these 173 derivations will be built: /nix/store/036blsc4zrqllkxan7f78dh9gd9ch2zr-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/07182vp9nm48fkgibfn911dbhlvs6isg-vars-check-certificates.drv /nix/store/0c327af2fd5cnkww69224q282fhqif1m-nixos-version.drv /nix/store/55f9lva7k6y69isr6l4606a87783kyj1-system-path.drv /nix/store/0fgv91gxpg863ikjkcqkgvqpdy20k3ss-dbus-1.drv /nix/store/0sggpnpx0hb7ps7mipz1v6p0j50j74f9-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/0zdzqh8g7k3r2bwrjb5s1dj9xvfzj537-etc-hostname.drv /nix/store/10cjbryhq5paprzm1glmzihlq892wip3-etc-hostname.drv /nix/store/avlwy5jy9zv3hhg6afzphr9drn1ry34q-extra-hosts.drv /nix/store/nkmcxp3a6fc4ddajmj6v2glyjzq33blh-string-hosts.drv /nix/store/17212vlrjfmvkqaswkiz14msw9an4lhv-hosts.drv /nix/store/1nk8gzqdwcbys8cscgg83vgibcwy841s-unit-acme-renew-test.foo.timer.drv /nix/store/5mg2klpahqbhhj18pc86bzcjzwryrqag-nixos-tmpfiles.d.drv /nix/store/rv9gkiwp80lshzgggldij33s91qcbhz3-10-acme.conf.drv /nix/store/1nkv0v377n31jy983ily8bqz76grf2f5-tmpfiles.d.drv /nix/store/xp35r326fj62za90d48wq8wc4bkd3kw2-system-path.drv /nix/store/nihq11xlx2x2v5r4qai3r52bnw21ylrw-dbus-1.drv /nix/store/3cvhiixn9p70zaxj52can8zb98c2h82z-X-Restart-Triggers-dbus-broker.drv /nix/store/1r4r6xhvb5z70v8691ynlnk2ndgrjqkv-unit-dbus-broker.service.drv /nix/store/p47hngn6zbdrmdwc5prb4iy0kaw2f2kp-firewall-start.drv /nix/store/1z3aifsiz4y9cs7rbjl3m6bx31jn97b2-firewall-reload.drv /nix/store/zrlrzqqfagjz0jcz42yvi1cj0lw3mjmj-etc-systemd-resolved.conf.drv /nix/store/204dxl6q98aagw0i8wfjp7dag8l7c4kh-X-Reload-Triggers-systemd-resolved.drv /nix/store/206g7s9riiy6lv7v18s759skhyssvl7h-etc-os-release.drv /nix/store/7c1lrgaw59r3wfm255fi7a1wmina4bqz-ca.json.drv /nix/store/r63sd0zwbh0af90rmwx7vh8m0jq0bj8w-X-Restart-Triggers-step-ca.drv /nix/store/225hkfgaw476hz05hcplk7amgb1aq2jw-unit-step-ca.service.drv /nix/store/hrl0sjk0xfm9hw09pm0ink17zwa6ql3w-nginx.conf.drv /nix/store/9pzia84fjf3dp0mlldh1cgys8vzdgakb-unit-script-nginx-pre-start.drv /nix/store/2x27sgxinrwnhrl48vzdw0dnkk8svw33-unit-nginx.service.drv /nix/store/khgs7ihg3g7vh72ix6dxh9ia91y4hjx3-mount-secret-fs.drv /nix/store/346x4w58bsshz20k49dilgs4s18r1hyv-decrypt-age-secrets.drv /nix/store/di1sgdiyzlm65p5kpam2px5qrwg223hx-acme-postrun.drv /nix/store/w7nqaqnlj2zf8lbzf5qy6i2yx8hrw8hs-unit-script-acme-order-renew-test.foo-start.drv /nix/store/35a5msij0380fgxm7ckwqrc2hd9rg2za-unit-acme-order-renew-test.foo.service.drv /nix/store/3qbzpkzqfykrppymh72m1ifiswms94iv-X-Restart-Triggers-acme-test.foo.drv /nix/store/3sa3xcmqapmjqbib7w953639g4pschv1-X-Restart-Triggers-systemd-networkd.drv /nix/store/3x9q456fy4k9p5j89dji9y9mpl6qpj0b-unit-40-eth1.network.drv /nix/store/d8ff6hxagc6l6hin0m2hq0r0nrkvq1nw-etc-systemd-journald.conf.drv /nix/store/pmnycx38zniwbw8hm1bk8ffpyva22z4n-X-Restart-Triggers-systemd-journald.drv /nix/store/40j99f0lg5ah7qm70wni3rcdgc8yvapd-unit-systemd-journald.service.drv /nix/store/41akw2ffnkpsxh6ns0nvpbv9h8122q3m-unit-systemd-timedated.service.drv /nix/store/aablpnhbgk1rgyyikmjz9h0b21kkcpbb-ensure-all-wrappers-paths-exist.drv /nix/store/i7m0gybsphnlx20ymfzaqysx0v3w094p-system-path.drv /nix/store/79wgv1358924zi13p4q1kdh7v81cm9ww-mounts.sh.drv /nix/store/rv3573hrr5mdx1flkrli0b7ywchdw8dc-stage-2-init.sh.drv /nix/store/6w49gzpshs71lyvgsdjs7pjq6md86kla-issue.drv /nix/store/4c69mj6pj2q8zv6g1hr9w9hxjnm5skkk-unit-systemd-fsck-.service.drv /nix/store/w4qdj5p84rmf9r68byxc43sc9yiq2p23-dbus-1.drv /nix/store/xqj7p4mqjc9wdybczp1nz9zdwswrrp3v-X-Restart-Triggers-dbus-broker.drv /nix/store/4r5sl2xj5mcx5s3sw2bc4wx70blbv6b5-unit-dbus-broker.service.drv /nix/store/xhhbkra230h3h37sfmjzrx9pry9wyrd0-unit-40-eth1.network.drv /nix/store/509xd8748dnlngc6nf21aggssb5s0swr-X-Reload-Triggers-systemd-networkd.drv /nix/store/5g0i3ihpykv6r1fx4mw25gs5fs6fgwhb-unit-systemd-networkd.service.drv /nix/store/bjj3534h4wyky0f37a7m2d7n964w54wh-acme-setup-privileged.drv /nix/store/gawjnj6ywdqsjb33sfpdn87jjwh4x030-unit-script-acme-setup-start.drv /nix/store/5h5ima3fyiinwyj2xb2bq3y2dba3lij3-unit-acme-setup.service.drv /nix/store/61vgapasj8nxhaqk3sk97194mj3hg0nj-unit-nginx-config-reload.service.drv /nix/store/6ldnq6arjyd9r09a9mbjyb1g5glhlycm-unit-console-getty.service.drv /nix/store/7yik6sfchavysp6hdgfdqy5f3px4n50d-unit-firewall.service.drv /nix/store/b235wnldakyza7759nqsqcqnswaglih7-unit-script-acme-test.foo-start.drv /nix/store/9wqw1c35dyazfkqk1mb0asw40q50qr0b-unit-acme-test.foo.service.drv /nix/store/ck3idjnbv8mdwy53vxzvw4nks8qb4b7r-unit-serial-getty-ttyAMA0.service-disabled.drv /nix/store/cya14f0ilf8j8xqw8hr52g1k19qggbxj-unit-systemd-resolved.service.drv /nix/store/gsypd4p0iypxmf53bh23b9hyda2kdj15-etc-sysctl.d-60-nixos.conf.drv /nix/store/47flc519dahv34nbbw8kifxgdfvjcdwg-X-Restart-Triggers-systemd-sysctl.drv /nix/store/flkfj59gdkzn377j4vx8j3hz0yfyysy0-unit-systemd-sysctl.service.drv /nix/store/p4nwmvczbf1aramqjbp8g0c1gy66vi7d-shutdown-ramfs-contents.json.drv /nix/store/fx2936y2z43mv5k4anjsbrly8nh8xw93-unit-generate-shutdown-ramfs.service.drv /nix/store/nypkzlrjjxkmh8ihsb5ffv5cmz99ml8w-X-Restart-Triggers-systemd-journald-.drv /nix/store/iwbbqq0szaipxfl6z500g78r2r4am7gm-unit-systemd-journald-.service.drv /nix/store/kicwid2acpsgdyfzmx7wq9a81gv25fw8-unit-nix-optimise.service.drv /nix/store/lg4q0w5rxy73klw02s88fhzr904mmsfh-unit-serial-getty-.service.drv /nix/store/lmhxk40mj9hm6fqxssbrv692r9n6lqbk-unit-resolvconf.service-disabled.drv /nix/store/mwc5c1h7kc7s9yd2kpg9jpah3k92q0j8-unit-serial-getty-hvc0.service-disabled.drv /nix/store/nb6pmnhsmblmjl22yzlv69gpcz1ilb8k-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/nfsb6wnspim9z90liacbz5d5ivf3hvka-unit-suid-sgid-wrappers.service-disabled.drv /nix/store/pghpah75x548w51shvbilx2by5khmw4d-unit-systemd-makefs-.service.drv /nix/store/791h9g6qz4m9cfn07nwzi3aghnz7fc9w-cacert-blocklist.txt.drv /nix/store/v6gnvpsqg2zy7lh9z4y7mrpi1fw5dgw4-cacert-extra-certificates-bundle.crt.drv /nix/store/nklv508p47j1xxshg8c0a97h7m51zsl7-nss-cacert-3.126.drv /nix/store/qpyg3ymybdm6vga454s1q8hhwzf4vplp-nix.conf.drv /nix/store/xkqslb4vv7lakqjgqqfmk2bjpy6qpfcq-X-Restart-Triggers-nix-daemon.drv /nix/store/q1j3dvdlkhd1lbig94fsv172yw2y2hbp-unit-nix-daemon.service.drv /nix/store/q7mn3bk0yndwz8isxqjmlcy5vjsbkn5b-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/s0n4fxc8q9f6zhhg06cy28fjq4bl84n1-unit-systemd-tmpfiles-resetup.service.drv /nix/store/nq99azn1ndbxls4gb7nqjmmvkx440hry-unit-script-nix-gc-start.drv /nix/store/x854xplzbs213rgdkfzqljsdikki38dg-unit-nix-gc.service.drv /nix/store/7apg9mz61s25m2c2zrhxm01w9shd5amd-system-units.drv /nix/store/7f78x2fmrsc9klkk2bnfp2wycywk8rmn-etc-shells.drv /nix/store/89vwpz3bz4fz4damgb9ynfkw7whg8s7p-etc-ssh-ssh_config.drv /nix/store/g8q751dagdaxa2ljj43b6c9agzfq245j-fontconfig-etc.drv /nix/store/h2nswfhm1dlk7xk4z8k9c5ddgbr8a69x-etc-systemd-system.conf.drv /nix/store/xrhb93sk5vaxqsd5p0kpsy0npnhb66ix-set-environment.drv /nix/store/ixfd32bzms4lnna1mnfvdjg3fsk86x02-etc-profile.drv /nix/store/jwsj8l7jnx6i89xg8dqvsyqa1mrnyp6j-useradd.drv /nix/store/n3ppy744kf9khg1vvzv4qfgylgc32zws-etc-systemd-sleep.conf.drv /nix/store/ri012zg7hplgcrszi2sw51y9i5k5hjzn-etc-pam-environment.drv /nix/store/lgk45vajijsh6rkn95gk9p4k35llbqff-unit-dbus-broker.service.drv /nix/store/s8i1msjm157aqwqz225fbd303xcaqz2v-user-units.drv /nix/store/svx4s645mc3j5nfhi30d6sv6lgifv4ny-etc-fstab.drv /nix/store/ngmx324ppgdy1kkqnbc6jjmj2qxp726f-string-hosts.drv /nix/store/vp9kqhkx48jvrr07a7j93914h0njf5jb-hosts.drv /nix/store/vq7y4hrging6m8zivlly08lzk1bdd6sd-etc-systemd-user.conf.drv /nix/store/y45g5n9jahbf13da7nnvn0isalxx9k1v-etc-lvm-lvm.conf.drv /nix/store/y68j8f7ylr7dqq735kv2q9yh6lgzshhz-etc-ssh-ssh_known_hosts.drv /nix/store/yj48gb9bf7a5xmra8d86r67yr0ziafkf-etc-nix-registry.json.drv /nix/store/z5767hi6a200q7kai4ag4a06c6d2lv91-etc-bashrc.drv /nix/store/xazlijk5kcpq06gy3wl9bxldvr3m74f7-etc.drv /nix/store/5jqj162zjfjrmhrjl5bs8al1ynvy5ryz-decrypt-age-secrets.drv /nix/store/yaq1v5mpwvwcmlxjmd2l8xdpbwz0wa70-hashed-password.root.drv /nix/store/znkkq5v4lfmsl9a3bjahlhlrw5d9vrxw-users-groups.json.drv /nix/store/yzr953km1bdy7jf2h2vz3i3mp254q9vq-dry-activate.drv /nix/store/zdg047dgrnc74zc96icz45vib2mn44r9-activate.drv /nix/store/flcvpjjma4jnmlbq4ahigz0q8y3h6b9h-nixos-system-server-test.drv /nix/store/41m0fyk2k53mc7wmycbl2hxwsd2zbxgv-run-server-nspawn.drv /nix/store/4jmsfw3k4gmpf29v59xiy8lg5jj2g454-unit-40-eth1.network.drv /nix/store/qmyis2dzw5mgw8xrk10l8p0yr3v98z34-users-groups.json.drv /nix/store/56w0h3a4fpvg80qy29nsga20p8w05148-dry-activate.drv /nix/store/laiy4wdfcimms3cl04fm3sn937fal9qp-users-groups.json.drv /nix/store/lsmdqplqyqqsad0jad6fiwpp6cn3y7az-X-Reload-Triggers-systemd-networkd.drv /nix/store/98fx6s8m7rp3sp8y3xrcr43pcn5hkbps-unit-systemd-networkd.service.drv /nix/store/s25zfsar9afmppnmhr5p97sa0gvfmn7f-firewall-start.drv /nix/store/mxm71xxx5yfvkwmwi771pmw6iz44nl4y-firewall-reload.drv /nix/store/n8af5xibzvhqggjmph1wbpwbmlc6nsnr-unit-firewall.service.drv /nix/store/gya49ya05hxgyjmw0q3zhv5jqgrqa1iy-nixos-tmpfiles.d.drv /nix/store/icrgzyl3wwpyr7jb8yd2x5wddllzil0m-tmpfiles.d.drv /nix/store/x3m1dsfh6zm5cbgvp1nlwi6vj18nn1k6-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/qgpr7v625jnbdlqhrcd8n30df096078i-unit-systemd-tmpfiles-resetup.service.drv /nix/store/b6cmgxcxaq28cj31v27xh96gqm09ax8m-system-units.drv /nix/store/iz06l0qnliwjxriy68zhlzz32y9ldpxf-etc-hostname.drv /nix/store/bsv76v513ifi8hh3pdjiw7lkq1aa33fb-unit-dbus-broker.service.drv /nix/store/x63hc8x0m0klf52jc7cb8zzlk18n8yli-user-units.drv /nix/store/ywpdy3bm62z849lz8ld26g7v5qgfsav4-etc.drv /nix/store/iqsa6x23cg1x5ccjd8vwdzjdfv6aqfag-activate.drv /nix/store/mj20q92j38nc657gk8v0vzbmwwjparr7-dry-activate.drv /nix/store/dsznz8qxr2wnbirzw35dbydmnp79vqm1-nixos-system-client-test.drv /nix/store/6pi52w6msfh2dsvzs2py7rmq9n6a0vjh-run-client-nspawn.drv /nix/store/6x8vlzfw6a1jwykqww188jzl2wgvirva-unit-nginx-config-reload.service.drv /nix/store/p2pajkvlgbsiqwjk6fr7rara76y5slbm-X-Restart-Triggers-dbus-broker.drv /nix/store/765lb4n55pyp19fkdh5xk7w0p9krr7br-unit-dbus-broker.service.drv /nix/store/jgkn1fj8dvcsa4ny8dg4aznv46za5mvy-system-generators.drv /nix/store/qhjp8r9fvamgbhsi2vllmi94vh41kmhb-nginx-recommended-proxy_set_header-headers.conf.drv /nix/store/jxs8mpphxfvsihamf75vw4xpp33zjq96-nginx.conf.drv /nix/store/p037k6aw6dkczp797q66csvh9gw3wl20-user-generators.drv /nix/store/i2dj4hz76ic7bsjdifxs6ck848im76kx-string-hosts.drv /nix/store/qbsv3xqikz30whfw55dx28jgb2pxkglf-hosts.drv /nix/store/97m1jalfv4s1y5mvy3z6dj0xv0m1zvng-unit-acme-renew-ca.foo.timer.drv /nix/store/ga9j6b9clrzkykvwqnxsjmfsdavcv1ai-unit-dbus-broker.service.drv /nix/store/9f6p9w5xf1g9a8rmdvn87z28xqfbjsjr-X-Restart-Triggers-acme-ca.foo.drv /nix/store/j06h07j5hl1jqwhfrjy1bd3dm5y6ypr3-unit-script-acme-ca.foo-start.drv /nix/store/h7c9v4lnmls01zx9587yy0wvdr953bvn-unit-acme-ca.foo.service.drv /nix/store/y898rkhm36am6993pvcnnaa5laap4y5a-acme-postrun.drv /nix/store/p3bvivbjsggzi4ffpblddgslgf0f7qc2-unit-acme-order-renew-ca.foo.service.drv /nix/store/ppcmml1d42bis7nzxsyx769ahv8b25fb-acme-setup-privileged.drv /nix/store/rql21w9n48yizvh0qwz5z9cqwcan37m4-unit-acme-setup.service.drv /nix/store/ib64ycmmq30p4r13ab6qxdav5rblh91c-unit-script-nginx-pre-start.drv /nix/store/w8zix7a8632j0y0fy0b59mc0xwwvffk6-unit-nginx.service.drv /nix/store/qby0arlghmjjb4r1vy6qw0pz9bmir7p5-X-Reload-Triggers-systemd-networkd.drv /nix/store/xxvrywgz666irh40lbw4m2jd7q1nxkdf-unit-systemd-networkd.service.drv /nix/store/r3bql8cb7q6qbhfyl664arl171bilp2v-system-units.drv /nix/store/wyskiha16j5lfb3b6jsjmy9r4zvy16s9-system-shutdown.drv /nix/store/yar80azcmf9pfvznisxdvzn3v3fllsxx-user-units.drv /nix/store/cpgwkbn7ry1yl26rm3qwvjq3l6c4j95k-etc.drv /nix/store/8i6gac09b42xkzm4f3l155920m1pg0r8-activate.drv /nix/store/ag3gvcdyh6r1qg6xgrlbfnn66cylsiih-nixos-system-ca-test.drv /nix/store/d1asqq2n5mj32zr7bzpwz5a9p9kwhjg6-python3.14-nixos-test-lib-1.0.0.drv /nix/store/dwkb5yjg136a24wsx0jynfsrdpz8p19h-nixos-test-driver-1.1.drv /nix/store/qc93adsfvqp1ykah9sj9gzshblp1lcmb-test-script.drv /nix/store/qdwyawzyrqsfzmj8rhhvphxwkmr5a3pv-run-ca-nspawn.drv /nix/store/svyi7cxnbf3mvb820ycdikpi3bv5ab0x-driverConfiguration.json.drv /nix/store/h5jni7wdzixpmf9b9x1q16agx46jj4pl-nixos-test-driver-certificates.drv /nix/store/jndkr37idfbzpnqkq8m460arbv828g86-container-test-run-certificates.drv these 54 paths will be fetched (50.0 MiB download, 182.8 MiB unpacked): /nix/store/gy9x2syb0ffqyivh3qgbc0b5an6wfqw7-dash-0.5.13.5 /nix/store/3xs5n111fdyzjl495kzwmyk6zac6ph6k-fc-00-nixos-cache.conf /nix/store/5481vlz41b1pjybjjbmimzx3pjrxd2az-fc-10-nixos-rendering.conf /nix/store/h7abm226rmivv3b4hs65si09hdn43q7z-fc-52-nixos-default-fonts.conf /nix/store/7g28cnm3if5q3h0hc482i5833rf1m31i-fc-53-nixos-reject-type1.conf /nix/store/mcjg3ysqamqq75sv1wpgwi9cjzmx6lcr-fc-53-no-bitmaps.conf /nix/store/mfawq4j2pvaj4h80xdsqk2lanrwdrsaw-fc-53-user-aliases.conf /nix/store/b1f25am04sr8vfi9x7kn61mbjihrg3hl-fc-cache /nix/store/3dasan0q8dfvh9k9w38h1h67d37y7h9l-flock-0.4.0 /nix/store/l5cjiblb29r98wn5g3lkh7s9j5ambkz0-fontconfig-conf /nix/store/aakb43z0k7gywf8xqz7lw4ashd7xkv6b-gixy-0.1.21 /nix/store/xl18w48kp2498byp5xf7bg7cx2kplcb0-hicolor-icon-theme-0.18 /nix/store/ym4ihffihssbi4zsgsp4j0p07232qbyi-jbigkit-2.1 /nix/store/m83jgn44gl01c0jc9n7a4zkmpdl821zp-lego-4.35.2 /nix/store/15s822ngb5ik60b2q50317iqz3shq46v-minica-1.1.0 /nix/store/6v63d65lmlayzqpddsckhzy1b9yznalp-netpbm-11.15.3 /nix/store/4h2fccxzs3h5c1ww71ddqji95bgnwi66-netpbm-11.15.3-bin /nix/store/dzs48kkdqfp6lrafhms1gfnh3cnw08xc-netpbm-11.15.3-dev /nix/store/fkdqkdrrn8xnqyqajh1x9l6123fhmbja-nginx-1.30.4 /nix/store/i63i6lmhrzq0fwg8fxid2hnfavb8i3d2-nginx-config-formatter-1.4.0 /nix/store/w40l43ygihy9q79nmvq1nk26rd7qqv7n-nginx-mod-moreheaders-0.40 /nix/store/gyhchka2gri0p0360xiz89wqa15dkn7q-nginx-mod-rtmp-1.2.2 /nix/store/x000drx7p37fwkgfjyy9fjb4p5q743nk-nixos-rebuild-ng-26.11 /nix/store/g00jzi34lq18jqfalq12s2psxr9ln9k6-openssl-3.6.3-man /nix/store/5143c16q2d1qfjspicc8w7wkzbmhrain-openssl-4.0.1 /nix/store/mmac1mzri6djs04wc98cidkql4xwqdwj-pam.d /nix/store/4bpqplazhnba4jcy5jwfk0kkavan8sa5-python3.14-appdirs-1.4.4 /nix/store/rg795q2f38r1mmdfi3qbzv8si8iab1l7-python3.14-buildcatrust-0.5.1 /nix/store/09655jj6sbfrjyxa317qjczdm6ir577x-python3.14-cached-property-2.0.1 /nix/store/kf4fih9l3fyh0mbvpayiljf6f0hms1sl-python3.14-colorama-0.4.6 /nix/store/qzlwxl8a118rw7zal6s7c4xy9baga4hq-python3.14-configargparse-1.7.5 /nix/store/nl83wsqrb5wpsrjxg7jnh41vamic61pz-python3.14-junit-xml-1.9 /nix/store/1y2xjjnypwmbcz54rdh3pqfc9y473vi8-python3.14-ovmfvartool-unstable-2022-09-04 /nix/store/qrv3g723y75k0fsl4gmp7p2m5plb1w0w-python3.14-ptpython-3.0.32 /nix/store/bmx919fsx8i1l6hak9nwbhvdwdili3rj-python3.14-pyparsing-2.4.7 /nix/store/dqw4wzkag2dx1rw3xjxi7q72s6ws5prh-python3.14-remote-pdb-2.1.0 /nix/store/ajv6zbbqf1f60a70h57rfv95bxk5wblc-python3.14-ruff-0.16.4 /nix/store/829d0y93rbjv25sa0id07vi2khwpfr78-python3.14-ty-0.0.75 /nix/store/i0l058zc2cbzs7pjcqcp2zihxkwvabqj-run-nspawn-1.0 /nix/store/0yn5bip297fgy63a8bsv83a0p629qg8s-socat-1.8.1.3 /nix/store/a334pcha90aqvb7ldfpgdywfalr5b1i6-sound-theme-freedesktop-0.8 /nix/store/3ahxigmadhbxwr2fx33x5qwwfs0aj1kb-step-ca-0.30.2 /nix/store/6a8nhs8qs77nbh9fphlmcf7rrbn86wcx-stub-ld-aarch64-unknown-linux-musl /nix/store/4c80gn5yc5z1kjkx6xsyr57pb4n5ikzd-sudoers /nix/store/36rrkx7d10qwrn0cn8pjv09zjbvr5nyz-system-generators /nix/store/3gj2slcqsqndi7awjx95xkfr2ajbsy98-system-shutdown /nix/store/7b8arnagnln57y30hv5mq9n36jp4vr85-systemd-261.2-dev /nix/store/4hflikkibxal03hak61rjyx2x92mj42h-systemd-default-tmpfiles /nix/store/v1l72vhbsqri9hhkq7lc487k5mvrpswn-systemd-generator-environment.json /nix/store/hf0fzlj3pz4iiib6ymrzslj2x11xpd93-user-generators /nix/store/92qvsz35lhi0v4237017z7yi7vhq1c0s-vde2-2.3.3 /nix/store/j5mrcm7bxg02x7405am55h9wdkwaqsl3-vhost-device-vsock-0.3.0 /nix/store/ml5j6krbh643dgrq3hywi1fmfhaz7p1z-xwininfo-1.1.6 /nix/store/h9avm2x8xacpq4fp0skz2aiqkcz8l5ff-zlib-ng-2.3.3 building '/nix/store/hrl0sjk0xfm9hw09pm0ink17zwa6ql3w-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rv9gkiwp80lshzgggldij33s91qcbhz3-10-acme.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/9f6p9w5xf1g9a8rmdvn87z28xqfbjsjr-X-Restart-Triggers-acme-ca.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3qbzpkzqfykrppymh72m1ifiswms94iv-X-Restart-Triggers-acme-test.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/di1sgdiyzlm65p5kpam2px5qrwg223hx-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hrl0sjk0xfm9hw09pm0ink17zwa6ql3w-nginx.conf.drv' nginx.conf> structuredAttrs is enabled nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/47flc519dahv34nbbw8kifxgdfvjcdwg-X-Restart-Triggers-systemd-sysctl.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y898rkhm36am6993pvcnnaa5laap4y5a-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bjj3534h4wyky0f37a7m2d7n964w54wh-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ppcmml1d42bis7nzxsyx769ahv8b25fb-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7c1lrgaw59r3wfm255fi7a1wmina4bqz-ca.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/55f9lva7k6y69isr6l4606a87783kyj1-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/i7m0gybsphnlx20ymfzaqysx0v3w094p-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rv9gkiwp80lshzgggldij33s91qcbhz3-10-acme.conf.drv' building '/nix/store/9f6p9w5xf1g9a8rmdvn87z28xqfbjsjr-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/3qbzpkzqfykrppymh72m1ifiswms94iv-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/di1sgdiyzlm65p5kpam2px5qrwg223hx-acme-postrun.drv' building '/nix/store/346x4w58bsshz20k49dilgs4s18r1hyv-decrypt-age-secrets.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0zdzqh8g7k3r2bwrjb5s1dj9xvfzj537-etc-hostname.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ixfd32bzms4lnna1mnfvdjg3fsk86x02-etc-profile.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bjj3534h4wyky0f37a7m2d7n964w54wh-acme-setup-privileged.drv' building '/nix/store/47flc519dahv34nbbw8kifxgdfvjcdwg-X-Restart-Triggers-systemd-sysctl.drv' building '/nix/store/flkfj59gdkzn377j4vx8j3hz0yfyysy0-unit-systemd-sysctl.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y898rkhm36am6993pvcnnaa5laap4y5a-acme-postrun.drv' building '/nix/store/avlwy5jy9zv3hhg6afzphr9drn1ry34q-extra-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p47hngn6zbdrmdwc5prb4iy0kaw2f2kp-firewall-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qhjp8r9fvamgbhsi2vllmi94vh41kmhb-nginx-recommended-proxy_set_header-headers.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5mg2klpahqbhhj18pc86bzcjzwryrqag-nixos-tmpfiles.d.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/nklv508p47j1xxshg8c0a97h7m51zsl7-nss-cacert-3.126.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p4nwmvczbf1aramqjbp8g0c1gy66vi7d-shutdown-ramfs-contents.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/i2dj4hz76ic7bsjdifxs6ck848im76kx-string-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jgkn1fj8dvcsa4ny8dg4aznv46za5mvy-system-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/xp35r326fj62za90d48wq8wc4bkd3kw2-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wyskiha16j5lfb3b6jsjmy9r4zvy16s9-system-shutdown.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ppcmml1d42bis7nzxsyx769ahv8b25fb-acme-setup-privileged.drv' building '/nix/store/7c1lrgaw59r3wfm255fi7a1wmina4bqz-ca.json.drv' ca.json> structuredAttrs is enabled building '/nix/store/55f9lva7k6y69isr6l4606a87783kyj1-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/i7m0gybsphnlx20ymfzaqysx0v3w094p-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/346x4w58bsshz20k49dilgs4s18r1hyv-decrypt-age-secrets.drv' building '/nix/store/0zdzqh8g7k3r2bwrjb5s1dj9xvfzj537-etc-hostname.drv' building '/nix/store/r63sd0zwbh0af90rmwx7vh8m0jq0bj8w-X-Restart-Triggers-step-ca.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qc93adsfvqp1ykah9sj9gzshblp1lcmb-test-script.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/xhhbkra230h3h37sfmjzrx9pry9wyrd0-unit-40-eth1.network.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/nb6pmnhsmblmjl22yzlv69gpcz1ilb8k-unit-acme-account-2c44cb477b4787b2cf13.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0sggpnpx0hb7ps7mipz1v6p0j50j74f9-unit-acme-account-d22a46d9459bf683a338.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/97m1jalfv4s1y5mvy3z6dj0xv0m1zvng-unit-acme-renew-ca.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/1nk8gzqdwcbys8cscgg83vgibcwy841s-unit-acme-renew-test.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/61vgapasj8nxhaqk3sk97194mj3hg0nj-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ixfd32bzms4lnna1mnfvdjg3fsk86x02-etc-profile.drv' building '/nix/store/0fgv91gxpg863ikjkcqkgvqpdy20k3ss-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/flkfj59gdkzn377j4vx8j3hz0yfyysy0-unit-systemd-sysctl.service.drv' unit-systemd-sysctl.service> structuredAttrs is enabled building '/nix/store/avlwy5jy9zv3hhg6afzphr9drn1ry34q-extra-hosts.drv' building '/nix/store/qhjp8r9fvamgbhsi2vllmi94vh41kmhb-nginx-recommended-proxy_set_header-headers.conf.drv' building '/nix/store/p47hngn6zbdrmdwc5prb4iy0kaw2f2kp-firewall-start.drv' building '/nix/store/5mg2klpahqbhhj18pc86bzcjzwryrqag-nixos-tmpfiles.d.drv' building '/nix/store/1nkv0v377n31jy983ily8bqz76grf2f5-tmpfiles.d.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/w4qdj5p84rmf9r68byxc43sc9yiq2p23-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6x8vlzfw6a1jwykqww188jzl2wgvirva-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/j06h07j5hl1jqwhfrjy1bd3dm5y6ypr3-unit-script-acme-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/036blsc4zrqllkxan7f78dh9gd9ch2zr-unit-script-acme-order-renew-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/w7nqaqnlj2zf8lbzf5qy6i2yx8hrw8hs-unit-script-acme-order-renew-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/gawjnj6ywdqsjb33sfpdn87jjwh4x030-unit-script-acme-setup-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/b235wnldakyza7759nqsqcqnswaglih7-unit-script-acme-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/9pzia84fjf3dp0mlldh1cgys8vzdgakb-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p037k6aw6dkczp797q66csvh9gw3wl20-user-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qmyis2dzw5mgw8xrk10l8p0yr3v98z34-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/i2dj4hz76ic7bsjdifxs6ck848im76kx-string-hosts.drv' building '/nix/store/p4nwmvczbf1aramqjbp8g0c1gy66vi7d-shutdown-ramfs-contents.json.drv' building '/nix/store/nklv508p47j1xxshg8c0a97h7m51zsl7-nss-cacert-3.126.drv' nss-cacert-3.126> structuredAttrs is enabled nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/k4vka17r0mi25andb6xkc2jvmxxba95i-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/k4vka17r0mi25andb6xkc2jvmxxba95i-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/k4vka17r0mi25andb6xkc2jvmxxba95i-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/5q67yjqwfhnawvp1s3qzjym4j07ndg8n-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/5q67yjqwfhnawvp1s3qzjym4j07ndg8n-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/5q67yjqwfhnawvp1s3qzjym4j07ndg8n-nss-cacert-3.126-hashed nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/sm1rla6dnaj4lsmr109byl7vx99p6vl1-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/sm1rla6dnaj4lsmr109byl7vx99p6vl1-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/sm1rla6dnaj4lsmr109byl7vx99p6vl1-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/z76r0dk1gq05fx6irkpny50b3ydfw493-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/z76r0dk1gq05fx6irkpny50b3ydfw493-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/z76r0dk1gq05fx6irkpny50b3ydfw493-nss-cacert-3.126-unbundled building '/nix/store/jgkn1fj8dvcsa4ny8dg4aznv46za5mvy-system-generators.drv' building '/nix/store/wyskiha16j5lfb3b6jsjmy9r4zvy16s9-system-shutdown.drv' building '/nix/store/xp35r326fj62za90d48wq8wc4bkd3kw2-system-path.drv' system-path> structuredAttrs is enabled building '/nix/store/1z3aifsiz4y9cs7rbjl3m6bx31jn97b2-firewall-reload.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/17212vlrjfmvkqaswkiz14msw9an4lhv-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qbsv3xqikz30whfw55dx28jgb2pxkglf-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vp9kqhkx48jvrr07a7j93914h0njf5jb-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jxs8mpphxfvsihamf75vw4xpp33zjq96-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' system-path> created 1718 symlinks in user environment building '/nix/store/fx2936y2z43mv5k4anjsbrly8nh8xw93-unit-generate-shutdown-ramfs.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/q1j3dvdlkhd1lbig94fsv172yw2y2hbp-unit-nix-daemon.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/znkkq5v4lfmsl9a3bjahlhlrw5d9vrxw-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/07182vp9nm48fkgibfn911dbhlvs6isg-vars-check-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/r63sd0zwbh0af90rmwx7vh8m0jq0bj8w-X-Restart-Triggers-step-ca.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/qc93adsfvqp1ykah9sj9gzshblp1lcmb-test-script.drv' building '/nix/store/xhhbkra230h3h37sfmjzrx9pry9wyrd0-unit-40-eth1.network.drv' unit-40-eth1.network> structuredAttrs is enabled building '/nix/store/nb6pmnhsmblmjl22yzlv69gpcz1ilb8k-unit-acme-account-2c44cb477b4787b2cf13.target.drv' unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled building '/nix/store/0sggpnpx0hb7ps7mipz1v6p0j50j74f9-unit-acme-account-d22a46d9459bf683a338.target.drv' unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled building '/nix/store/97m1jalfv4s1y5mvy3z6dj0xv0m1zvng-unit-acme-renew-ca.foo.timer.drv' unit-acme-renew-ca.foo.timer> structuredAttrs is enabled building '/nix/store/1nk8gzqdwcbys8cscgg83vgibcwy841s-unit-acme-renew-test.foo.timer.drv' unit-acme-renew-test.foo.timer> structuredAttrs is enabled building '/nix/store/225hkfgaw476hz05hcplk7amgb1aq2jw-unit-step-ca.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/61vgapasj8nxhaqk3sk97194mj3hg0nj-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/509xd8748dnlngc6nf21aggssb5s0swr-X-Reload-Triggers-systemd-networkd.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0fgv91gxpg863ikjkcqkgvqpdy20k3ss-dbus-1.drv' building '/nix/store/p2pajkvlgbsiqwjk6fr7rara76y5slbm-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/036blsc4zrqllkxan7f78dh9gd9ch2zr-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/p3bvivbjsggzi4ffpblddgslgf0f7qc2-unit-acme-order-renew-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/b235wnldakyza7759nqsqcqnswaglih7-unit-script-acme-test.foo-start.drv' building '/nix/store/17212vlrjfmvkqaswkiz14msw9an4lhv-hosts.drv' building '/nix/store/qbsv3xqikz30whfw55dx28jgb2pxkglf-hosts.drv' building '/nix/store/vp9kqhkx48jvrr07a7j93914h0njf5jb-hosts.drv' building '/nix/store/p037k6aw6dkczp797q66csvh9gw3wl20-user-generators.drv' building '/nix/store/j06h07j5hl1jqwhfrjy1bd3dm5y6ypr3-unit-script-acme-ca.foo-start.drv' building '/nix/store/6x8vlzfw6a1jwykqww188jzl2wgvirva-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/qmyis2dzw5mgw8xrk10l8p0yr3v98z34-users-groups.json.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/w4qdj5p84rmf9r68byxc43sc9yiq2p23-dbus-1.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/nihq11xlx2x2v5r4qai3r52bnw21ylrw-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/jxs8mpphxfvsihamf75vw4xpp33zjq96-nginx.conf.drv' nginx.conf> structuredAttrs is enabled building '/nix/store/56w0h3a4fpvg80qy29nsga20p8w05148-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/1z3aifsiz4y9cs7rbjl3m6bx31jn97b2-firewall-reload.drv' building '/nix/store/h7c9v4lnmls01zx9587yy0wvdr953bvn-unit-acme-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/1nkv0v377n31jy983ily8bqz76grf2f5-tmpfiles.d.drv' building '/nix/store/gawjnj6ywdqsjb33sfpdn87jjwh4x030-unit-script-acme-setup-start.drv' building '/nix/store/q7mn3bk0yndwz8isxqjmlcy5vjsbkn5b-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/w7nqaqnlj2zf8lbzf5qy6i2yx8hrw8hs-unit-script-acme-order-renew-test.foo-start.drv' building '/nix/store/9pzia84fjf3dp0mlldh1cgys8vzdgakb-unit-script-nginx-pre-start.drv' building '/nix/store/9wqw1c35dyazfkqk1mb0asw40q50qr0b-unit-acme-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ib64ycmmq30p4r13ab6qxdav5rblh91c-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/znkkq5v4lfmsl9a3bjahlhlrw5d9vrxw-users-groups.json.drv' building '/nix/store/5h5ima3fyiinwyj2xb2bq3y2dba3lij3-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rql21w9n48yizvh0qwz5z9cqwcan37m4-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7yik6sfchavysp6hdgfdqy5f3px4n50d-unit-firewall.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/xqj7p4mqjc9wdybczp1nz9zdwswrrp3v-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/35a5msij0380fgxm7ckwqrc2hd9rg2za-unit-acme-order-renew-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/fx2936y2z43mv5k4anjsbrly8nh8xw93-unit-generate-shutdown-ramfs.service.drv' unit-generate-shutdown-ramfs.service> structuredAttrs is enabled building '/nix/store/yzr953km1bdy7jf2h2vz3i3mp254q9vq-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/07182vp9nm48fkgibfn911dbhlvs6isg-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/2x27sgxinrwnhrl48vzdw0dnkk8svw33-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/q1j3dvdlkhd1lbig94fsv172yw2y2hbp-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled building '/nix/store/225hkfgaw476hz05hcplk7amgb1aq2jw-unit-step-ca.service.drv' unit-step-ca.service> structuredAttrs is enabled building '/nix/store/509xd8748dnlngc6nf21aggssb5s0swr-X-Reload-Triggers-systemd-networkd.drv' building '/nix/store/5g0i3ihpykv6r1fx4mw25gs5fs6fgwhb-unit-systemd-networkd.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p2pajkvlgbsiqwjk6fr7rara76y5slbm-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/765lb4n55pyp19fkdh5xk7w0p9krr7br-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ga9j6b9clrzkykvwqnxsjmfsdavcv1ai-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p3bvivbjsggzi4ffpblddgslgf0f7qc2-unit-acme-order-renew-ca.foo.service.drv' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled building '/nix/store/nihq11xlx2x2v5r4qai3r52bnw21ylrw-dbus-1.drv' building '/nix/store/3cvhiixn9p70zaxj52can8zb98c2h82z-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/56w0h3a4fpvg80qy29nsga20p8w05148-dry-activate.drv' building '/nix/store/h7c9v4lnmls01zx9587yy0wvdr953bvn-unit-acme-ca.foo.service.drv' unit-acme-ca.foo.service> structuredAttrs is enabled building '/nix/store/ib64ycmmq30p4r13ab6qxdav5rblh91c-unit-script-nginx-pre-start.drv' building '/nix/store/yzr953km1bdy7jf2h2vz3i3mp254q9vq-dry-activate.drv' building '/nix/store/9wqw1c35dyazfkqk1mb0asw40q50qr0b-unit-acme-test.foo.service.drv' unit-acme-test.foo.service> structuredAttrs is enabled building '/nix/store/q7mn3bk0yndwz8isxqjmlcy5vjsbkn5b-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/7yik6sfchavysp6hdgfdqy5f3px4n50d-unit-firewall.service.drv' unit-firewall.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/rql21w9n48yizvh0qwz5z9cqwcan37m4-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/35a5msij0380fgxm7ckwqrc2hd9rg2za-unit-acme-order-renew-test.foo.service.drv' unit-acme-order-renew-test.foo.service> structuredAttrs is enabled building '/nix/store/xqj7p4mqjc9wdybczp1nz9zdwswrrp3v-X-Restart-Triggers-dbus-broker.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/5h5ima3fyiinwyj2xb2bq3y2dba3lij3-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/765lb4n55pyp19fkdh5xk7w0p9krr7br-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/2x27sgxinrwnhrl48vzdw0dnkk8svw33-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/yar80azcmf9pfvznisxdvzn3v3fllsxx-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/w8zix7a8632j0y0fy0b59mc0xwwvffk6-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5g0i3ihpykv6r1fx4mw25gs5fs6fgwhb-unit-systemd-networkd.service.drv' unit-systemd-networkd.service> structuredAttrs is enabled building '/nix/store/4r5sl2xj5mcx5s3sw2bc4wx70blbv6b5-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/lgk45vajijsh6rkn95gk9p4k35llbqff-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/s0n4fxc8q9f6zhhg06cy28fjq4bl84n1-unit-systemd-tmpfiles-resetup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ga9j6b9clrzkykvwqnxsjmfsdavcv1ai-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/3cvhiixn9p70zaxj52can8zb98c2h82z-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/1r4r6xhvb5z70v8691ynlnk2ndgrjqkv-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bsv76v513ifi8hh3pdjiw7lkq1aa33fb-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/w8zix7a8632j0y0fy0b59mc0xwwvffk6-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/yar80azcmf9pfvznisxdvzn3v3fllsxx-user-units.drv' building '/nix/store/lgk45vajijsh6rkn95gk9p4k35llbqff-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/4r5sl2xj5mcx5s3sw2bc4wx70blbv6b5-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/s0n4fxc8q9f6zhhg06cy28fjq4bl84n1-unit-systemd-tmpfiles-resetup.service.drv' unit-systemd-tmpfiles-resetup.service> structuredAttrs is enabled building '/nix/store/7apg9mz61s25m2c2zrhxm01w9shd5amd-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/r3bql8cb7q6qbhfyl664arl171bilp2v-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/s8i1msjm157aqwqz225fbd303xcaqz2v-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/1r4r6xhvb5z70v8691ynlnk2ndgrjqkv-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/bsv76v513ifi8hh3pdjiw7lkq1aa33fb-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/b6cmgxcxaq28cj31v27xh96gqm09ax8m-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/x63hc8x0m0klf52jc7cb8zzlk18n8yli-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7apg9mz61s25m2c2zrhxm01w9shd5amd-system-units.drv' building '/nix/store/r3bql8cb7q6qbhfyl664arl171bilp2v-system-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/s8i1msjm157aqwqz225fbd303xcaqz2v-user-units.drv' building '/nix/store/xazlijk5kcpq06gy3wl9bxldvr3m74f7-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/cpgwkbn7ry1yl26rm3qwvjq3l6c4j95k-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/x63hc8x0m0klf52jc7cb8zzlk18n8yli-user-units.drv' building '/nix/store/b6cmgxcxaq28cj31v27xh96gqm09ax8m-system-units.drv' building '/nix/store/ywpdy3bm62z849lz8ld26g7v5qgfsav4-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/xazlijk5kcpq06gy3wl9bxldvr3m74f7-etc.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/zdg047dgrnc74zc96icz45vib2mn44r9-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ywpdy3bm62z849lz8ld26g7v5qgfsav4-etc.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/iqsa6x23cg1x5ccjd8vwdzjdfv6aqfag-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/cpgwkbn7ry1yl26rm3qwvjq3l6c4j95k-etc.drv' building '/nix/store/8i6gac09b42xkzm4f3l155920m1pg0r8-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/zdg047dgrnc74zc96icz45vib2mn44r9-activate.drv' building '/nix/store/flcvpjjma4jnmlbq4ahigz0q8y3h6b9h-nixos-system-server-test.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/iqsa6x23cg1x5ccjd8vwdzjdfv6aqfag-activate.drv' building '/nix/store/dsznz8qxr2wnbirzw35dbydmnp79vqm1-nixos-system-client-test.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/flcvpjjma4jnmlbq4ahigz0q8y3h6b9h-nixos-system-server-test.drv' nixos-system-server-test> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/41m0fyk2k53mc7wmycbl2hxwsd2zbxgv-run-server-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/8i6gac09b42xkzm4f3l155920m1pg0r8-activate.drv' building '/nix/store/dsznz8qxr2wnbirzw35dbydmnp79vqm1-nixos-system-client-test.drv' nixos-system-client-test> structuredAttrs is enabled building '/nix/store/ag3gvcdyh6r1qg6xgrlbfnn66cylsiih-nixos-system-ca-test.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/6pi52w6msfh2dsvzs2py7rmq9n6a0vjh-run-client-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/41m0fyk2k53mc7wmycbl2hxwsd2zbxgv-run-server-nspawn.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ag3gvcdyh6r1qg6xgrlbfnn66cylsiih-nixos-system-ca-test.drv' nixos-system-ca-test> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/6pi52w6msfh2dsvzs2py7rmq9n6a0vjh-run-client-nspawn.drv' building '/nix/store/qdwyawzyrqsfzmj8rhhvphxwkmr5a3pv-run-ca-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qdwyawzyrqsfzmj8rhhvphxwkmr5a3pv-run-ca-nspawn.drv' building '/nix/store/svyi7cxnbf3mvb820ycdikpi3bv5ab0x-driverConfiguration.json.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/svyi7cxnbf3mvb820ycdikpi3bv5ab0x-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/h5jni7wdzixpmf9b9x1q16agx46jj4pl-nixos-test-driver-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/h5jni7wdzixpmf9b9x1q16agx46jj4pl-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/jndkr37idfbzpnqkq8m460arbv828g86-container-test-run-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jndkr37idfbzpnqkq8m460arbv828g86-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> client: systemd-nspawn running (pid 54) container-test-run-certificates> ca: systemd-nspawn running (pid 53) container-test-run-certificates> server: systemd-nspawn running (pid 55) container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> ca # [7346534.949225] ca systemd-journald[78]: Journal started container-test-run-certificates> ca # [7346534.949284] ca systemd-journald[78]: Runtime Journal (/run/log/journal/be580ce3434e4396b1d36119bc9d5f8a) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> ca # [7346534.953666] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [7346534.961918] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [7346534.953143] client systemd-journald[69]: Journal started container-test-run-certificates> ca # [7346534.962754] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [7346534.953210] client systemd-journald[69]: Runtime Journal (/run/log/journal/84e730bf37bf4b09b31ba71b4ba571fa) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> ca # [7346534.963545] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [7346534.962063] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [7346534.972038] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/be580ce3434e4396b1d36119bc9d5f8a is 1.761ms for 6 entries. container-test-run-certificates> client # [7346534.962793] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [7346534.972038] ca systemd-journald[78]: System Journal (/var/log/journal/be580ce3434e4396b1d36119bc9d5f8a) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [7346534.963560] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [7346534.985827] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [7346534.973145] client systemd-journald[69]: Time spent on flushing to /var/log/journal/84e730bf37bf4b09b31ba71b4ba571fa is 1.785ms for 5 entries. container-test-run-certificates> ca # [7346534.986493] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [7346534.973145] client systemd-journald[69]: System Journal (/var/log/journal/84e730bf37bf4b09b31ba71b4ba571fa) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [7346534.986613] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [7346534.985801] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [7346534.987392] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [7346534.986484] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [7346534.987435] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [7346534.986611] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [7346534.988341] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [7346534.987409] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [7346534.988377] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [7346534.987449] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [7346534.990465] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [7346534.988354] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [7346534.991250] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [7346534.988387] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [7346535.017382] ca systemd-tmpfiles[123]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [7346534.990355] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [7346535.017608] ca systemd-tmpfiles[123]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [7346535.017756] ca systemd-tmpfiles[123]: fchmod() of /var/log/journal/be580ce3434e4396b1d36119bc9d5f8a failed: Operation not permitted container-test-run-certificates> ca # [7346535.017983] ca systemd-tmpfiles[123]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [7346535.019471] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [7346535.020590] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [7346535.021369] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [7346535.032803] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [7346535.038840] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [7346535.039940] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [7346535.050393] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [7346534.953717] server systemd-journald[69]: Journal started container-test-run-certificates> client # [7346534.991250] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [7346534.953772] server systemd-journald[69]: Runtime Journal (/run/log/journal/645c30cb6e2149b88c5ce73ef9aaf8b5) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> client # [7346535.016814] client systemd-tmpfiles[112]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [7346535.017009] client systemd-tmpfiles[112]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [7346534.959136] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [7346535.017139] client systemd-tmpfiles[112]: fchmod() of /var/log/journal/84e730bf37bf4b09b31ba71b4ba571fa failed: Operation not permitted container-test-run-certificates> client # [7346535.017338] client systemd-tmpfiles[112]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [7346535.018836] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [7346535.019969] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [7346535.020790] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> client # [7346535.033279] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [7346535.039364] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [7346535.040840] client systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [7346534.969194] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [7346535.050026] client systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [7346534.970054] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> server # [7346534.970707] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> server # [7346534.978067] server systemd-journald[69]: Time spent on flushing to /var/log/journal/645c30cb6e2149b88c5ce73ef9aaf8b5 is 1.515ms for 6 entries. container-test-run-certificates> server # [7346534.978067] server systemd-journald[69]: System Journal (/var/log/journal/645c30cb6e2149b88c5ce73ef9aaf8b5) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [7346534.992449] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [7346534.993898] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [7346534.995279] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [7346534.995414] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [7346534.996250] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [7346534.996305] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [7346534.997205] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [7346534.998019] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [7346534.998053] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [7346535.016953] server systemd-tmpfiles[116]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [7346535.017147] server systemd-tmpfiles[116]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [7346535.017275] server systemd-tmpfiles[116]: fchmod() of /var/log/journal/645c30cb6e2149b88c5ce73ef9aaf8b5 failed: Operation not permitted container-test-run-certificates> server # [7346535.017472] server systemd-tmpfiles[116]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [7346535.018946] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [7346535.019970] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [7346535.020791] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [7346535.033111] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [7346535.039030] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [7346535.040041] server systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [7346535.049806] server systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [7346535.109345] ca systemd[1]: Finished Firewall. container-test-run-certificates> ca # [7346535.109496] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [7346535.109703] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [7346535.110687] ca systemd[1]: Starting Network Management... container-test-run-certificates> client # [7346535.102011] client systemd[1]: Finished Firewall. container-test-run-certificates> client # [7346535.102627] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [7346535.102911] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [7346535.103993] client systemd[1]: Starting Network Management... container-test-run-certificates> server # [7346535.107185] server systemd[1]: Finished Firewall. container-test-run-certificates> server # [7346535.107272] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [7346535.107490] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [7346535.108467] server systemd[1]: Starting Network Management... container-test-run-certificates> client # [7346535.542734] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [7346535.542825] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [7346535.552180] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [7346535.552349] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [7346535.552503] client systemd-networkd[182]: lo: Link UP container-test-run-certificates> client # [7346535.552507] client systemd-networkd[182]: lo: Gained carrier container-test-run-certificates> client # [7346535.552675] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [7346535.553088] client systemd[1]: Started Network Management. container-test-run-certificates> client # [7346535.553151] client systemd-networkd[182]: eth1: Link UP container-test-run-certificates> client # [7346535.553446] client systemd-networkd[182]: eth1: Gained carrier container-test-run-certificates> client # [7346535.554114] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [7346535.601541] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [7346535.709733] client systemd-resolved[91]: Positive Trust Anchors: container-test-run-certificates> client # [7346535.709745] client systemd-resolved[91]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [7346535.709749] client systemd-resolved[91]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [7346535.709783] client systemd-resolved[91]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [7346535.732309] client systemd-resolved[91]: Using system hostname 'client'. container-test-run-certificates> client # [7346535.733669] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [7346535.733749] client systemd[1]: Reached target Network. container-test-run-certificates> client # [7346535.733820] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [7346535.733872] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [7346535.733907] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [7346535.733924] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [7346535.734054] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [7346535.734171] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [7346535.734283] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [7346535.734306] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [7346535.734343] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [7346535.735423] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [7346535.736323] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [7346535.737698] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [7346535.541116] server systemd-networkd[186]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [7346535.541209] server systemd-networkd[186]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [7346535.550084] server systemd-networkd[186]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [7346535.550266] server systemd-networkd[186]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [7346535.550432] server systemd-networkd[186]: lo: Link UP container-test-run-certificates> server # [7346535.550436] server systemd-networkd[186]: lo: Gained carrier container-test-run-certificates> server # [7346535.550609] server systemd-networkd[186]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [7346535.551010] server systemd[1]: Started Network Management. container-test-run-certificates> server # [7346535.551092] server systemd-networkd[186]: eth1: Link UP container-test-run-certificates> server # [7346535.551341] server systemd-networkd[186]: eth1: Gained carrier container-test-run-certificates> server # [7346535.552055] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [7346535.600776] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [7346535.717183] server systemd-resolved[94]: Positive Trust Anchors: container-test-run-certificates> server # [7346535.717193] server systemd-resolved[94]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [7346535.717196] server systemd-resolved[94]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [7346535.717231] server systemd-resolved[94]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [7346535.739560] server systemd-resolved[94]: Using system hostname 'server'. container-test-run-certificates> server # [7346535.740972] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [7346535.741052] server systemd[1]: Reached target Network. container-test-run-certificates> server # [7346535.741113] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [7346535.741161] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [7346535.741397] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [7346535.741429] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [7346535.741451] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [7346535.741472] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [7346535.741593] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [7346535.741696] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [7346535.741809] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [7346535.741832] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [7346535.741870] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [7346535.873121] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [7346535.554864] ca systemd-networkd[195]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [7346535.554954] ca systemd-networkd[195]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [7346535.561967] ca systemd-networkd[195]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [7346535.562130] ca systemd-networkd[195]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [7346535.562288] ca systemd-networkd[195]: lo: Link UP container-test-run-certificates> ca # [7346535.562292] ca systemd-networkd[195]: lo: Gained carrier container-test-run-certificates> ca # [7346535.562477] ca systemd-networkd[195]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [7346535.562864] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [7346535.592336] ca systemd-networkd[195]: eth1: Link UP container-test-run-certificates> ca # [7346535.592420] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [7346535.592591] ca systemd-networkd[195]: eth1: Gained carrier container-test-run-certificates> ca # [7346535.641385] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [7346535.736789] ca systemd-resolved[100]: Positive Trust Anchors: container-test-run-certificates> ca # [7346535.736801] ca systemd-resolved[100]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [7346535.736804] ca systemd-resolved[100]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [7346535.736839] ca systemd-resolved[100]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [7346535.759015] ca systemd-resolved[100]: Using system hostname 'ca'. container-test-run-certificates> ca # [7346535.760397] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [7346535.760494] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [7346535.760561] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [7346535.760613] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [7346535.760860] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [7346535.760901] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [7346535.760930] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [7346535.760952] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [7346535.761090] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [7346535.761201] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [7346535.761331] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [7346535.761363] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [7346535.761411] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [7346535.873151] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [7346535.874141] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [7346535.874187] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> server # [7346535.874299] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [7346535.875145] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [7346535.874341] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> ca # [7346535.876280] ca systemd[1]: Starting step-ca service... container-test-run-certificates> server # [7346535.875314] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [7346535.877723] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [7346535.876655] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [7346535.894078] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [7346535.894368] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [7346535.976596] ca acme-setup-privileged[200]: + set -euo pipefail container-test-run-certificates> server # [7346535.981280] server acme-setup-privileged[191]: + set -euo pipefail container-test-run-certificates> ca # [7346535.976596] ca acme-setup-privileged[200]: + cd /var/lib/acme container-test-run-certificates> server # [7346535.981280] server acme-setup-privileged[191]: + cd /var/lib/acme container-test-run-certificates> ca # [7346535.977324] ca acme-setup-privileged[200]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> server # [7346535.981591] server acme-setup-privileged[191]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [7346535.978320] ca acme-setup-privileged[200]: + chown -R acme .lego/accounts container-test-run-certificates> server # [7346535.983056] server acme-setup-privileged[191]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [7346535.980364] ca acme-setup-privileged[200]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> server # [7346535.984874] server acme-setup-privileged[191]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> ca # [7346535.980364] ca acme-setup-privileged[200]: + '[' -d ca.foo ']' container-test-run-certificates> server # [7346535.984901] server acme-setup-privileged[191]: + '[' -d test.foo ']' container-test-run-certificates> ca # [7346535.980478] ca acme-setup-privileged[200]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> server # [7346535.984901] server acme-setup-privileged[191]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> ca # [7346535.980478] ca acme-setup-privileged[200]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> server # [7346535.984901] server acme-setup-privileged[191]: + '[' -d .lego/test.foo ']' container-test-run-certificates> ca # [7346536.000956] ca nsncd[202]: Sep 02 00:06:02.054 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [7346536.001147] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [7346536.001231] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [7346536.001356] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [7346536.037279] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [7346536.038245] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [7346536.049922] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [7346536.051087] ca systemd[1]: Started Console Getty. container-test-run-certificates> server # [7346536.006209] server nsncd[193]: Sep 02 00:06:02.059 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [7346536.006225] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [7346536.051139] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [7346536.006336] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [7346536.051162] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [7346536.006448] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [7346536.037533] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [7346536.038778] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [7346536.050133] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [7346536.051418] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [7346536.051462] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [7346536.051478] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [7346536.113026] server dbus-broker-launch[194]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [7346536.113739] server dbus-broker-launch[194]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [7346536.113739] server dbus-broker-launch[194]: Invalid user-name in /nix/store/aszr859gd9lnmlsj2dls188ya32g6xf8-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [7346536.114180] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [7346536.122442] server dbus-broker-launch[194]: Ready container-test-run-certificates> client # [7346535.890140] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [7346536.004661] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [7346536.004732] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [7346536.004796] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [7346536.005558] client nsncd[188]: Sep 02 00:06:02.058 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [7346536.037420] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [7346536.038353] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [7346536.048639] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [7346536.049823] client systemd[1]: Started Console Getty. container-test-run-certificates> client # [7346536.049865] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [7346536.049887] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [7346536.145463] ca dbus-broker-launch[204]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [7346536.146401] ca dbus-broker-launch[204]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [7346536.146401] ca dbus-broker-launch[204]: Invalid user-name in /nix/store/nrvy3kisslkv7qydv3v2ib6szfdky5q3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [7346536.146876] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [7346536.155354] ca dbus-broker-launch[204]: Ready container-test-run-certificates> client # [7346536.216733] client dbus-broker-launch[189]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [7346536.217877] client dbus-broker-launch[189]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [7346536.217877] client dbus-broker-launch[189]: Invalid user-name in /nix/store/ssk8893k9jd7id6pd9yzim0h6prlbdma-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [7346536.218271] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [7346536.225817] client dbus-broker-launch[189]: Ready container-test-run-certificates> client # [7346536.607475] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> client # [7346536.608519] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [7346536.622299] client systemd-logind[204]: New seat seat0. container-test-run-certificates> client # [7346536.622466] client systemd[1]: Started User Login Management. container-test-run-certificates> client # [7346536.660561] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [7346536.673969] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [7346536.674110] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [7346536.674915] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [7346536.675259] client systemd[1]: Startup finished in 2.125s. container-test-run-certificates> ca # [7346536.607277] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [7346536.608374] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [7346536.644543] ca systemd-logind[230]: New seat seat0. container-test-run-certificates> ca # [7346536.644673] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [7346536.661535] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [7346536.673439] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [7346536.673560] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [7346536.704037] ca acme-setup-start[218]: + set -euo pipefail container-test-run-certificates> ca # [7346536.704037] ca acme-setup-start[218]: + test -e ca/key.pem container-test-run-certificates> ca # [7346536.704650] ca acme-setup-start[218]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [7346536.725757] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [7346536.727278] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> ca # [7346536.778060] ca step-ca[203]: badger 2026/09/02 00:06:02 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [7346536.781639] ca step-ca[203]: 2026/09/02 00:06:02 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [7346536.786234] ca step-ca[203]: 2026/09/02 00:06:02 Starting Smallstep CA/0.30.2 (linux/arm64) container-test-run-certificates> ca # [7346536.786234] ca step-ca[203]: 2026/09/02 00:06:02 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [7346536.786234] ca step-ca[203]: 2026/09/02 00:06:02 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [7346536.786234] ca step-ca[203]: 2026/09/02 00:06:02 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [7346536.786318] ca step-ca[203]: 2026/09/02 00:06:02 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [7346536.786318] ca step-ca[203]: 2026/09/02 00:06:02 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [7346536.786318] ca step-ca[203]: 2026/09/02 00:06:02 X.509 Root Fingerprint: e402915422ebb43c74b1cff0df0c2da9405790353a17b701af328fc37ae165a4 container-test-run-certificates> ca # [7346536.786849] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [7346536.787184] ca step-ca[203]: 2026/09/02 00:06:02 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> ca # [7346536.960279] ca systemd-networkd[195]: eth1: Gained IPv6LL container-test-run-certificates> server # [7346536.609524] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [7346536.610527] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [7346536.611239] server systemd-logind[219]: New seat seat0. container-test-run-certificates> server # [7346536.611513] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [7346536.612872] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [7346536.670637] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [7346536.670811] server systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [7346536.706842] server acme-setup-start[207]: + set -euo pipefail container-test-run-certificates> server # [7346536.706842] server acme-setup-start[207]: + test -e ca/key.pem container-test-run-certificates> server # [7346536.707472] server acme-setup-start[207]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [7346536.727824] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [7346536.729533] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> ca # [7346537.206359] ca acme-ca.foo-start[260]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [7346537.208958] ca acme-ca.foo-start[260]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [7346537.209056] ca acme-ca.foo-start[260]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [7346537.223858] ca acme-ca.foo-start[293]: + cd ca.foo container-test-run-certificates> ca # [7346537.223858] ca acme-ca.foo-start[293]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> client # [7346536.864230] client systemd-networkd[182]: eth1: Gained IPv6LL container-test-run-certificates> ca # [7346537.225692] ca acme-ca.foo-start[294]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [7346537.225977] ca acme-ca.foo-start[293]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [7346537.227359] ca acme-ca.foo-start[293]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [7346537.227617] ca acme-ca.foo-start[260]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [7346537.229409] ca acme-ca.foo-start[260]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [7346537.230776] ca acme-ca.foo-start[260]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [7346537.232649] ca acme-ca.foo-start[260]: + for fixpath in out certificates container-test-run-certificates> ca # [7346537.232649] ca acme-ca.foo-start[260]: + '[' -d out ']' container-test-run-certificates> ca # [7346537.232709] ca acme-ca.foo-start[260]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [7346537.234360] ca acme-ca.foo-start[260]: + chown -R acme:nginx out container-test-run-certificates> ca # [7346537.238017] ca acme-ca.foo-start[260]: + for fixpath in out certificates container-test-run-certificates> ca # [7346537.238047] ca acme-ca.foo-start[260]: + '[' -d certificates ']' container-test-run-certificates> ca # [7346537.241209] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [7346537.276563] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> server # [7346537.199558] server acme-test.foo-start[244]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7346537.202699] server acme-test.foo-start[244]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [7346537.202780] server acme-test.foo-start[244]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [7346537.217684] server acme-test.foo-start[254]: + cd test.foo container-test-run-certificates> server # [7346537.218261] server acme-test.foo-start[254]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [7346537.219446] server acme-test.foo-start[255]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [7346537.219772] server acme-test.foo-start[254]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [7346537.221103] server acme-test.foo-start[254]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [7346537.221354] server acme-test.foo-start[244]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [7346537.223247] server acme-test.foo-start[244]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [7346537.224961] server acme-test.foo-start[244]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [7346537.226376] server acme-test.foo-start[244]: + for fixpath in out certificates container-test-run-certificates> server # [7346537.226376] server acme-test.foo-start[244]: + '[' -d out ']' container-test-run-certificates> server # [7346537.226481] server acme-test.foo-start[244]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [7346537.227740] server acme-test.foo-start[244]: + chown -R acme:nginx out container-test-run-certificates> server # [7346537.230564] server acme-test.foo-start[244]: + for fixpath in out certificates container-test-run-certificates> server # [7346537.230564] server acme-test.foo-start[244]: + '[' -d certificates ']' container-test-run-certificates> server # [7346537.233782] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [7346537.235386] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> server # [7346537.572214] server systemd-networkd[186]: eth1: Gained IPv6LL container-test-run-certificates> server # [7346537.766990] server nginx-pre-start[266]: nginx: the configuration file /nix/store/ldafm91pv9vld74irca8avm5fh9l2p2m-nginx.conf syntax is ok container-test-run-certificates> server # [7346537.767289] server nginx-pre-start[266]: nginx: configuration file /nix/store/ldafm91pv9vld74irca8avm5fh9l2p2m-nginx.conf test is successful container-test-run-certificates> server # [7346537.774733] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [7346537.775122] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [7346537.776629] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [7346537.772147] ca nginx-pre-start[305]: nginx: the configuration file /nix/store/x7nyri68sw69z98vv03jd76l8kyd8frn-nginx.conf syntax is ok container-test-run-certificates> ca # [7346537.772759] ca nginx-pre-start[305]: nginx: configuration file /nix/store/x7nyri68sw69z98vv03jd76l8kyd8frn-nginx.conf test is successful container-test-run-certificates> ca # [7346537.777144] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [7346537.777614] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [7346537.779080] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca # [7346538.316302] ca acme-order-renew-ca.foo-start[308]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [7346538.320315] ca acme-order-renew-ca.foo-start[308]: + set -euo pipefail container-test-run-certificates> ca # [7346538.320445] ca acme-order-renew-ca.foo-start[308]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [7346538.320499] ca acme-order-renew-ca.foo-start[308]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [7346538.321954] ca acme-order-renew-ca.foo-start[308]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [7346538.350458] ca acme-order-renew-ca.foo-start[319]: 2026/09/02 00:06:04 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [7346538.350802] ca acme-order-renew-ca.foo-start[319]: 2026/09/02 00:06:04 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [7346538.378294] ca step-ca[203]: time="2026-09-02T00:06:04Z" level=info duration="96.762µs" duration-ns=96762 fields.time="2026-09-02T00:06:04Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=8bce0408-f432-406b-aea5-4b15398525c7 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7346538.378672] ca acme-order-renew-ca.foo-start[319]: 2026/09/02 00:06:04 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [7346538.454289] ca step-ca[203]: time="2026-09-02T00:06:04Z" level=info duration=75.381702ms duration-ns=75381702 fields.time="2026-09-02T00:06:04Z" method=HEAD name=ca nonce=eUtJWmwwMnhxTWdvZHBtcmt1cE1YR0FUSEI2ZjJpd2E path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=5ac7ef45-c1d4-4bf5-9cc8-b06d3e5a8f4b size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7346538.468767] ca step-ca[203]: time="2026-09-02T00:06:04Z" level=info duration=13.23854ms duration-ns=13238540 fields.time="2026-09-02T00:06:04Z" method=POST name=ca nonce=ZE1uVXJOSjZ0ZUx1c2psdUZmSm14d1JsWVFNQ3ZVa1g path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=747baaca-cc47-44a7-a0bc-06369abe108e response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/0vD8GSLQs4Z9Otl6XL6sZaaIVfW66TCx/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7346538.469254] ca acme-order-renew-ca.foo-start[319]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [7346538.469254] ca acme-order-renew-ca.foo-start[319]: Your account credentials have been saved in your container-test-run-certificates> ca # [7346538.469254] ca acme-order-renew-ca.foo-start[319]: configuration directory at "accounts". container-test-run-certificates> ca # [7346538.469254] ca acme-order-renew-ca.foo-start[319]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [7346538.469254] ca acme-order-renew-ca.foo-start[319]: configuration directory will also contain private keys container-test-run-certificates> ca # [7346538.469254] ca acme-order-renew-ca.foo-start[319]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [7346538.469254] ca acme-order-renew-ca.foo-start[319]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [7346538.469254] ca acme-order-renew-ca.foo-start[319]: 2026/09/02 00:06:04 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [7346538.474455] ca step-ca[203]: time="2026-09-02T00:06:04Z" level=info duration=4.528501ms duration-ns=4528501 fields.time="2026-09-02T00:06:04Z" method=POST name=ca nonce=SVd2WjdiU0V6dTc1R2pWdEpIMUJSWjNlZ3dlVG5MYjk path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=4f1f286f-3620-451e-8500-f3a438a4f23c response="{\"id\":\"nA5h9glUeTLGtiCCWzfuyJyoMngL00j5\",\"status\":\"pending\",\"expires\":\"2026-09-03T00:06:04Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-09-02T00:05:04Z\",\"notAfter\":\"2026-12-01T00:06:04Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/MgxCUsNJgmiFHJfOTpqYjWAOUUrR0SfV\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/nA5h9glUeTLGtiCCWzfuyJyoMngL00j5/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7346538.543619] ca step-ca[203]: time="2026-09-02T00:06:04Z" level=info duration=12.179045ms duration-ns=12179045 fields.time="2026-09-02T00:06:04Z" method=POST name=ca nonce=ZHJUQ2FvUVZIMkpWQTlkY3lsQkN4RE5TUTU1eGNkZGE path=/acme/acme/authz/MgxCUsNJgmiFHJfOTpqYjWAOUUrR0SfV protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=153dcf88-664d-4694-bf19-40688011145b response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"trooQbS05nb4XIauXPUgFHwlMI5MH8z3\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/MgxCUsNJgmiFHJfOTpqYjWAOUUrR0SfV/5uIBDdzi8i8l2lfjdzuu7j2GskgXOyoI\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"trooQbS05nb4XIauXPUgFHwlMI5MH8z3\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/MgxCUsNJgmiFHJfOTpqYjWAOUUrR0SfV/1nwf4LB9c0JGXTTYtbb3d8Y6RXxhYf7e\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"trooQbS05nb4XIauXPUgFHwlMI5MH8z3\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/MgxCUsNJgmiFHJfOTpqYjWAOUUrR0SfV/mRy8T2J1N6lwvWFj2ZbKOnJk8EA2o8S6\"}],\"wildcard\":false,\"expires\":\"2026-09-03T00:06:04Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7346538.543901] ca acme-order-renew-ca.foo-start[319]: 2026/09/02 00:06:04 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/MgxCUsNJgmiFHJfOTpqYjWAOUUrR0SfV container-test-run-certificates> ca # [7346538.543901] ca acme-order-renew-ca.foo-start[319]: 2026/09/02 00:06:04 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [7346538.543901] ca acme-order-renew-ca.foo-start[319]: 2026/09/02 00:06:04 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [7346538.543901] ca acme-order-renew-ca.foo-start[319]: 2026/09/02 00:06:04 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [7346538.550317] ca step-ca[203]: time="2026-09-02T00:06:04Z" level=info duration=5.88292ms duration-ns=5882920 fields.time="2026-09-02T00:06:04Z" method=POST name=ca nonce=S3ZpSUhyWmxGWTVQRExFRjFJNndjM3FxaWcwR2ZiUUM path=/acme/acme/challenge/MgxCUsNJgmiFHJfOTpqYjWAOUUrR0SfV/1nwf4LB9c0JGXTTYtbb3d8Y6RXxhYf7e protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=f9309936-de3d-49fe-8d59-72a6af298e3d response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"trooQbS05nb4XIauXPUgFHwlMI5MH8z3\",\"validated\":\"2026-09-02T00:06:04Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/MgxCUsNJgmiFHJfOTpqYjWAOUUrR0SfV/1nwf4LB9c0JGXTTYtbb3d8Y6RXxhYf7e\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7346538.550687] ca acme-order-renew-ca.foo-start[319]: 2026/09/02 00:06:04 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [7346538.550790] ca acme-order-renew-ca.foo-start[319]: 2026/09/02 00:06:04 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [7346538.559213] ca step-ca[203]: time="2026-09-02T00:06:04Z" level=info duration=6.722611ms duration-ns=6722611 fields.time="2026-09-02T00:06:04Z" method=POST name=ca nonce=SER4MFpJNWlMa05ZVFRFMlk2ZzRSOUdjODg1c042d3k path=/acme/acme/order/nA5h9glUeTLGtiCCWzfuyJyoMngL00j5/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=f8793d5a-2593-4a39-97cc-14c1f34ef2a8 response="{\"id\":\"nA5h9glUeTLGtiCCWzfuyJyoMngL00j5\",\"status\":\"valid\",\"expires\":\"2026-09-03T00:06:04Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-09-02T00:05:04Z\",\"notAfter\":\"2026-12-01T00:06:04Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/MgxCUsNJgmiFHJfOTpqYjWAOUUrR0SfV\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/nA5h9glUeTLGtiCCWzfuyJyoMngL00j5/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/OBX5eZfs2nO85Sv3SYB2V1jRd54ALWxY\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7346538.561713] ca step-ca[203]: time="2026-09-02T00:06:04Z" level=info certificate="MIIB1DCCAXqgAwIBAgIRAKNHYche+epsysFdkb62AF4wCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwOTAyMDAwNTA0WhcNMjYxMjAxMDAwNjA0WjARMQ8wDQYDVQQDEwZjYS5mb28wWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAATH1vlwO2EgrPaGhYvfuKYNdD4Cark6M5++KK4P76ewMF9x93VFnM42WiWlcoQQzaIzaHhPV/04/+mEIHq+10A3o4GkMIGhMA4GA1UdDwEB/wQEAwIHgDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHQYDVR0OBBYEFA1NFk7jELgI7FXoLR7wX2R08uzbMB8GA1UdIwQYMBaAFNOFAvIJpoDKLK54jxPeLyxTMHJzMBEGA1UdEQQKMAiCBmNhLmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSAAwRQIhAOwE0pDq1VpjhxtPUeg8qItQkByC+j9XLPpj+oEa9T48AiBXFno4rRWjibMn0r34/KAH8YDxhoiHiOsKcq8yR0kMDw==" duration=1.659622ms duration-ns=1659622 fields.time="2026-09-02T00:06:04Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=cFVoUmlWbkplQnVONkc0NVpLajB6dzJINHlJRnpOVk0 path=/acme/acme/certificate/OBX5eZfs2nO85Sv3SYB2V1jRd54ALWxY protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=d51b42e3-4b90-4337-81c0-1d6ab708c0f8 sans="map[dns:[ca.foo]]" serial=217034799658655037602750749786196279390 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-09-02T00:05:04Z" valid-to="2026-12-01T00:06:04Z" container-test-run-certificates> ca # [7346538.561918] ca acme-order-renew-ca.foo-start[319]: 2026/09/02 00:06:04 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [7346538.569087] ca acme-order-renew-ca.foo-start[308]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [7346538.323960] server acme-order-renew-test.foo-start[269]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7346538.326828] server acme-order-renew-test.foo-start[269]: + set -euo pipefail container-test-run-certificates> server # [7346538.326935] server acme-order-renew-test.foo-start[269]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [7346538.327000] server acme-order-renew-test.foo-start[269]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [7346538.328171] server acme-order-renew-test.foo-start[269]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [7346538.350594] server acme-order-renew-test.foo-start[281]: 2026/09/02 00:06:04 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [7346538.350911] server acme-order-renew-test.foo-start[281]: 2026/09/02 00:06:04 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> server # [7346538.382659] server acme-order-renew-test.foo-start[281]: 2026/09/02 00:06:04 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [7346538.383004] server acme-order-renew-test.foo-start[269]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [7346538.383004] server acme-order-renew-test.foo-start[269]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [7346538.383004] server acme-order-renew-test.foo-start[269]: + exit 10 container-test-run-certificates> server # [7346538.385946] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [7346538.386066] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [7346538.386337] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [7346538.392097] server systemd[1]: Startup finished in 3.841s. container-test-run-certificates> ca # [7346538.571091] ca acme-order-renew-ca.foo-start[308]: + touch out/acme-success container-test-run-certificates> ca # [7346538.572979] ca acme-order-renew-ca.foo-start[308]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [7346538.574289] ca acme-order-renew-ca.foo-start[308]: + touch out/renewed container-test-run-certificates> ca # [7346538.575898] ca acme-order-renew-ca.foo-start[308]: + echo Installing new certificate container-test-run-certificates> ca # [7346538.575898] ca acme-order-renew-ca.foo-start[308]: Installing new certificate container-test-run-certificates> ca # [7346538.575953] ca acme-order-renew-ca.foo-start[308]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [7346538.577245] ca acme-order-renew-ca.foo-start[353]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [7346538.577459] ca acme-order-renew-ca.foo-start[308]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [7346538.579070] ca acme-order-renew-ca.foo-start[354]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [7346538.579343] ca acme-order-renew-ca.foo-start[308]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [7346538.581136] ca acme-order-renew-ca.foo-start[355]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [7346538.581378] ca acme-order-renew-ca.foo-start[308]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [7346538.583200] ca acme-order-renew-ca.foo-start[308]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [7346538.584996] ca acme-order-renew-ca.foo-start[308]: + for fixpath in out certificates container-test-run-certificates> ca # [7346538.585027] ca acme-order-renew-ca.foo-start[308]: + '[' -d out ']' container-test-run-certificates> ca # [7346538.585027] ca acme-order-renew-ca.foo-start[308]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [7346538.586673] ca acme-order-renew-ca.foo-start[308]: + chown -R acme:nginx out container-test-run-certificates> ca # [7346538.589627] ca acme-order-renew-ca.foo-start[308]: + for fixpath in out certificates container-test-run-certificates> ca # [7346538.589657] ca acme-order-renew-ca.foo-start[308]: + '[' -d certificates ']' container-test-run-certificates> ca # [7346538.589657] ca acme-order-renew-ca.foo-start[308]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [7346538.591297] ca acme-order-renew-ca.foo-start[308]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [7346538.593946] ca acme-order-renew-ca.foo-start[308]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [7346538.735327] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [7346538.738764] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [7346538.738925] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca # [7346539.261842] ca nginx[371]: nginx: the configuration file /nix/store/x7nyri68sw69z98vv03jd76l8kyd8frn-nginx.conf syntax is ok container-test-run-certificates> ca # [7346539.262309] ca nginx[371]: nginx: configuration file /nix/store/x7nyri68sw69z98vv03jd76l8kyd8frn-nginx.conf test is successful container-test-run-certificates> ca # [7346539.777700] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [7346539.778128] ca systemd[1]: Startup finished in 5.217s. container-test-run-certificates> ca # [7346540.253911] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 3.89 seconds) container-test-run-certificates> ca # [7346540.741224] ca acme-order-renew-ca.foo-start[386]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [7346540.743877] ca acme-order-renew-ca.foo-start[386]: + set -euo pipefail container-test-run-certificates> ca # [7346540.743947] ca acme-order-renew-ca.foo-start[386]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [7346540.744075] ca acme-order-renew-ca.foo-start[386]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [7346540.745264] ca acme-order-renew-ca.foo-start[386]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [7346540.745264] ca acme-order-renew-ca.foo-start[386]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [7346540.745654] ca acme-order-renew-ca.foo-start[394]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [7346540.748603] ca acme-order-renew-ca.foo-start[386]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [7346540.748678] ca acme-order-renew-ca.foo-start[386]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [7346540.797343] ca step-ca[203]: time="2026-09-02T00:06:06Z" level=info duration="66.4µs" duration-ns=66400 fields.time="2026-09-02T00:06:06Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=6b51fdec-764d-455a-9af6-62c608f321fe response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7346540.797950] ca acme-order-renew-ca.foo-start[395]: 2026/09/02 00:06:06 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [7346540.797950] ca acme-order-renew-ca.foo-start[395]: 2026/09/02 00:06:06 [INFO] [ca.foo] The certificate expires at 2026-12-01T00:06:04Z, the renewal can be performed in 1439h59m37.149129919s: no renewal. container-test-run-certificates> ca # [7346540.798300] ca acme-order-renew-ca.foo-start[386]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [7346540.800258] ca acme-order-renew-ca.foo-start[386]: + touch out/acme-success container-test-run-certificates> ca # [7346540.802037] ca acme-order-renew-ca.foo-start[386]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [7346540.802997] ca acme-order-renew-ca.foo-start[386]: + for fixpath in out certificates container-test-run-certificates> ca # [7346540.802997] ca acme-order-renew-ca.foo-start[386]: + '[' -d out ']' container-test-run-certificates> ca # [7346540.803090] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [7346540.804820] ca acme-order-renew-ca.foo-start[386]: + chown -R acme:nginx out container-test-run-certificates> ca # [7346540.808132] ca acme-order-renew-ca.foo-start[386]: + for fixpath in out certificates container-test-run-certificates> ca # [7346540.808132] ca acme-order-renew-ca.foo-start[386]: + '[' -d certificates ']' container-test-run-certificates> ca # [7346540.808132] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [7346540.809778] ca acme-order-renew-ca.foo-start[386]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [7346540.812729] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [7346540.967103] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [7346540.967322] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [7346543.999934] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [7346544.000335] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [7346544.001668] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [7346544.004159] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.58 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 2 00:06:03 2026 GMT container-test-run-certificates> * expire date: Oct 2 00:06:03 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 0f5f39 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [7346544.524864] server acme-test.foo-start[314]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7346544.527920] server acme-test.foo-start[314]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [7346544.527920] server acme-test.foo-start[314]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [7346544.542965] server acme-test.foo-start[324]: + cd test.foo container-test-run-certificates> server # [7346544.543485] server acme-test.foo-start[324]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [7346544.544602] server acme-test.foo-start[325]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [7346544.544906] server acme-test.foo-start[324]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [7346544.545882] server acme-test.foo-start[324]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [7346544.546073] server acme-test.foo-start[314]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [7346544.547724] server acme-test.foo-start[314]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [7346544.549492] server acme-test.foo-start[314]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [7346544.551035] server acme-test.foo-start[314]: + for fixpath in out certificates container-test-run-certificates> server # [7346544.551035] server acme-test.foo-start[314]: + '[' -d out ']' container-test-run-certificates> server # [7346544.551125] server acme-test.foo-start[314]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [7346544.553374] server acme-test.foo-start[314]: + chown -R acme:nginx out container-test-run-certificates> server # [7346544.557007] server acme-test.foo-start[314]: + for fixpath in out certificates container-test-run-certificates> server # [7346544.557063] server acme-test.foo-start[314]: + '[' -d certificates ']' container-test-run-certificates> server # [7346544.560537] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [7346544.563966] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [7346545.113037] server acme-order-renew-test.foo-start[332]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7346545.116024] server acme-order-renew-test.foo-start[332]: + set -euo pipefail container-test-run-certificates> server # [7346545.116092] server acme-order-renew-test.foo-start[332]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [7346545.116198] server acme-order-renew-test.foo-start[332]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [7346545.117269] server acme-order-renew-test.foo-start[332]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [7346545.162984] server acme-order-renew-test.foo-start[340]: 2026/09/02 00:06:11 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [7346545.390104] server acme-order-renew-test.foo-start[340]: !!!! HEADS UP !!!! container-test-run-certificates> server # [7346545.390104] server acme-order-renew-test.foo-start[340]: Your account credentials have been saved in your container-test-run-certificates> server # [7346545.390104] server acme-order-renew-test.foo-start[340]: configuration directory at "accounts". container-test-run-certificates> server # [7346545.390104] server acme-order-renew-test.foo-start[340]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [7346545.390104] server acme-order-renew-test.foo-start[340]: configuration directory will also contain private keys container-test-run-certificates> server # [7346545.390104] server acme-order-renew-test.foo-start[340]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [7346545.162473] ca step-ca[203]: time="2026-09-02T00:06:11Z" level=info duration="43.56µs" duration-ns=43560 fields.time="2026-09-02T00:06:11Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=8c72811d-0ff3-4431-9722-1d4b44dce2db response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7346545.312776] ca step-ca[203]: time="2026-09-02T00:06:11Z" level=info duration=146.338984ms duration-ns=146338984 fields.time="2026-09-02T00:06:11Z" method=HEAD name=ca nonce=ZTFmRm1MQmVFbEVvUk10S2RybWM0SThjeWFYUmdySG8 path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=9e9a43e5-b377-4ee3-92e5-6194909fc3d3 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7346545.389209] ca step-ca[203]: time="2026-09-02T00:06:11Z" level=info duration=71.55669ms duration-ns=71556690 fields.time="2026-09-02T00:06:11Z" method=POST name=ca nonce=OXBmMG1qM0NRdVpIWW1TRUJ0MjNsc0tZNUZCaWhkNjI path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=50bef868-b8d6-478e-a86b-9ab029597cb7 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/HdqZr9FEojZKy54PADxSFGE1mg1eU8QO/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7346545.409817] ca step-ca[203]: time="2026-09-02T00:06:11Z" level=info duration=15.50249ms duration-ns=15502490 fields.time="2026-09-02T00:06:11Z" method=POST name=ca nonce=Y0I0WW9Na0JwT1NWZjhFRGJmckdlS2VxV2hjYmZOQjI path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=7a73c099-016b-40d3-925a-cf00bca6af36 response="{\"id\":\"caWR0Qu39Ipwt3OQV3RC3XvDT5kDQAMc\",\"status\":\"pending\",\"expires\":\"2026-09-03T00:06:11Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-09-02T00:05:11Z\",\"notAfter\":\"2026-12-01T00:06:11Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/716Gr9GT6dvum4Eavr2Yi8Sa9r8ZKkR0\"],\"finalize\":\"https://ca.foo/acme/acme/order/caWR0Qu39Ipwt3OQV3RC3XvDT5kDQAMc/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [110 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 2 00:06:03 2026 GMT container-test-run-certificates> * expire date: Oct 2 00:06:03 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 0f5f39 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [7346545.390104] server acme-order-renew-test.foo-start[340]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [7346545.390104] server acme-order-renew-test.foo-start[340]: 2026/09/02 00:06:11 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [7346545.498463] server acme-order-renew-test.foo-start[340]: 2026/09/02 00:06:11 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/716Gr9GT6dvum4Eavr2Yi8Sa9r8ZKkR0 container-test-run-certificates> server # [7346545.498463] server acme-order-renew-test.foo-start[340]: 2026/09/02 00:06:11 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [7346545.498527] server acme-order-renew-test.foo-start[340]: 2026/09/02 00:06:11 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [7346545.498527] server acme-order-renew-test.foo-start[340]: 2026/09/02 00:06:11 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [7346545.517314] server acme-order-renew-test.foo-start[340]: 2026/09/02 00:06:11 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [7346545.518156] server acme-order-renew-test.foo-start[340]: 2026/09/02 00:06:11 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [7346545.542532] server acme-order-renew-test.foo-start[340]: 2026/09/02 00:06:11 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [7346545.548100] server acme-order-renew-test.foo-start[332]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [7346545.549956] server acme-order-renew-test.foo-start[332]: + touch out/acme-success container-test-run-certificates> server # [7346545.551656] server acme-order-renew-test.foo-start[332]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [7346545.552847] server acme-order-renew-test.foo-start[332]: + touch out/renewed container-test-run-certificates> server # [7346545.554195] server acme-order-renew-test.foo-start[332]: + echo Installing new certificate container-test-run-certificates> server # [7346545.554195] server acme-order-renew-test.foo-start[332]: Installing new certificate container-test-run-certificates> server # [7346545.554235] server acme-order-renew-test.foo-start[332]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [7346545.555747] server acme-order-renew-test.foo-start[372]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [7346545.555991] server acme-order-renew-test.foo-start[332]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [7346545.557542] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [7346545.557777] server acme-order-renew-test.foo-start[332]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [7346545.559312] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [7346545.559574] server acme-order-renew-test.foo-start[332]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [7346545.561239] server acme-order-renew-test.foo-start[332]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [7346545.563333] server acme-order-renew-test.foo-start[332]: + for fixpath in out certificates container-test-run-certificates> server # [7346545.563360] server acme-order-renew-test.foo-start[332]: + '[' -d out ']' container-test-run-certificates> server # [7346545.563360] server acme-order-renew-test.foo-start[332]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [7346545.565063] server acme-order-renew-test.foo-start[332]: + chown -R acme:nginx out container-test-run-certificates> server # [7346545.568182] server acme-order-renew-test.foo-start[332]: + for fixpath in out certificates container-test-run-certificates> server # [7346545.568213] server acme-order-renew-test.foo-start[332]: + '[' -d certificates ']' container-test-run-certificates> server # [7346545.568213] server acme-order-renew-test.foo-start[332]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [7346545.569795] server acme-order-renew-test.foo-start[332]: + chown -R acme:nginx certificates container-test-run-certificates> server # [7346545.572368] server acme-order-renew-test.foo-start[332]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> server # [7346545.674206] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [7346545.679161] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [7346545.679466] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> ca # [7346545.497756] ca step-ca[203]: time="2026-09-02T00:06:11Z" level=info duration=27.046007ms duration-ns=27046007 fields.time="2026-09-02T00:06:11Z" method=POST name=ca nonce=cXB4RVVuUVROdkgyekVyOERtQU9SeFVISlF6ZjVFaTM path=/acme/acme/authz/716Gr9GT6dvum4Eavr2Yi8Sa9r8ZKkR0 protocol=HTTP/1.1 referer= remote-address="::1" request-id=da600dfc-516e-44a7-84ae-882d89615e28 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"NAB60wH24W9lnIKaffulSBT3vwFQt9bc\",\"url\":\"https://ca.foo/acme/acme/challenge/716Gr9GT6dvum4Eavr2Yi8Sa9r8ZKkR0/pjD9vWCHnG1k4AFPhbwGWgo5LCQ0OJS3\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"NAB60wH24W9lnIKaffulSBT3vwFQt9bc\",\"url\":\"https://ca.foo/acme/acme/challenge/716Gr9GT6dvum4Eavr2Yi8Sa9r8ZKkR0/DyJsrWcdOMdjvU889X4WxaSDqXUbGO9r\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"NAB60wH24W9lnIKaffulSBT3vwFQt9bc\",\"url\":\"https://ca.foo/acme/acme/challenge/716Gr9GT6dvum4Eavr2Yi8Sa9r8ZKkR0/HcWG4rYnc0NWOED9obDOQhSLTDf7Bpb8\"}],\"wildcard\":false,\"expires\":\"2026-09-03T00:06:11Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7346545.516583] ca step-ca[203]: time="2026-09-02T00:06:11Z" level=info duration=13.877268ms duration-ns=13877268 fields.time="2026-09-02T00:06:11Z" method=POST name=ca nonce=ZUVVRUFmWEhHM0N0RVRnaFdTMjN5QVZWcXA5SzlxeFk path=/acme/acme/challenge/716Gr9GT6dvum4Eavr2Yi8Sa9r8ZKkR0/DyJsrWcdOMdjvU889X4WxaSDqXUbGO9r protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=0e747428-01be-452a-9e85-6b43c9fae8a6 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"NAB60wH24W9lnIKaffulSBT3vwFQt9bc\",\"validated\":\"2026-09-02T00:06:11Z\",\"url\":\"https://ca.foo/acme/acme/challenge/716Gr9GT6dvum4Eavr2Yi8Sa9r8ZKkR0/DyJsrWcdOMdjvU889X4WxaSDqXUbGO9r\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7346545.535009] ca step-ca[203]: time="2026-09-02T00:06:11Z" level=info duration=11.749039ms duration-ns=11749039 fields.time="2026-09-02T00:06:11Z" method=POST name=ca nonce=YzVrbEZ0SGdza3IyM2hXdXE0cDk2dnd6VHhnTnB3UXc path=/acme/acme/order/caWR0Qu39Ipwt3OQV3RC3XvDT5kDQAMc/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=70d9a220-798d-4ae3-8f4b-34f3b6473e02 response="{\"id\":\"caWR0Qu39Ipwt3OQV3RC3XvDT5kDQAMc\",\"status\":\"valid\",\"expires\":\"2026-09-03T00:06:11Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-09-02T00:05:11Z\",\"notAfter\":\"2026-12-01T00:06:11Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/716Gr9GT6dvum4Eavr2Yi8Sa9r8ZKkR0\"],\"finalize\":\"https://ca.foo/acme/acme/order/caWR0Qu39Ipwt3OQV3RC3XvDT5kDQAMc/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/j6goTxsQk2x9sm04qYdCxaC5Yb7ehyNC\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7346545.541843] ca step-ca[203]: time="2026-09-02T00:06:11Z" level=info certificate="MIIB2DCCAX2gAwIBAgIQK4xwFQlFEAQr0eOerNm0tDAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA5MDIwMDA1MTFaFw0yNjEyMDEwMDA2MTFaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEsQIZyTMmWqUG6+YfcCywkMj2D9mfhrk1lgg1+5o5XxGCdG57u6lNAgLV1IqKu7jxZxTBjSC5BOQ5J7A7LK3Px6OBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBRkafT/rIs8UO6lVPYLGcKRHqjaSTAfBgNVHSMEGDAWgBTThQLyCaaAyiyueI8T3i8sUzByczATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSQAwRgIhAN42PLQ/sdkMs3ICB2MUx3GZdmks9UW2Tdtke6jUsXVbAiEA059N8RbwwTVdUDdhazSeq5hgX/IlKihDFpZnxRd9O6s=" duration=3.329885ms duration-ns=3329885 fields.time="2026-09-02T00:06:11Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=dG5UMXJVYWZyb0hVYVF5Y2VmWEtQOGZlWUMxa3pzcHU path=/acme/acme/certificate/j6goTxsQk2x9sm04qYdCxaC5Yb7ehyNC protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=c1c5da57-b585-4f96-99f5-7a8f113aee72 sans="map[dns:[test.foo]]" serial=57885998675482136794250316959859717300 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-09-02T00:05:11Z" valid-to="2026-12-01T00:06:11Z" container-test-run-certificates> server # [7346546.184601] server nginx[390]: nginx: the configuration file /nix/store/ldafm91pv9vld74irca8avm5fh9l2p2m-nginx.conf syntax is ok container-test-run-certificates> server # [7346546.184992] server nginx[390]: nginx: configuration file /nix/store/ldafm91pv9vld74irca8avm5fh9l2p2m-nginx.conf test is successful container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 2 00:06:03 2026 GMT container-test-run-certificates> * expire date: Oct 2 00:06:03 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 0f5f39 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [7346546.763249] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [932 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [79 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 2 00:05:11 2026 GMT container-test-run-certificates> * expire date: Dec 1 00:06:11 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 45774 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 876 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 3.18 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> 2b:8c:70:15:09:45:10:04:2b:d1:e3:9e:ac:d9:b4:b4 container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Sep 2 00:05:11 2026 GMT container-test-run-certificates> Not After : Dec 1 00:06:11 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:b1:02:19:c9:33:26:5a:a5:06:eb:e6:1f:70:2c: container-test-run-certificates> b0:90:c8:f6:0f:d9:9f:86:b9:35:96:08:35:fb:9a: container-test-run-certificates> 39:5f:11:82:74:6e:7b:bb:a9:4d:02:02:d5:d4:8a: container-test-run-certificates> 8a:bb:b8:f1:67:14:c1:8d:20:b9:04:e4:39:27:b0: container-test-run-certificates> 3b:2c:ad:cf:c7 container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> 64:69:F4:FF:AC:8B:3C:50:EE:A5:54:F6:0B:19:C2:91:1E:A8:DA:49 container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> D3:85:02:F2:09:A6:80:CA:2C:AE:78:8F:13:DE:2F:2C:53:30:72:73 container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:46:02:21:00:de:36:3c:b4:3f:b1:d9:0c:b3:72:02:07:63: container-test-run-certificates> 14:c7:71:99:76:69:2c:f5:45:b6:4d:db:64:7b:a8:d4:b1:75: container-test-run-certificates> 5b:02:21:00:d3:9f:4d:f1:16:f0:c1:35:5d:50:37:61:6b:34: container-test-run-certificates> 9e:ab:98:60:5f:f2:25:2a:28:43:16:96:67:c5:17:7d:3b:ab container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.04 seconds) container-test-run-certificates> (finished: run the VM test script, in 13.68 seconds) container-test-run-certificates> test script finished in 16.46s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 53) container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> kill NspawnMachine (pid 55) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> Container server terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.44 seconds) post-build step Upload to niks3: ok time=2026-09-02T00:06:17.697Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-09-02T00:06:19.430Z level=INFO msg="Uploading 1 narinfos" time=2026-09-02T00:06:19.757Z level=INFO msg="Upload complete. (2.309s)"