GT6dvum4Eavr2Yi8Sa9r8ZKkR0/HcWG4rYnc0NWOED9obDOQhSLTDf7Bpb8\"}],\"wildcard\":false,\"expires\":\"2026-09-03T00:06:11Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=662ca # [7346545.516583] ca step-ca[203]: time="2026-09-02T00:06:11Z" level=info duration=13.877268ms duration-ns=13877268 fields.time="2026-09-02T00:06:11Z" method=POST name=ca nonce=ZUVVRUFmWEhHM0N0RVRnaFdTMjN5QVZWcXA5SzlxeFk path=/acme/acme/challenge/716Gr9GT6dvum4Eavr2Yi8Sa9r8ZKkR0/DyJsrWcdOMdjvU889X4WxaSDqXUbGO9r protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=0e747428-01be-452a-9e85-6b43c9fae8a6 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"NAB60wH24W9lnIKaffulSBT3vwFQt9bc\",\"validated\":\"2026-09-02T00:06:11Z\",\"url\":\"https://ca.foo/acme/acme/challenge/716Gr9GT6dvum4Eavr2Yi8Sa9r8ZKkR0/DyJsrWcdOMdjvU889X4WxaSDqXUbGO9r\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=663ca # [7346545.535009] ca step-ca[203]: time="2026-09-02T00:06:11Z" level=info duration=11.749039ms duration-ns=11749039 fields.time="2026-09-02T00:06:11Z" method=POST name=ca nonce=YzVrbEZ0SGdza3IyM2hXdXE0cDk2dnd6VHhnTnB3UXc path=/acme/acme/order/caWR0Qu39Ipwt3OQV3RC3XvDT5kDQAMc/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=70d9a220-798d-4ae3-8f4b-34f3b6473e02 response="{\"id\":\"caWR0Qu39Ipwt3OQV3RC3XvDT5kDQAMc\",\"status\":\"valid\",\"expires\":\"2026-09-03T00:06:11Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-09-02T00:05:11Z\",\"notAfter\":\"2026-12-01T00:06:11Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/716Gr9GT6dvum4Eavr2Yi8Sa9r8ZKkR0\"],\"finalize\":\"https://ca.foo/acme/acme/order/caWR0Qu39Ipwt3OQV3RC3XvDT5kDQAMc/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/j6goTxsQk2x9sm04qYdCxaC5Yb7ehyNC\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=664ca # [7346545.541843] ca step-ca[203]: time="2026-09-02T00:06:11Z" level=info certificate="MIIB2DCCAX2gAwIBAgIQK4xwFQlFEAQr0eOerNm0tDAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA5MDIwMDA1MTFaFw0yNjEyMDEwMDA2MTFaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEsQIZyTMmWqUG6+YfcCywkMj2D9mfhrk1lgg1+5o5XxGCdG57u6lNAgLV1IqKu7jxZxTBjSC5BOQ5J7A7LK3Px6OBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBRkafT/rIs8UO6lVPYLGcKRHqjaSTAfBgNVHSMEGDAWgBTThQLyCaaAyiyueI8T3i8sUzByczATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSQAwRgIhAN42PLQ/sdkMs3ICB2MUx3GZdmks9UW2Tdtke6jUsXVbAiEA059N8RbwwTVdUDdhazSeq5hgX/IlKihDFpZnxRd9O6s=" duration=3.329885ms duration-ns=3329885 fields.time="2026-09-02T00:06:11Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=dG5UMXJVYWZyb0hVYVF5Y2VmWEtQOGZlWUMxa3pzcHU path=/acme/acme/certificate/j6goTxsQk2x9sm04qYdCxaC5Yb7ehyNC protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=c1c5da57-b585-4f96-99f5-7a8f113aee72 sans="map[dns:[test.foo]]" serial=57885998675482136794250316959859717300 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-09-02T00:05:11Z" valid-to="2026-12-01T00:06:11Z"665server # [7346546.184601] server nginx[390]: nginx: the configuration file /nix/store/ldafm91pv9vld74irca8avm5fh9l2p2m-nginx.conf syntax is ok666server # [7346546.184992] server nginx[390]: nginx: configuration file /nix/store/ldafm91pv9vld74irca8avm5fh9l2p2m-nginx.conf test is successful667* Host test.foo:443 was resolved.668* IPv6: 2001:db8:1::3669* IPv4: 192.168.1.3670* Trying [2001:db8:1::3]:443...671* ALPN: curl offers h2,http/1.1672} [5 bytes data]673* TLSv1.3 (OUT), TLS handshake, Client hello (1):674} [1552 bytes data]675* SSL Trust Anchors:676* OpenSSL default paths (fallback)677{ [5 bytes data]678* TLSv1.3 (IN), TLS handshake, Server hello (2):679{ [1210 bytes data]680* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):681{ [1 bytes data]682* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):683{ [19 bytes data]684* TLSv1.3 (IN), TLS handshake, Certificate (11):685{ [1009 bytes data]686* TLSv1.3 (IN), TLS handshake, CERT verify (15):687{ [111 bytes data]688* TLSv1.3 (IN), TLS handshake, Finished (20):689{ [52 bytes data]690* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):691} [1 bytes data]692* TLSv1.3 (OUT), TLS handshake, Finished (20):693} [52 bytes data]694* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey695* ALPN: server accepted h2696* Server certificate:697* subject: CN=test.foo698* start date: Sep 2 00:06:03 2026 GMT699* expire date: Oct 2 00:06:03 2028 GMT700* issuer: CN=minica root ca 0f5f39701* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384702* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384703* subjectAltName: "test.foo" matches cert's "test.foo"704* OpenSSL verify result: 13705* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)706* closing connection #0707curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)708More details here: https://curl.se/docs/sslcerts.html709710curl failed to verify the legitimacy of the server and therefore could not711establish a secure connection to it. To learn more about this situation and712how to fix it, please visit the webpage mentioned above.713server # [7346546.763249] server systemd[1]: Reloaded Nginx Web Server.714* Host test.foo:443 was resolved.715* IPv6: 2001:db8:1::3716* IPv4: 192.168.1.3717* Trying [2001:db8:1::3]:443...718* ALPN: curl offers h2,http/1.1719} [5 bytes data]720* TLSv1.3 (OUT), TLS handshake, Client hello (1):721} [1552 bytes data]722* SSL Trust Anchors:723* OpenSSL default paths (fallback)724{ [5 bytes data]725* TLSv1.3 (IN), TLS handshake, Server hello (2):726{ [1210 bytes data]727* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):728{ [1 bytes data]729* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):730{ [19 bytes data]731* TLSv1.3 (IN), TLS handshake, Certificate (11):732{ [932 bytes data]733* TLSv1.3 (IN), TLS handshake, CERT verify (15):734{ [79 bytes data]735* TLSv1.3 (IN), TLS handshake, Finished (20):736{ [52 bytes data]737* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):738} [1 bytes data]739* TLSv1.3 (OUT), TLS handshake, Finished (20):740} [52 bytes data]741* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey742* ALPN: server accepted h2743* Server certificate:744* subject: CN=test.foo745* start date: Sep 2 00:05:11 2026 GMT746* expire date: Dec 1 00:06:11 2026 GMT747* issuer: CN=Clan Intermediate CA748* Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256749* Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256750* Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256751* subjectAltName: "test.foo" matches cert's "test.foo"752* OpenSSL verify result: 0753* SSL certificate verified via OpenSSL.754* Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 45774 755 % Total % Received % Xferd Average Speed Time Time Time Current756 Dload Upload Total Spent Left Speed757 0 0 0 0 0 0 0 0 0* using HTTP/2758* [HTTP/2] [1] OPENED stream for https://test.foo/759* [HTTP/2] [1] [:method: GET]760* [HTTP/2] [1] [:scheme: https]761* [HTTP/2] [1] [:authority: test.foo]762* [HTTP/2] [1] [:path: /]763* [HTTP/2] [1] [user-agent: curl/8.21.0]764* [HTTP/2] [1] [accept: */*]765} [5 bytes data]766767768769770771* Request completely sent off772{ [5 bytes data]773* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):774{ [265 bytes data]775* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):776{ [265 bytes data]777778779780781782783784{ [5 bytes data]785100 20 100 20 0 0 876 0 0786* Connection #0 to host test.foo:443 left intact787client: (finished: waiting for success: curl -v https://test.foo, in 3.18 seconds)788client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2789Certificate:790 Data:791 Version: 3 (0x2)792 Serial Number:793 2b:8c:70:15:09:45:10:04:2b:d1:e3:9e:ac:d9:b4:b4794 Signature Algorithm: ecdsa-with-SHA256795 Issuer: CN=Clan Intermediate CA796 Validity797 Not Before: Sep 2 00:05:11 2026 GMT798 Not After : Dec 1 00:06:11 2026 GMT799 Subject: CN=test.foo800 Subject Public Key Info:801 Public Key Algorithm: id-ecPublicKey802 Public-Key: (256 bit)803 pub:804 04:b1:02:19:c9:33:26:5a:a5:06:eb:e6:1f:70:2c:805 b0:90:c8:f6:0f:d9:9f:86:b9:35:96:08:35:fb:9a:806 39:5f:11:82:74:6e:7b:bb:a9:4d:02:02:d5:d4:8a:807 8a:bb:b8:f1:67:14:c1:8d:20:b9:04:e4:39:27:b0:808 3b:2c:ad:cf:c7809 ASN1 OID: prime256v1810 NIST CURVE: P-256811 X509v3 extensions:812 X509v3 Key Usage: critical813 Digital Signature814 X509v3 Extended Key Usage: 815 TLS Web Server Authentication, TLS Web Client Authentication816 X509v3 Subject Key Identifier: 817 64:69:F4:FF:AC:8B:3C:50:EE:A5:54:F6:0B:19:C2:91:1E:A8:DA:49818 X509v3 Authority Key Identifier: 819 D3:85:02:F2:09:A6:80:CA:2C:AE:78:8F:13:DE:2F:2C:53:30:72:73820 X509v3 Subject Alternative Name: 821 DNS:test.foo822 1.3.6.1.4.1.37476.9000.64.1: 823 0......acme..824 Signature Algorithm: ecdsa-with-SHA256825 Signature Value:826 30:46:02:21:00:de:36:3c:b4:3f:b1:d9:0c:b3:72:02:07:63:827 14:c7:71:99:76:69:2c:f5:45:b6:4d:db:64:7b:a8:d4:b1:75:828 5b:02:21:00:d3:9f:4d:f1:16:f0:c1:35:5d:50:37:61:6b:34:829 9e:ab:98:60:5f:f2:25:2a:28:43:16:96:67:c5:17:7d:3b:ab830client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2, in 0.04 seconds)831(finished: run the VM test script, in 13.68 seconds)832test script finished in 16.46s833cleanup834kill NspawnMachine (pid 53)835kill NspawnMachine (pid 54)836kill NspawnMachine (pid 55)837Container ca terminated by signal KILL.838Container client terminated by signal KILL.839Container server terminated by signal KILL.840(finished: cleanup, in 0.44 seconds)