these 175 derivations will be built: /nix/store/036blsc4zrqllkxan7f78dh9gd9ch2zr-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/07182vp9nm48fkgibfn911dbhlvs6isg-vars-check-certificates.drv /nix/store/0c327af2fd5cnkww69224q282fhqif1m-nixos-version.drv /nix/store/55f9lva7k6y69isr6l4606a87783kyj1-system-path.drv /nix/store/0fgv91gxpg863ikjkcqkgvqpdy20k3ss-dbus-1.drv /nix/store/0sggpnpx0hb7ps7mipz1v6p0j50j74f9-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/1nk8gzqdwcbys8cscgg83vgibcwy841s-unit-acme-renew-test.foo.timer.drv /nix/store/di1sgdiyzlm65p5kpam2px5qrwg223hx-acme-postrun.drv /nix/store/w7nqaqnlj2zf8lbzf5qy6i2yx8hrw8hs-unit-script-acme-order-renew-test.foo-start.drv /nix/store/35a5msij0380fgxm7ckwqrc2hd9rg2za-unit-acme-order-renew-test.foo.service.drv /nix/store/d8ff6hxagc6l6hin0m2hq0r0nrkvq1nw-etc-systemd-journald.conf.drv /nix/store/pmnycx38zniwbw8hm1bk8ffpyva22z4n-X-Restart-Triggers-systemd-journald.drv /nix/store/40j99f0lg5ah7qm70wni3rcdgc8yvapd-unit-systemd-journald.service.drv /nix/store/41akw2ffnkpsxh6ns0nvpbv9h8122q3m-unit-systemd-timedated.service.drv /nix/store/4c69mj6pj2q8zv6g1hr9w9hxjnm5skkk-unit-systemd-fsck-.service.drv /nix/store/i7m0gybsphnlx20ymfzaqysx0v3w094p-system-path.drv /nix/store/w4qdj5p84rmf9r68byxc43sc9yiq2p23-dbus-1.drv /nix/store/xqj7p4mqjc9wdybczp1nz9zdwswrrp3v-X-Restart-Triggers-dbus-broker.drv /nix/store/4r5sl2xj5mcx5s3sw2bc4wx70blbv6b5-unit-dbus-broker.service.drv /nix/store/3sa3xcmqapmjqbib7w953639g4pschv1-X-Restart-Triggers-systemd-networkd.drv /nix/store/xhhbkra230h3h37sfmjzrx9pry9wyrd0-unit-40-eth1.network.drv /nix/store/509xd8748dnlngc6nf21aggssb5s0swr-X-Reload-Triggers-systemd-networkd.drv /nix/store/5g0i3ihpykv6r1fx4mw25gs5fs6fgwhb-unit-systemd-networkd.service.drv /nix/store/bjj3534h4wyky0f37a7m2d7n964w54wh-acme-setup-privileged.drv /nix/store/gawjnj6ywdqsjb33sfpdn87jjwh4x030-unit-script-acme-setup-start.drv /nix/store/5h5ima3fyiinwyj2xb2bq3y2dba3lij3-unit-acme-setup.service.drv /nix/store/61vgapasj8nxhaqk3sk97194mj3hg0nj-unit-nginx-config-reload.service.drv /nix/store/6ldnq6arjyd9r09a9mbjyb1g5glhlycm-unit-console-getty.service.drv /nix/store/p47hngn6zbdrmdwc5prb4iy0kaw2f2kp-firewall-start.drv /nix/store/1z3aifsiz4y9cs7rbjl3m6bx31jn97b2-firewall-reload.drv /nix/store/7yik6sfchavysp6hdgfdqy5f3px4n50d-unit-firewall.service.drv /nix/store/3qbzpkzqfykrppymh72m1ifiswms94iv-X-Restart-Triggers-acme-test.foo.drv /nix/store/b235wnldakyza7759nqsqcqnswaglih7-unit-script-acme-test.foo-start.drv /nix/store/9wqw1c35dyazfkqk1mb0asw40q50qr0b-unit-acme-test.foo.service.drv /nix/store/s1q4g3njblrv12v29als39vvg4f753rk-nginx.conf.drv /nix/store/w142xcnwysmrw2pjqis19jg1ikmia9jp-unit-script-nginx-pre-start.drv /nix/store/blvbi6ql6710rbyd771j2s09b3dfd1j8-unit-nginx.service.drv /nix/store/ck3idjnbv8mdwy53vxzvw4nks8qb4b7r-unit-serial-getty-ttyAMA0.service-disabled.drv /nix/store/791h9g6qz4m9cfn07nwzi3aghnz7fc9w-cacert-blocklist.txt.drv /nix/store/v6gnvpsqg2zy7lh9z4y7mrpi1fw5dgw4-cacert-extra-certificates-bundle.crt.drv /nix/store/8vwzf0zl4zs9v9z7cqf6adhnz3j0hrf6-nss-cacert-3.126.drv /nix/store/qpyg3ymybdm6vga454s1q8hhwzf4vplp-nix.conf.drv /nix/store/xkqslb4vv7lakqjgqqfmk2bjpy6qpfcq-X-Restart-Triggers-nix-daemon.drv /nix/store/clh1lkz8vdlrcbp6h6mnyxdw643whbmj-unit-nix-daemon.service.drv /nix/store/zrlrzqqfagjz0jcz42yvi1cj0lw3mjmj-etc-systemd-resolved.conf.drv /nix/store/204dxl6q98aagw0i8wfjp7dag8l7c4kh-X-Reload-Triggers-systemd-resolved.drv /nix/store/cya14f0ilf8j8xqw8hr52g1k19qggbxj-unit-systemd-resolved.service.drv /nix/store/d8a7ilky1sszbwx5zyq01xza4bxhambf-unit-systemd-networkd-wait-online.service-disabled.drv /nix/store/gsypd4p0iypxmf53bh23b9hyda2kdj15-etc-sysctl.d-60-nixos.conf.drv /nix/store/47flc519dahv34nbbw8kifxgdfvjcdwg-X-Restart-Triggers-systemd-sysctl.drv /nix/store/flkfj59gdkzn377j4vx8j3hz0yfyysy0-unit-systemd-sysctl.service.drv /nix/store/206g7s9riiy6lv7v18s759skhyssvl7h-etc-os-release.drv /nix/store/p4nwmvczbf1aramqjbp8g0c1gy66vi7d-shutdown-ramfs-contents.json.drv /nix/store/fx2936y2z43mv5k4anjsbrly8nh8xw93-unit-generate-shutdown-ramfs.service.drv /nix/store/nypkzlrjjxkmh8ihsb5ffv5cmz99ml8w-X-Restart-Triggers-systemd-journald-.drv /nix/store/iwbbqq0szaipxfl6z500g78r2r4am7gm-unit-systemd-journald-.service.drv /nix/store/kicwid2acpsgdyfzmx7wq9a81gv25fw8-unit-nix-optimise.service.drv /nix/store/lg4q0w5rxy73klw02s88fhzr904mmsfh-unit-serial-getty-.service.drv /nix/store/lmhxk40mj9hm6fqxssbrv692r9n6lqbk-unit-resolvconf.service-disabled.drv /nix/store/mwc5c1h7kc7s9yd2kpg9jpah3k92q0j8-unit-serial-getty-hvc0.service-disabled.drv /nix/store/nb6pmnhsmblmjl22yzlv69gpcz1ilb8k-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/nfsb6wnspim9z90liacbz5d5ivf3hvka-unit-suid-sgid-wrappers.service-disabled.drv /nix/store/pghpah75x548w51shvbilx2by5khmw4d-unit-systemd-makefs-.service.drv /nix/store/5mg2klpahqbhhj18pc86bzcjzwryrqag-nixos-tmpfiles.d.drv /nix/store/rv9gkiwp80lshzgggldij33s91qcbhz3-10-acme.conf.drv /nix/store/1nkv0v377n31jy983ily8bqz76grf2f5-tmpfiles.d.drv /nix/store/q7mn3bk0yndwz8isxqjmlcy5vjsbkn5b-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/s0n4fxc8q9f6zhhg06cy28fjq4bl84n1-unit-systemd-tmpfiles-resetup.service.drv /nix/store/nq99azn1ndbxls4gb7nqjmmvkx440hry-unit-script-nix-gc-start.drv /nix/store/x854xplzbs213rgdkfzqljsdikki38dg-unit-nix-gc.service.drv /nix/store/0sk6ks2nbna8kzv6alp54viwvn2d2nwm-system-units.drv /nix/store/0zdzqh8g7k3r2bwrjb5s1dj9xvfzj537-etc-hostname.drv /nix/store/dqvgx3mishwyspmig2fi98lgvzw4n876-ca.json.drv /nix/store/105vgajzp65wlwmkjzw3kjmg9a62dkyy-X-Restart-Triggers-step-ca.drv /nix/store/10cjbryhq5paprzm1glmzihlq892wip3-etc-hostname.drv /nix/store/79wgv1358924zi13p4q1kdh7v81cm9ww-mounts.sh.drv /nix/store/khgs7ihg3g7vh72ix6dxh9ia91y4hjx3-mount-secret-fs.drv /nix/store/9k8c6rc9g9wyv9qw0019g4lbql8pr088-decrypt-age-secrets.drv /nix/store/yaq1v5mpwvwcmlxjmd2l8xdpbwz0wa70-hashed-password.root.drv /nix/store/laiy4wdfcimms3cl04fm3sn937fal9qp-users-groups.json.drv /nix/store/avlwy5jy9zv3hhg6afzphr9drn1ry34q-extra-hosts.drv /nix/store/f1fz88a2dr2nxbc1qz3212629xhprw00-localhost-hosts.drv /nix/store/nkmcxp3a6fc4ddajmj6v2glyjzq33blh-string-hosts.drv /nix/store/17212vlrjfmvkqaswkiz14msw9an4lhv-hosts.drv /nix/store/4jmsfw3k4gmpf29v59xiy8lg5jj2g454-unit-40-eth1.network.drv /nix/store/6w49gzpshs71lyvgsdjs7pjq6md86kla-issue.drv /nix/store/7f78x2fmrsc9klkk2bnfp2wycywk8rmn-etc-shells.drv /nix/store/89vwpz3bz4fz4damgb9ynfkw7whg8s7p-etc-ssh-ssh_config.drv /nix/store/g8q751dagdaxa2ljj43b6c9agzfq245j-fontconfig-etc.drv /nix/store/h2nswfhm1dlk7xk4z8k9c5ddgbr8a69x-etc-systemd-system.conf.drv /nix/store/gya49ya05hxgyjmw0q3zhv5jqgrqa1iy-nixos-tmpfiles.d.drv /nix/store/icrgzyl3wwpyr7jb8yd2x5wddllzil0m-tmpfiles.d.drv /nix/store/xrhb93sk5vaxqsd5p0kpsy0npnhb66ix-set-environment.drv /nix/store/ixfd32bzms4lnna1mnfvdjg3fsk86x02-etc-profile.drv /nix/store/iz06l0qnliwjxriy68zhlzz32y9ldpxf-etc-hostname.drv /nix/store/jwsj8l7jnx6i89xg8dqvsyqa1mrnyp6j-useradd.drv /nix/store/n3ppy744kf9khg1vvzv4qfgylgc32zws-etc-systemd-sleep.conf.drv /nix/store/xp35r326fj62za90d48wq8wc4bkd3kw2-system-path.drv /nix/store/nihq11xlx2x2v5r4qai3r52bnw21ylrw-dbus-1.drv /nix/store/ri012zg7hplgcrszi2sw51y9i5k5hjzn-etc-pam-environment.drv /nix/store/3cvhiixn9p70zaxj52can8zb98c2h82z-X-Restart-Triggers-dbus-broker.drv /nix/store/1r4r6xhvb5z70v8691ynlnk2ndgrjqkv-unit-dbus-broker.service.drv /nix/store/lsmdqplqyqqsad0jad6fiwpp6cn3y7az-X-Reload-Triggers-systemd-networkd.drv /nix/store/98fx6s8m7rp3sp8y3xrcr43pcn5hkbps-unit-systemd-networkd.service.drv /nix/store/s25zfsar9afmppnmhr5p97sa0gvfmn7f-firewall-start.drv /nix/store/mxm71xxx5yfvkwmwi771pmw6iz44nl4y-firewall-reload.drv /nix/store/n8af5xibzvhqggjmph1wbpwbmlc6nsnr-unit-firewall.service.drv /nix/store/x3m1dsfh6zm5cbgvp1nlwi6vj18nn1k6-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/qgpr7v625jnbdlqhrcd8n30df096078i-unit-systemd-tmpfiles-resetup.service.drv /nix/store/rq48kvkc4bi0djs3s604y0kx1v5hp22y-system-units.drv /nix/store/svx4s645mc3j5nfhi30d6sv6lgifv4ny-etc-fstab.drv /nix/store/vq7y4hrging6m8zivlly08lzk1bdd6sd-etc-systemd-user.conf.drv /nix/store/bsv76v513ifi8hh3pdjiw7lkq1aa33fb-unit-dbus-broker.service.drv /nix/store/x63hc8x0m0klf52jc7cb8zzlk18n8yli-user-units.drv /nix/store/y45g5n9jahbf13da7nnvn0isalxx9k1v-etc-lvm-lvm.conf.drv /nix/store/y68j8f7ylr7dqq735kv2q9yh6lgzshhz-etc-ssh-ssh_known_hosts.drv /nix/store/yj48gb9bf7a5xmra8d86r67yr0ziafkf-etc-nix-registry.json.drv /nix/store/z5767hi6a200q7kai4ag4a06c6d2lv91-etc-bashrc.drv /nix/store/v78hv4ayh6ms0fld96152riafjfsvdvn-etc.drv /nix/store/1558mq4pj82bv6gi66zxd3m0m7g4jxqa-activate.drv /nix/store/1qpr37x364y6lmlbrq9dy5idrbw2hp3w-decrypt-age-secrets.drv /nix/store/qhjp8r9fvamgbhsi2vllmi94vh41kmhb-nginx-recommended-proxy_set_header-headers.conf.drv /nix/store/2n9jkw7mdsbl0av1rmpymvbdhksrdga7-nginx.conf.drv /nix/store/3x9q456fy4k9p5j89dji9y9mpl6qpj0b-unit-40-eth1.network.drv /nix/store/znkkq5v4lfmsl9a3bjahlhlrw5d9vrxw-users-groups.json.drv /nix/store/lgk45vajijsh6rkn95gk9p4k35llbqff-unit-dbus-broker.service.drv /nix/store/s8i1msjm157aqwqz225fbd303xcaqz2v-user-units.drv /nix/store/ngmx324ppgdy1kkqnbc6jjmj2qxp726f-string-hosts.drv /nix/store/vp9kqhkx48jvrr07a7j93914h0njf5jb-hosts.drv /nix/store/zqp3v6v1zw8rlby0f3p63cl1nyv000bw-etc.drv /nix/store/94x651m4951vw857h4i737ahp6pm3p7m-activate.drv /nix/store/aablpnhbgk1rgyyikmjz9h0b21kkcpbb-ensure-all-wrappers-paths-exist.drv /nix/store/rv3573hrr5mdx1flkrli0b7ywchdw8dc-stage-2-init.sh.drv /nix/store/ynfyapp5cancgb9wh78nfp5pzxpbjjxn-dry-activate.drv /nix/store/4n487qij50l9n36i30y2xsm3dp1hsfmb-nixos-system-server-test.drv /nix/store/xlb36ixss5wsrxhlz65s5615fpa8vnsm-dry-activate.drv /nix/store/4z9mqnv37274dqwnx2di8jcyqg5zlm15-nixos-system-client-test.drv /nix/store/qmyis2dzw5mgw8xrk10l8p0yr3v98z34-users-groups.json.drv /nix/store/7cv835y8lfj1ahd75a2kl0gwg1igckv8-dry-activate.drv /nix/store/6x8vlzfw6a1jwykqww188jzl2wgvirva-unit-nginx-config-reload.service.drv /nix/store/97m1jalfv4s1y5mvy3z6dj0xv0m1zvng-unit-acme-renew-ca.foo.timer.drv /nix/store/p2pajkvlgbsiqwjk6fr7rara76y5slbm-X-Restart-Triggers-dbus-broker.drv /nix/store/ga9j6b9clrzkykvwqnxsjmfsdavcv1ai-unit-dbus-broker.service.drv /nix/store/kg3f7q9sks9rmxpy683i2accxdpinmr5-unit-script-nginx-pre-start.drv /nix/store/h1gwc83hkwvl0rjd94kw42spiqryfhls-unit-nginx.service.drv /nix/store/9f6p9w5xf1g9a8rmdvn87z28xqfbjsjr-X-Restart-Triggers-acme-ca.foo.drv /nix/store/j06h07j5hl1jqwhfrjy1bd3dm5y6ypr3-unit-script-acme-ca.foo-start.drv /nix/store/h7c9v4lnmls01zx9587yy0wvdr953bvn-unit-acme-ca.foo.service.drv /nix/store/i37iqa1gansd71k9j9lqdwjxlrc4wa9x-unit-step-ca.service.drv /nix/store/y898rkhm36am6993pvcnnaa5laap4y5a-acme-postrun.drv /nix/store/p3bvivbjsggzi4ffpblddgslgf0f7qc2-unit-acme-order-renew-ca.foo.service.drv /nix/store/ppcmml1d42bis7nzxsyx769ahv8b25fb-acme-setup-privileged.drv /nix/store/rql21w9n48yizvh0qwz5z9cqwcan37m4-unit-acme-setup.service.drv /nix/store/qby0arlghmjjb4r1vy6qw0pz9bmir7p5-X-Reload-Triggers-systemd-networkd.drv /nix/store/xxvrywgz666irh40lbw4m2jd7q1nxkdf-unit-systemd-networkd.service.drv /nix/store/6yyaajv4ydh9sb2ldkfqfjvhyh2asphj-system-units.drv /nix/store/jgkn1fj8dvcsa4ny8dg4aznv46za5mvy-system-generators.drv /nix/store/p037k6aw6dkczp797q66csvh9gw3wl20-user-generators.drv /nix/store/i2dj4hz76ic7bsjdifxs6ck848im76kx-string-hosts.drv /nix/store/qbsv3xqikz30whfw55dx28jgb2pxkglf-hosts.drv /nix/store/wyskiha16j5lfb3b6jsjmy9r4zvy16s9-system-shutdown.drv /nix/store/765lb4n55pyp19fkdh5xk7w0p9krr7br-unit-dbus-broker.service.drv /nix/store/yar80azcmf9pfvznisxdvzn3v3fllsxx-user-units.drv /nix/store/n9m6yrmi1bgvh2fa9g25i5x0q778h8kl-etc.drv /nix/store/f1i894vgx4z35046b215fcw4pi8dfg6z-activate.drv /nix/store/p86nmrfis21ydi033srxllc9np8anx6m-nixos-system-ca-test.drv /nix/store/892zn6m6xna13fvn0mbblx9rgqmdl1jv-run-ca-nspawn.drv /nix/store/diz1grnvcw5vkpnzmnpgdd6ykvbfg3ha-run-client-nspawn.drv /nix/store/g7sm2xzml8vxkdlsysws3aa6f2bjs4f3-run-server-nspawn.drv /nix/store/qc93adsfvqp1ykah9sj9gzshblp1lcmb-test-script.drv /nix/store/7imf41s45m3d0sqrgvvx423220cjazap-driverConfiguration.json.drv /nix/store/d1asqq2n5mj32zr7bzpwz5a9p9kwhjg6-python3.14-nixos-test-lib-1.0.0.drv /nix/store/mk21ibfp18fb31kxyss5mafm9y9ic953-nixos-test-driver-1.1.drv /nix/store/5ykkf4ybywbqihk5a9qyn2lwg5km6gdd-nixos-test-driver-certificates.drv /nix/store/611vvaxrp8gh6am5zmx6vs99005gkisw-container-test-run-certificates.drv these 3 paths will be fetched (22.2 MiB download, 72.9 MiB unpacked): /nix/store/g00jzi34lq18jqfalq12s2psxr9ln9k6-openssl-3.6.3-man /nix/store/rg795q2f38r1mmdfi3qbzv8si8iab1l7-python3.14-buildcatrust-0.5.1 /nix/store/3ahxigmadhbxwr2fx33x5qwwfs0aj1kb-step-ca-0.30.2 building '/nix/store/9f6p9w5xf1g9a8rmdvn87z28xqfbjsjr-X-Restart-Triggers-acme-ca.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3qbzpkzqfykrppymh72m1ifiswms94iv-X-Restart-Triggers-acme-test.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/9f6p9w5xf1g9a8rmdvn87z28xqfbjsjr-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/61vgapasj8nxhaqk3sk97194mj3hg0nj-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6x8vlzfw6a1jwykqww188jzl2wgvirva-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kicwid2acpsgdyfzmx7wq9a81gv25fw8-unit-nix-optimise.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/lmhxk40mj9hm6fqxssbrv692r9n6lqbk-unit-resolvconf.service-disabled.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/j06h07j5hl1jqwhfrjy1bd3dm5y6ypr3-unit-script-acme-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3qbzpkzqfykrppymh72m1ifiswms94iv-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/61vgapasj8nxhaqk3sk97194mj3hg0nj-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/6x8vlzfw6a1jwykqww188jzl2wgvirva-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/kicwid2acpsgdyfzmx7wq9a81gv25fw8-unit-nix-optimise.service.drv' unit-nix-optimise.service> structuredAttrs is enabled building '/nix/store/lmhxk40mj9hm6fqxssbrv692r9n6lqbk-unit-resolvconf.service-disabled.drv' building '/nix/store/j06h07j5hl1jqwhfrjy1bd3dm5y6ypr3-unit-script-acme-ca.foo-start.drv' building '/nix/store/di1sgdiyzlm65p5kpam2px5qrwg223hx-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/55f9lva7k6y69isr6l4606a87783kyj1-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/di1sgdiyzlm65p5kpam2px5qrwg223hx-acme-postrun.drv' building '/nix/store/55f9lva7k6y69isr6l4606a87783kyj1-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/y898rkhm36am6993pvcnnaa5laap4y5a-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0fgv91gxpg863ikjkcqkgvqpdy20k3ss-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ppcmml1d42bis7nzxsyx769ahv8b25fb-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dqvgx3mishwyspmig2fi98lgvzw4n876-ca.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y898rkhm36am6993pvcnnaa5laap4y5a-acme-postrun.drv' building '/nix/store/0fgv91gxpg863ikjkcqkgvqpdy20k3ss-dbus-1.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/p2pajkvlgbsiqwjk6fr7rara76y5slbm-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ppcmml1d42bis7nzxsyx769ahv8b25fb-acme-setup-privileged.drv' building '/nix/store/rql21w9n48yizvh0qwz5z9cqwcan37m4-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dqvgx3mishwyspmig2fi98lgvzw4n876-ca.json.drv' ca.json> structuredAttrs is enabled building '/nix/store/105vgajzp65wlwmkjzw3kjmg9a62dkyy-X-Restart-Triggers-step-ca.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p2pajkvlgbsiqwjk6fr7rara76y5slbm-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/765lb4n55pyp19fkdh5xk7w0p9krr7br-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ga9j6b9clrzkykvwqnxsjmfsdavcv1ai-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rql21w9n48yizvh0qwz5z9cqwcan37m4-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/105vgajzp65wlwmkjzw3kjmg9a62dkyy-X-Restart-Triggers-step-ca.drv' building '/nix/store/i37iqa1gansd71k9j9lqdwjxlrc4wa9x-unit-step-ca.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/765lb4n55pyp19fkdh5xk7w0p9krr7br-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ga9j6b9clrzkykvwqnxsjmfsdavcv1ai-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/i37iqa1gansd71k9j9lqdwjxlrc4wa9x-unit-step-ca.service.drv' unit-step-ca.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/bjj3534h4wyky0f37a7m2d7n964w54wh-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/791h9g6qz4m9cfn07nwzi3aghnz7fc9w-cacert-blocklist.txt.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0sggpnpx0hb7ps7mipz1v6p0j50j74f9-unit-acme-account-d22a46d9459bf683a338.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/h7c9v4lnmls01zx9587yy0wvdr953bvn-unit-acme-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/97m1jalfv4s1y5mvy3z6dj0xv0m1zvng-unit-acme-renew-ca.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/1nk8gzqdwcbys8cscgg83vgibcwy841s-unit-acme-renew-test.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7yik6sfchavysp6hdgfdqy5f3px4n50d-unit-firewall.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bjj3534h4wyky0f37a7m2d7n964w54wh-acme-setup-privileged.drv' building '/nix/store/wyskiha16j5lfb3b6jsjmy9r4zvy16s9-system-shutdown.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5h5ima3fyiinwyj2xb2bq3y2dba3lij3-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/791h9g6qz4m9cfn07nwzi3aghnz7fc9w-cacert-blocklist.txt.drv' building '/nix/store/h7c9v4lnmls01zx9587yy0wvdr953bvn-unit-acme-ca.foo.service.drv' unit-acme-ca.foo.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/1qpr37x364y6lmlbrq9dy5idrbw2hp3w-decrypt-age-secrets.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/0sggpnpx0hb7ps7mipz1v6p0j50j74f9-unit-acme-account-d22a46d9459bf683a338.target.drv' unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled building '/nix/store/97m1jalfv4s1y5mvy3z6dj0xv0m1zvng-unit-acme-renew-ca.foo.timer.drv' unit-acme-renew-ca.foo.timer> structuredAttrs is enabled building '/nix/store/1nk8gzqdwcbys8cscgg83vgibcwy841s-unit-acme-renew-test.foo.timer.drv' unit-acme-renew-test.foo.timer> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/7yik6sfchavysp6hdgfdqy5f3px4n50d-unit-firewall.service.drv' unit-firewall.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/5h5ima3fyiinwyj2xb2bq3y2dba3lij3-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/wyskiha16j5lfb3b6jsjmy9r4zvy16s9-system-shutdown.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/1qpr37x364y6lmlbrq9dy5idrbw2hp3w-decrypt-age-secrets.drv' building '/nix/store/0zdzqh8g7k3r2bwrjb5s1dj9xvfzj537-etc-hostname.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/0zdzqh8g7k3r2bwrjb5s1dj9xvfzj537-etc-hostname.drv' building '/nix/store/avlwy5jy9zv3hhg6afzphr9drn1ry34q-extra-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/2n9jkw7mdsbl0av1rmpymvbdhksrdga7-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/s1q4g3njblrv12v29als39vvg4f753rk-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/avlwy5jy9zv3hhg6afzphr9drn1ry34q-extra-hosts.drv' building '/nix/store/17212vlrjfmvkqaswkiz14msw9an4lhv-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vp9kqhkx48jvrr07a7j93914h0njf5jb-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/vp9kqhkx48jvrr07a7j93914h0njf5jb-hosts.drv' building '/nix/store/17212vlrjfmvkqaswkiz14msw9an4lhv-hosts.drv' building '/nix/store/2n9jkw7mdsbl0av1rmpymvbdhksrdga7-nginx.conf.drv' nginx.conf> structuredAttrs is enabled building '/nix/store/nb6pmnhsmblmjl22yzlv69gpcz1ilb8k-unit-acme-account-2c44cb477b4787b2cf13.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/036blsc4zrqllkxan7f78dh9gd9ch2zr-unit-script-acme-order-renew-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/s1q4g3njblrv12v29als39vvg4f753rk-nginx.conf.drv' nginx.conf> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/kg3f7q9sks9rmxpy683i2accxdpinmr5-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/w142xcnwysmrw2pjqis19jg1ikmia9jp-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kg3f7q9sks9rmxpy683i2accxdpinmr5-unit-script-nginx-pre-start.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/nb6pmnhsmblmjl22yzlv69gpcz1ilb8k-unit-acme-account-2c44cb477b4787b2cf13.target.drv' unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/036blsc4zrqllkxan7f78dh9gd9ch2zr-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/h1gwc83hkwvl0rjd94kw42spiqryfhls-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/w142xcnwysmrw2pjqis19jg1ikmia9jp-unit-script-nginx-pre-start.drv' building '/nix/store/blvbi6ql6710rbyd771j2s09b3dfd1j8-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/8vwzf0zl4zs9v9z7cqf6adhnz3j0hrf6-nss-cacert-3.126.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/i2dj4hz76ic7bsjdifxs6ck848im76kx-string-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/blvbi6ql6710rbyd771j2s09b3dfd1j8-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/8vwzf0zl4zs9v9z7cqf6adhnz3j0hrf6-nss-cacert-3.126.drv' nss-cacert-3.126> structuredAttrs is enabled nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/lfsxiqcshjj2c2z0bbvcbxkbn55mkgpq-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/lfsxiqcshjj2c2z0bbvcbxkbn55mkgpq-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/lfsxiqcshjj2c2z0bbvcbxkbn55mkgpq-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/6jqqamk35idanan9mirmgvh1l1yvd7n7-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/6jqqamk35idanan9mirmgvh1l1yvd7n7-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/6jqqamk35idanan9mirmgvh1l1yvd7n7-nss-cacert-3.126-hashed nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/4z43i8j042aw6yz9shlhfaj8fln6fm90-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/4z43i8j042aw6yz9shlhfaj8fln6fm90-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/4z43i8j042aw6yz9shlhfaj8fln6fm90-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/lgizlvyqwxyijj95di09c0ydsdxd9v9b-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/lgizlvyqwxyijj95di09c0ydsdxd9v9b-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/lgizlvyqwxyijj95di09c0ydsdxd9v9b-nss-cacert-3.126-unbundled building '/nix/store/i2dj4hz76ic7bsjdifxs6ck848im76kx-string-hosts.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/qbsv3xqikz30whfw55dx28jgb2pxkglf-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/h1gwc83hkwvl0rjd94kw42spiqryfhls-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/clh1lkz8vdlrcbp6h6mnyxdw643whbmj-unit-nix-daemon.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jgkn1fj8dvcsa4ny8dg4aznv46za5mvy-system-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/i7m0gybsphnlx20ymfzaqysx0v3w094p-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qbsv3xqikz30whfw55dx28jgb2pxkglf-hosts.drv' building '/nix/store/i7m0gybsphnlx20ymfzaqysx0v3w094p-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/xp35r326fj62za90d48wq8wc4bkd3kw2-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/jgkn1fj8dvcsa4ny8dg4aznv46za5mvy-system-generators.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/xp35r326fj62za90d48wq8wc4bkd3kw2-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/w4qdj5p84rmf9r68byxc43sc9yiq2p23-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/clh1lkz8vdlrcbp6h6mnyxdw643whbmj-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled building '/nix/store/qc93adsfvqp1ykah9sj9gzshblp1lcmb-test-script.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p3bvivbjsggzi4ffpblddgslgf0f7qc2-unit-acme-order-renew-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/w4qdj5p84rmf9r68byxc43sc9yiq2p23-dbus-1.drv' building '/nix/store/xqj7p4mqjc9wdybczp1nz9zdwswrrp3v-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/nihq11xlx2x2v5r4qai3r52bnw21ylrw-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/p3bvivbjsggzi4ffpblddgslgf0f7qc2-unit-acme-order-renew-ca.foo.service.drv' building '/nix/store/qc93adsfvqp1ykah9sj9gzshblp1lcmb-test-script.drv' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/w7nqaqnlj2zf8lbzf5qy6i2yx8hrw8hs-unit-script-acme-order-renew-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/b235wnldakyza7759nqsqcqnswaglih7-unit-script-acme-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/xqj7p4mqjc9wdybczp1nz9zdwswrrp3v-X-Restart-Triggers-dbus-broker.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/nihq11xlx2x2v5r4qai3r52bnw21ylrw-dbus-1.drv' building '/nix/store/4r5sl2xj5mcx5s3sw2bc4wx70blbv6b5-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/lgk45vajijsh6rkn95gk9p4k35llbqff-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/4r5sl2xj5mcx5s3sw2bc4wx70blbv6b5-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/w7nqaqnlj2zf8lbzf5qy6i2yx8hrw8hs-unit-script-acme-order-renew-test.foo-start.drv' building '/nix/store/lgk45vajijsh6rkn95gk9p4k35llbqff-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/3cvhiixn9p70zaxj52can8zb98c2h82z-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/b235wnldakyza7759nqsqcqnswaglih7-unit-script-acme-test.foo-start.drv' building '/nix/store/35a5msij0380fgxm7ckwqrc2hd9rg2za-unit-acme-order-renew-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6yyaajv4ydh9sb2ldkfqfjvhyh2asphj-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/p037k6aw6dkczp797q66csvh9gw3wl20-user-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/yar80azcmf9pfvznisxdvzn3v3fllsxx-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qmyis2dzw5mgw8xrk10l8p0yr3v98z34-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/znkkq5v4lfmsl9a3bjahlhlrw5d9vrxw-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/07182vp9nm48fkgibfn911dbhlvs6isg-vars-check-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/s8i1msjm157aqwqz225fbd303xcaqz2v-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/9wqw1c35dyazfkqk1mb0asw40q50qr0b-unit-acme-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/35a5msij0380fgxm7ckwqrc2hd9rg2za-unit-acme-order-renew-test.foo.service.drv' unit-acme-order-renew-test.foo.service> structuredAttrs is enabled building '/nix/store/6yyaajv4ydh9sb2ldkfqfjvhyh2asphj-system-units.drv' building '/nix/store/3cvhiixn9p70zaxj52can8zb98c2h82z-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/p037k6aw6dkczp797q66csvh9gw3wl20-user-generators.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/07182vp9nm48fkgibfn911dbhlvs6isg-vars-check-certificates.drv' building '/nix/store/qmyis2dzw5mgw8xrk10l8p0yr3v98z34-users-groups.json.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/yar80azcmf9pfvznisxdvzn3v3fllsxx-user-units.drv' building '/nix/store/znkkq5v4lfmsl9a3bjahlhlrw5d9vrxw-users-groups.json.drv' building '/nix/store/7cv835y8lfj1ahd75a2kl0gwg1igckv8-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/9wqw1c35dyazfkqk1mb0asw40q50qr0b-unit-acme-test.foo.service.drv' unit-acme-test.foo.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ynfyapp5cancgb9wh78nfp5pzxpbjjxn-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/7cv835y8lfj1ahd75a2kl0gwg1igckv8-dry-activate.drv' building '/nix/store/n9m6yrmi1bgvh2fa9g25i5x0q778h8kl-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ynfyapp5cancgb9wh78nfp5pzxpbjjxn-dry-activate.drv' building '/nix/store/s8i1msjm157aqwqz225fbd303xcaqz2v-user-units.drv' building '/nix/store/0sk6ks2nbna8kzv6alp54viwvn2d2nwm-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/1r4r6xhvb5z70v8691ynlnk2ndgrjqkv-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bsv76v513ifi8hh3pdjiw7lkq1aa33fb-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/n9m6yrmi1bgvh2fa9g25i5x0q778h8kl-etc.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/f1i894vgx4z35046b215fcw4pi8dfg6z-activate.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/bsv76v513ifi8hh3pdjiw7lkq1aa33fb-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/0sk6ks2nbna8kzv6alp54viwvn2d2nwm-system-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/x63hc8x0m0klf52jc7cb8zzlk18n8yli-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/1r4r6xhvb5z70v8691ynlnk2ndgrjqkv-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/zqp3v6v1zw8rlby0f3p63cl1nyv000bw-etc.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/x63hc8x0m0klf52jc7cb8zzlk18n8yli-user-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/f1i894vgx4z35046b215fcw4pi8dfg6z-activate.drv' building '/nix/store/p86nmrfis21ydi033srxllc9np8anx6m-nixos-system-ca-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rq48kvkc4bi0djs3s604y0kx1v5hp22y-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/zqp3v6v1zw8rlby0f3p63cl1nyv000bw-etc.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/p86nmrfis21ydi033srxllc9np8anx6m-nixos-system-ca-test.drv' nixos-system-ca-test> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/94x651m4951vw857h4i737ahp6pm3p7m-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/892zn6m6xna13fvn0mbblx9rgqmdl1jv-run-ca-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/892zn6m6xna13fvn0mbblx9rgqmdl1jv-run-ca-nspawn.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/94x651m4951vw857h4i737ahp6pm3p7m-activate.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/rq48kvkc4bi0djs3s604y0kx1v5hp22y-system-units.drv' building '/nix/store/v78hv4ayh6ms0fld96152riafjfsvdvn-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/4n487qij50l9n36i30y2xsm3dp1hsfmb-nixos-system-server-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v78hv4ayh6ms0fld96152riafjfsvdvn-etc.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/1558mq4pj82bv6gi66zxd3m0m7g4jxqa-activate.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/4n487qij50l9n36i30y2xsm3dp1hsfmb-nixos-system-server-test.drv' nixos-system-server-test> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/g7sm2xzml8vxkdlsysws3aa6f2bjs4f3-run-server-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/g7sm2xzml8vxkdlsysws3aa6f2bjs4f3-run-server-nspawn.drv' building '/nix/store/1558mq4pj82bv6gi66zxd3m0m7g4jxqa-activate.drv' building '/nix/store/4z9mqnv37274dqwnx2di8jcyqg5zlm15-nixos-system-client-test.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/4z9mqnv37274dqwnx2di8jcyqg5zlm15-nixos-system-client-test.drv' nixos-system-client-test> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/diz1grnvcw5vkpnzmnpgdd6ykvbfg3ha-run-client-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/diz1grnvcw5vkpnzmnpgdd6ykvbfg3ha-run-client-nspawn.drv' building '/nix/store/7imf41s45m3d0sqrgvvx423220cjazap-driverConfiguration.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7imf41s45m3d0sqrgvvx423220cjazap-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/5ykkf4ybywbqihk5a9qyn2lwg5km6gdd-nixos-test-driver-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/5ykkf4ybywbqihk5a9qyn2lwg5km6gdd-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! building '/nix/store/611vvaxrp8gh6am5zmx6vs99005gkisw-container-test-run-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/611vvaxrp8gh6am5zmx6vs99005gkisw-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> ca: systemd-nspawn running (pid 53) container-test-run-certificates> client: systemd-nspawn running (pid 54) container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> server: systemd-nspawn running (pid 56) container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> ca # [7451232.530956] ca systemd-journald[78]: Journal started container-test-run-certificates> ca # [7451232.531013] ca systemd-journald[78]: Runtime Journal (/run/log/journal/9469826fe7d94086b350cb3425d07d49) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> ca # [7451232.532020] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [7451232.541955] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [7451232.542850] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [7451232.543532] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [7451232.551445] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/9469826fe7d94086b350cb3425d07d49 is 1.121ms for 6 entries. container-test-run-certificates> ca # [7451232.551445] ca systemd-journald[78]: System Journal (/var/log/journal/9469826fe7d94086b350cb3425d07d49) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [7451232.563578] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [7451232.564232] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [7451232.564355] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [7451232.565160] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [7451232.565208] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [7451232.566061] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [7451232.566094] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [7451232.576644] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [7451232.577836] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [7451232.595824] ca systemd-tmpfiles[125]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [7451232.596047] ca systemd-tmpfiles[125]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [7451232.596206] ca systemd-tmpfiles[125]: fchmod() of /var/log/journal/9469826fe7d94086b350cb3425d07d49 failed: Operation not permitted container-test-run-certificates> ca # [7451232.596432] ca systemd-tmpfiles[125]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [7451232.597786] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [7451232.537976] server systemd-journald[69]: Journal started container-test-run-certificates> server # [7451232.538033] server systemd-journald[69]: Runtime Journal (/run/log/journal/4e737d24bc6f4958ab290e36aee6cd82) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> server # [7451232.541246] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> server # [7451232.550722] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> server # [7451232.551499] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> server # [7451232.552134] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> server # [7451232.561196] server systemd-journald[69]: Time spent on flushing to /var/log/journal/4e737d24bc6f4958ab290e36aee6cd82 is 1.264ms for 6 entries. container-test-run-certificates> server # [7451232.561196] server systemd-journald[69]: System Journal (/var/log/journal/4e737d24bc6f4958ab290e36aee6cd82) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [7451232.569192] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [7451232.569823] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [7451232.569954] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [7451232.570838] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [7451232.570890] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [7451232.571804] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [7451232.571837] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [7451232.576481] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [7451232.577828] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [7451232.594230] server systemd-tmpfiles[112]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [7451232.594451] server systemd-tmpfiles[112]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [7451232.594601] server systemd-tmpfiles[112]: fchmod() of /var/log/journal/4e737d24bc6f4958ab290e36aee6cd82 failed: Operation not permitted container-test-run-certificates> server # [7451232.594824] server systemd-tmpfiles[112]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [7451232.596288] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [7451232.530765] client systemd-journald[69]: Journal started container-test-run-certificates> server # [7451232.597391] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [7451232.530892] client systemd-journald[69]: Runtime Journal (/run/log/journal/67330704e48e4194ad846ae619414360) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> server # [7451232.598125] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> client # [7451232.538126] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [7451232.539071] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [7451232.539915] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [7451232.548778] client systemd-journald[69]: Time spent on flushing to /var/log/journal/67330704e48e4194ad846ae619414360 is 1.492ms for 5 entries. container-test-run-certificates> client # [7451232.548778] client systemd-journald[69]: System Journal (/var/log/journal/67330704e48e4194ad846ae619414360) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [7451232.556685] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [7451232.556931] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [7451232.557024] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [7451232.557776] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [7451232.557817] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [7451232.558733] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [7451232.558768] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [7451232.576527] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [7451232.577896] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [7451232.594698] client systemd-tmpfiles[116]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [7451232.595078] client systemd-tmpfiles[116]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [7451232.595207] client systemd-tmpfiles[116]: fchmod() of /var/log/journal/67330704e48e4194ad846ae619414360 failed: Operation not permitted container-test-run-certificates> client # [7451232.595406] client systemd-tmpfiles[116]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [7451232.596658] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [7451232.597677] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [7451232.598383] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [7451232.598801] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [7451232.599519] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [7451232.613324] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [7451232.616434] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [7451232.617454] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [7451232.626579] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [7451232.686063] ca systemd[1]: Finished Firewall. container-test-run-certificates> ca # [7451232.686158] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [7451232.686368] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [7451232.687316] ca systemd[1]: Starting Network Management... container-test-run-certificates> ca # [7451232.709276] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [7451232.610167] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [7451232.611928] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [7451232.620456] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [7451232.616278] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [7451232.617540] client systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [7451232.621483] server systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [7451232.631588] server systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [7451232.697798] server systemd[1]: Finished Firewall. container-test-run-certificates> client # [7451232.628507] client systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [7451232.697956] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [7451232.683284] client systemd[1]: Finished Firewall. container-test-run-certificates> server # [7451232.698201] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [7451232.683446] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [7451232.699176] server systemd[1]: Starting Network Management... container-test-run-certificates> client # [7451232.683671] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [7451232.709300] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [7451232.684770] client systemd[1]: Starting Network Management... container-test-run-certificates> client # [7451232.709676] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [7451233.093418] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [7451233.093505] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [7451233.105196] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [7451233.105365] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [7451233.105527] client systemd-networkd[182]: lo: Link UP container-test-run-certificates> client # [7451233.105531] client systemd-networkd[182]: lo: Gained carrier container-test-run-certificates> client # [7451233.105708] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [7451233.106102] client systemd[1]: Started Network Management. container-test-run-certificates> client # [7451233.106186] client systemd-networkd[182]: eth1: Link UP container-test-run-certificates> client # [7451233.106492] client systemd-networkd[182]: eth1: Gained carrier container-test-run-certificates> client # [7451233.107284] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [7451233.168620] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [7451233.269288] client systemd-resolved[89]: Positive Trust Anchors: container-test-run-certificates> client # [7451233.269299] client systemd-resolved[89]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [7451233.269303] client systemd-resolved[89]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [7451233.269337] client systemd-resolved[89]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [7451233.290918] client systemd-resolved[89]: Using system hostname 'client'. container-test-run-certificates> client # [7451233.292674] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [7451233.292797] client systemd[1]: Reached target Network. container-test-run-certificates> client # [7451233.292917] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [7451233.293018] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [7451233.293067] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [7451233.293105] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [7451233.293330] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [7451233.293536] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [7451233.293753] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [7451233.293803] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [7451233.293892] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [7451233.348522] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [7451233.112332] server systemd-networkd[186]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [7451233.112425] server systemd-networkd[186]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [7451233.119309] server systemd-networkd[186]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [7451233.119474] server systemd-networkd[186]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [7451233.119640] server systemd-networkd[186]: lo: Link UP container-test-run-certificates> server # [7451233.119644] server systemd-networkd[186]: lo: Gained carrier container-test-run-certificates> server # [7451233.119849] server systemd-networkd[186]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [7451233.120273] server systemd[1]: Started Network Management. container-test-run-certificates> server # [7451233.160249] server systemd-networkd[186]: eth1: Link UP container-test-run-certificates> server # [7451233.160597] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [7451233.160839] server systemd-networkd[186]: eth1: Gained carrier container-test-run-certificates> server # [7451233.194276] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [7451233.261816] server systemd-resolved[92]: Positive Trust Anchors: container-test-run-certificates> server # [7451233.261828] server systemd-resolved[92]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [7451233.261831] server systemd-resolved[92]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [7451233.261868] server systemd-resolved[92]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [7451233.284343] server systemd-resolved[92]: Using system hostname 'server'. container-test-run-certificates> server # [7451233.285718] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [7451233.285855] server systemd[1]: Reached target Network. container-test-run-certificates> server # [7451233.285959] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [7451233.286044] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [7451233.286412] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [7451233.286474] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [7451233.286523] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [7451233.286565] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [7451233.286783] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [7451233.286981] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [7451233.287196] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [7451233.287242] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [7451233.287316] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [7451233.289555] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [7451233.290886] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [7451233.290949] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [7451233.292350] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [7451233.294456] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [7451233.112344] ca systemd-networkd[195]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [7451233.112435] ca systemd-networkd[195]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [7451233.119323] ca systemd-networkd[195]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [7451233.119483] ca systemd-networkd[195]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [7451233.119687] ca systemd-networkd[195]: lo: Link UP container-test-run-certificates> ca # [7451233.119690] ca systemd-networkd[195]: lo: Gained carrier container-test-run-certificates> ca # [7451233.119882] ca systemd-networkd[195]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [7451233.120307] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [7451233.160335] ca systemd-networkd[195]: eth1: Link UP container-test-run-certificates> ca # [7451233.160469] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [7451233.160858] ca systemd-networkd[195]: eth1: Gained carrier container-test-run-certificates> ca # [7451233.194263] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [7451233.264616] ca systemd-resolved[101]: Positive Trust Anchors: container-test-run-certificates> ca # [7451233.264625] ca systemd-resolved[101]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [7451233.264629] ca systemd-resolved[101]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [7451233.264669] ca systemd-resolved[101]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [7451233.285975] ca systemd-resolved[101]: Using system hostname 'ca'. container-test-run-certificates> ca # [7451233.287278] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [7451233.287417] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [7451233.287520] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [7451233.287612] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [7451233.287993] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [7451233.288065] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [7451233.288111] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [7451233.288149] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [7451233.288447] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [7451233.288671] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [7451233.288893] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [7451233.288936] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [7451233.289018] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [7451233.291145] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [7451233.292407] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [7451233.292482] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [7451233.294002] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [7451233.348542] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [7451233.350393] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [7451233.365692] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [7451233.365725] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [7451233.452779] ca acme-setup-privileged[201]: + set -euo pipefail container-test-run-certificates> ca # [7451233.452779] ca acme-setup-privileged[201]: + cd /var/lib/acme container-test-run-certificates> ca # [7451233.452779] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [7451233.454482] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [7451233.456038] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [7451233.456038] ca acme-setup-privileged[201]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [7451233.456152] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [7451233.456152] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [7451233.532905] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [7451233.574096] ca nsncd[203]: Sep 03 05:10:59.627 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [7451233.574208] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [7451233.574339] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [7451233.574448] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [7451233.576673] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [7451233.577929] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [7451233.468464] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> server # [7451233.468464] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [7451233.468915] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> server # [7451233.469928] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> server # [7451233.471843] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [7451233.471883] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> server # [7451233.471883] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [7451233.471883] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> server # [7451233.508856] server nsncd[194]: Sep 03 05:10:59.561 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [7451233.508938] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [7451233.509010] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [7451233.509064] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [7451233.510159] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [7451233.511018] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [7451233.538915] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [7451233.539781] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [7451233.542158] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [7451233.542198] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [7451233.542215] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [7451233.350819] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [7451233.353160] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [7451233.370123] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [7451233.491410] client nsncd[189]: Sep 03 05:10:59.544 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [7451233.491436] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [7451233.491512] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [7451233.491584] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [7451233.501563] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [7451233.502642] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [7451233.531520] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> client # [7451233.532953] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [7451233.534764] client systemd[1]: Started Console Getty. container-test-run-certificates> client # [7451233.534818] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [7451233.534839] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [7451233.623996] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [7451233.625578] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [7451233.625578] server dbus-broker-launch[195]: Invalid user-name in /nix/store/aszr859gd9lnmlsj2dls188ya32g6xf8-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [7451233.626026] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [7451233.634169] server dbus-broker-launch[195]: Ready container-test-run-certificates> client # [7451233.629374] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [7451233.630478] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [7451233.630478] client dbus-broker-launch[190]: Invalid user-name in /nix/store/ssk8893k9jd7id6pd9yzim0h6prlbdma-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [7451233.630895] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [7451233.639291] client dbus-broker-launch[190]: Ready container-test-run-certificates> client # [7451234.044188] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [7451234.044555] client systemd[1]: Started User Login Management. container-test-run-certificates> ca # [7451233.632724] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [7451233.634094] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [7451233.634154] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [7451233.634180] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [7451233.646655] ca dbus-broker-launch[208]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [7451233.647565] ca dbus-broker-launch[208]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [7451233.647565] ca dbus-broker-launch[208]: Invalid user-name in /nix/store/nrvy3kisslkv7qydv3v2ib6szfdky5q3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [7451233.648216] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [7451233.655967] ca dbus-broker-launch[208]: Ready container-test-run-certificates> client # [7451234.076814] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [7451234.090500] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [7451234.090598] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [7451234.091054] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [7451234.091439] client systemd[1]: Startup finished in 2.012s. container-test-run-certificates> server # [7451234.026790] server systemd-logind[223]: New seat seat0. container-test-run-certificates> server # [7451234.027068] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [7451234.029725] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [7451234.083511] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [7451234.083659] server systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [7451234.112334] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> server # [7451234.112334] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> server # [7451234.112334] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [7451234.133109] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [7451234.135184] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> client # [7451234.308077] client systemd-networkd[182]: eth1: Gained IPv6LL container-test-run-certificates> ca # [7451234.139834] ca systemd-logind[235]: New seat seat0. container-test-run-certificates> ca # [7451234.140074] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [7451234.141812] ca acme-setup-start[219]: + set -euo pipefail container-test-run-certificates> ca # [7451234.141812] ca acme-setup-start[219]: + test -e ca/key.pem container-test-run-certificates> ca # [7451234.142362] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [7451234.142618] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [7451234.153493] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [7451234.153674] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [7451234.163068] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [7451234.164642] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> ca # [7451234.246278] ca step-ca[204]: badger 2026/09/03 05:11:00 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [7451234.251394] ca step-ca[204]: 2026/09/03 05:11:00 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [7451234.258744] ca step-ca[204]: 2026/09/03 05:11:00 Starting Smallstep CA/0.30.2 (linux/arm64) container-test-run-certificates> ca # [7451234.258744] ca step-ca[204]: 2026/09/03 05:11:00 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [7451234.258744] ca step-ca[204]: 2026/09/03 05:11:00 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [7451234.258744] ca step-ca[204]: 2026/09/03 05:11:00 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [7451234.258744] ca step-ca[204]: 2026/09/03 05:11:00 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [7451234.258744] ca step-ca[204]: 2026/09/03 05:11:00 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [7451234.258744] ca step-ca[204]: 2026/09/03 05:11:00 X.509 Root Fingerprint: f0dc1d5e5cc59b71e44fb3e5996d4e2d60a72d6859cf66e500ddfeb7389647da container-test-run-certificates> ca # [7451234.259492] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [7451234.259647] ca step-ca[204]: 2026/09/03 05:11:00 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> server # [7451234.647279] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7451234.650222] server acme-test.foo-start[245]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [7451234.650320] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [7451234.665668] server acme-test.foo-start[255]: + cd test.foo container-test-run-certificates> server # [7451234.666115] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [7451234.667334] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [7451234.667744] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [7451234.668906] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [7451234.669150] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [7451234.671023] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [7451234.672444] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [7451234.673958] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [7451234.673992] server acme-test.foo-start[245]: + '[' -d out ']' container-test-run-certificates> server # [7451234.673992] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [7451234.675878] server acme-test.foo-start[245]: + chown -R acme:nginx out container-test-run-certificates> server # [7451234.678843] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [7451234.678875] server acme-test.foo-start[245]: + '[' -d certificates ']' container-test-run-certificates> server # [7451234.682312] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [7451234.684309] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> server # [7451234.816280] server systemd-networkd[186]: eth1: Gained IPv6LL container-test-run-certificates> ca # [7451234.676468] ca acme-ca.foo-start[261]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [7451234.679294] ca acme-ca.foo-start[261]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [7451234.679384] ca acme-ca.foo-start[261]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [7451234.691283] ca acme-ca.foo-start[294]: + cd ca.foo container-test-run-certificates> ca # [7451234.691643] ca acme-ca.foo-start[294]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [7451234.692945] ca acme-ca.foo-start[295]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [7451234.693223] ca acme-ca.foo-start[294]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [7451234.694181] ca acme-ca.foo-start[294]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [7451234.694395] ca acme-ca.foo-start[261]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [7451234.695847] ca acme-ca.foo-start[261]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [7451234.697575] ca acme-ca.foo-start[261]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [7451234.698986] ca acme-ca.foo-start[261]: + for fixpath in out certificates container-test-run-certificates> ca # [7451234.699017] ca acme-ca.foo-start[261]: + '[' -d out ']' container-test-run-certificates> ca # [7451234.699017] ca acme-ca.foo-start[261]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [7451234.700505] ca acme-ca.foo-start[261]: + chown -R acme:nginx out container-test-run-certificates> ca # [7451234.704202] ca acme-ca.foo-start[261]: + for fixpath in out certificates container-test-run-certificates> ca # [7451234.704202] ca acme-ca.foo-start[261]: + '[' -d certificates ']' container-test-run-certificates> ca # [7451234.728359] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [7451234.730168] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [7451234.916274] ca systemd-networkd[195]: eth1: Gained IPv6LL container-test-run-certificates> ca # [7451235.218498] ca nginx-pre-start[306]: nginx: the configuration file /nix/store/jwfw4qdij81lq64xr33fi49z93gggc3p-nginx.conf syntax is ok container-test-run-certificates> ca # [7451235.219048] ca nginx-pre-start[306]: nginx: configuration file /nix/store/jwfw4qdij81lq64xr33fi49z93gggc3p-nginx.conf test is successful container-test-run-certificates> ca # [7451235.222907] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [7451235.223362] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [7451235.224750] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> server # [7451235.240439] server nginx-pre-start[267]: nginx: the configuration file /nix/store/1hcqj3qwgk1l5wg86fhwxyq6ddsn1ggy-nginx.conf syntax is ok container-test-run-certificates> server # [7451235.240825] server nginx-pre-start[267]: nginx: configuration file /nix/store/1hcqj3qwgk1l5wg86fhwxyq6ddsn1ggy-nginx.conf test is successful container-test-run-certificates> server # [7451235.264684] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [7451235.265303] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [7451235.267199] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [7451235.817735] ca acme-order-renew-ca.foo-start[309]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [7451235.820469] ca acme-order-renew-ca.foo-start[309]: + set -euo pipefail container-test-run-certificates> ca # [7451235.820550] ca acme-order-renew-ca.foo-start[309]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [7451235.820661] ca acme-order-renew-ca.foo-start[309]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [7451235.821787] ca acme-order-renew-ca.foo-start[309]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [7451235.837435] ca acme-order-renew-ca.foo-start[320]: 2026/09/03 05:11:01 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [7451235.837821] ca acme-order-renew-ca.foo-start[320]: 2026/09/03 05:11:01 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [7451235.860255] ca step-ca[204]: time="2026-09-03T05:11:01Z" level=info duration="130.522µs" duration-ns=130522 fields.time="2026-09-03T05:11:01Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=70627f01-38a0-46ec-bf14-b4de45afd2d8 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7451235.860686] ca acme-order-renew-ca.foo-start[320]: 2026/09/03 05:11:01 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [7451235.861299] ca step-ca[204]: time="2026-09-03T05:11:01Z" level=info duration="538.567µs" duration-ns=538567 fields.time="2026-09-03T05:11:01Z" method=HEAD name=ca nonce=WWZHUGM1aW5KZTl3TDMzNGFodW0waHVvcnFkRDNka0U path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=651f38c9-f7a1-4cce-a017-e7fe4fcc3b54 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7451235.863634] ca step-ca[204]: time="2026-09-03T05:11:01Z" level=info duration=1.766544ms duration-ns=1766544 fields.time="2026-09-03T05:11:01Z" method=POST name=ca nonce=cFYxZDdRTUlTVWpDNXZ2dHlFOUgyWFRjOTFIN0dJN1I path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=832d26cf-63f3-4937-8ba3-2dbc688b854e response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/0oqICSdNGivdkvDf2n92xPj6SEKvfBus/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7451235.864126] ca acme-order-renew-ca.foo-start[320]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [7451235.864126] ca acme-order-renew-ca.foo-start[320]: Your account credentials have been saved in your container-test-run-certificates> ca # [7451235.864126] ca acme-order-renew-ca.foo-start[320]: configuration directory at "accounts". container-test-run-certificates> ca # [7451235.864126] ca acme-order-renew-ca.foo-start[320]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [7451235.864126] ca acme-order-renew-ca.foo-start[320]: configuration directory will also contain private keys container-test-run-certificates> ca # [7451235.864126] ca acme-order-renew-ca.foo-start[320]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [7451235.864126] ca acme-order-renew-ca.foo-start[320]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [7451235.864126] ca acme-order-renew-ca.foo-start[320]: 2026/09/03 05:11:01 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [7451235.867153] ca step-ca[204]: time="2026-09-03T05:11:01Z" level=info duration=2.629156ms duration-ns=2629156 fields.time="2026-09-03T05:11:01Z" method=POST name=ca nonce=R2NDbVZlNHFqM2lOc1pBMDNVNlNhZ0hLa1pUNnBtbzI path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=a0b0b53a-877d-47ed-a9bd-dacf58b851ab response="{\"id\":\"avRVvMbAHCJqmmcSrab934IOabjq6R74\",\"status\":\"pending\",\"expires\":\"2026-09-04T05:11:01Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-09-03T05:10:01Z\",\"notAfter\":\"2026-12-02T05:11:01Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/JpouxYSJtURphn2iVYD6hewU2LUHof7Z\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/avRVvMbAHCJqmmcSrab934IOabjq6R74/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7451235.926218] ca step-ca[204]: time="2026-09-03T05:11:01Z" level=info duration=2.111068ms duration-ns=2111068 fields.time="2026-09-03T05:11:01Z" method=POST name=ca nonce=TUdVaVlEc3FGUnZyTDE1Z3ZqdDh3V3didDZYeDlGM3U path=/acme/acme/authz/JpouxYSJtURphn2iVYD6hewU2LUHof7Z protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=e60181ac-9765-483f-b37e-f857923c6bbc response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"GIBg2joBybSJGSz9FswqbjVVtSYOrXwR\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/JpouxYSJtURphn2iVYD6hewU2LUHof7Z/hkQ2esmBAgF7eIVeD7vdXbS22cTDCymk\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"GIBg2joBybSJGSz9FswqbjVVtSYOrXwR\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/JpouxYSJtURphn2iVYD6hewU2LUHof7Z/mVPeBehIMtDwQCctxIjEsX2SqEZ3wuvk\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"GIBg2joBybSJGSz9FswqbjVVtSYOrXwR\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/JpouxYSJtURphn2iVYD6hewU2LUHof7Z/JysEr6XjkMD5lZQinoQ4XpFjrbdvF2WD\"}],\"wildcard\":false,\"expires\":\"2026-09-04T05:11:01Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7451235.926544] ca acme-order-renew-ca.foo-start[320]: 2026/09/03 05:11:01 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/JpouxYSJtURphn2iVYD6hewU2LUHof7Z container-test-run-certificates> ca # [7451235.926544] ca acme-order-renew-ca.foo-start[320]: 2026/09/03 05:11:01 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [7451235.926544] ca acme-order-renew-ca.foo-start[320]: 2026/09/03 05:11:01 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [7451235.926645] ca acme-order-renew-ca.foo-start[320]: 2026/09/03 05:11:01 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [7451235.930213] ca step-ca[204]: time="2026-09-03T05:11:01Z" level=info duration=3.130481ms duration-ns=3130481 fields.time="2026-09-03T05:11:01Z" method=POST name=ca nonce=NHQ3NVJuSlR0ZEIxdnlOUkNKWk5oa1BpUGhCZkEzNU0 path=/acme/acme/challenge/JpouxYSJtURphn2iVYD6hewU2LUHof7Z/mVPeBehIMtDwQCctxIjEsX2SqEZ3wuvk protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=477f2303-2aaa-4d7b-b080-4549fb9b16c0 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"GIBg2joBybSJGSz9FswqbjVVtSYOrXwR\",\"validated\":\"2026-09-03T05:11:01Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/JpouxYSJtURphn2iVYD6hewU2LUHof7Z/mVPeBehIMtDwQCctxIjEsX2SqEZ3wuvk\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7451235.930585] ca acme-order-renew-ca.foo-start[320]: 2026/09/03 05:11:01 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [7451235.930708] ca acme-order-renew-ca.foo-start[320]: 2026/09/03 05:11:01 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [7451235.937947] ca step-ca[204]: time="2026-09-03T05:11:01Z" level=info duration=5.29335ms duration-ns=5293350 fields.time="2026-09-03T05:11:01Z" method=POST name=ca nonce=TWxQMjduTFViZ0JoR0FVZTdrV1FFa04yR2lvT2d3ZEE path=/acme/acme/order/avRVvMbAHCJqmmcSrab934IOabjq6R74/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=0248272a-0b14-4c15-90c1-1e4253c0165b response="{\"id\":\"avRVvMbAHCJqmmcSrab934IOabjq6R74\",\"status\":\"valid\",\"expires\":\"2026-09-04T05:11:01Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-09-03T05:10:01Z\",\"notAfter\":\"2026-12-02T05:11:01Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/JpouxYSJtURphn2iVYD6hewU2LUHof7Z\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/avRVvMbAHCJqmmcSrab934IOabjq6R74/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/nO5drl7YhmRZryq6j6HoTwfG6OpfcImI\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7451235.940315] ca step-ca[204]: time="2026-09-03T05:11:01Z" level=info certificate=MIIB0zCCAXqgAwIBAgIRALKdSUpgHUDy9UDrZ5avYNkwCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwOTAzMDUxMDAxWhcNMjYxMjAyMDUxMTAxWjARMQ8wDQYDVQQDEwZjYS5mb28wWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAS2vpVShQBW9rZ+JTOLOtGkXXV6te4ZWANYtnNqMqwUt1DMDzQIaQSjE2FD0B8al/RzCQdcqsVnXQMnJRCdKfg3o4GkMIGhMA4GA1UdDwEB/wQEAwIHgDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHQYDVR0OBBYEFJ2yVXdwx26AYK2zR8O8W2cbtV3CMB8GA1UdIwQYMBaAFNFqRJ1BBy/MzAovHdKP6cHdSJ0SMBEGA1UdEQQKMAiCBmNhLmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDRwAwRAIgXIWLdMX3jB/AK+qUP9aY9hqxj7iwkDxXYitVcGL12x4CIGqKgFVVmu1RZ/Uv34S8+kIG58audEHyVFROFo5qBWRR duration=1.4733ms duration-ns=1473300 fields.time="2026-09-03T05:11:01Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=SXZDVjZpTHgybjN6TkNad25JZVVtMU5mc3g5Q2tLUWs path=/acme/acme/certificate/nO5drl7YhmRZryq6j6HoTwfG6OpfcImI protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=bad18dd5-f7ab-4937-86b3-27ceb08fcee2 sans="map[dns:[ca.foo]]" serial=237419260365036012446916178831779782873 size=1340 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-09-03T05:10:01Z" valid-to="2026-12-02T05:11:01Z" container-test-run-certificates> ca # [7451235.940527] ca acme-order-renew-ca.foo-start[320]: 2026/09/03 05:11:01 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [7451235.946428] ca acme-order-renew-ca.foo-start[309]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [7451235.948863] ca acme-order-renew-ca.foo-start[309]: + touch out/acme-success container-test-run-certificates> ca # [7451235.950659] ca acme-order-renew-ca.foo-start[309]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [7451235.951640] ca acme-order-renew-ca.foo-start[309]: + touch out/renewed container-test-run-certificates> ca # [7451235.953199] ca acme-order-renew-ca.foo-start[309]: + echo Installing new certificate container-test-run-certificates> ca # [7451235.953199] ca acme-order-renew-ca.foo-start[309]: Installing new certificate container-test-run-certificates> ca # [7451235.953248] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [7451235.954517] ca acme-order-renew-ca.foo-start[353]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [7451235.954712] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [7451235.956569] ca acme-order-renew-ca.foo-start[354]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [7451235.956814] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [7451235.958245] ca acme-order-renew-ca.foo-start[355]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [7451235.958456] ca acme-order-renew-ca.foo-start[309]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [7451235.959847] ca acme-order-renew-ca.foo-start[309]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [7451235.961312] ca acme-order-renew-ca.foo-start[309]: + for fixpath in out certificates container-test-run-certificates> ca # [7451235.961336] ca acme-order-renew-ca.foo-start[309]: + '[' -d out ']' container-test-run-certificates> ca # [7451235.961336] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [7451235.963317] ca acme-order-renew-ca.foo-start[309]: + chown -R acme:nginx out container-test-run-certificates> ca # [7451235.966302] ca acme-order-renew-ca.foo-start[309]: + for fixpath in out certificates container-test-run-certificates> ca # [7451235.966323] ca acme-order-renew-ca.foo-start[309]: + '[' -d certificates ']' container-test-run-certificates> ca # [7451235.966323] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [7451235.968215] ca acme-order-renew-ca.foo-start[309]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [7451235.970828] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [7451236.080581] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [7451235.809607] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7451235.812608] server acme-order-renew-test.foo-start[270]: + set -euo pipefail container-test-run-certificates> server # [7451235.812706] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [7451235.812805] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [7451235.813885] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [7451235.831398] server acme-order-renew-test.foo-start[282]: 2026/09/03 05:11:01 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [7451235.832037] server acme-order-renew-test.foo-start[282]: 2026/09/03 05:11:01 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [7451236.084888] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [7451236.085130] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca # [7451236.641870] ca nginx[371]: nginx: the configuration file /nix/store/jwfw4qdij81lq64xr33fi49z93gggc3p-nginx.conf syntax is ok container-test-run-certificates> ca # [7451236.642471] ca nginx[371]: nginx: configuration file /nix/store/jwfw4qdij81lq64xr33fi49z93gggc3p-nginx.conf test is successful container-test-run-certificates> server # [7451236.884028] server acme-order-renew-test.foo-start[282]: 2026/09/03 05:11:02 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 2 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [7451236.889423] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [7451236.889423] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [7451236.889423] server acme-order-renew-test.foo-start[270]: + exit 10 container-test-run-certificates> server # [7451236.892391] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [7451236.892489] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [7451236.892805] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [7451236.893099] server systemd[1]: Startup finished in 4.805s. container-test-run-certificates> ca # [7451237.156963] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [7451237.157317] ca systemd[1]: Startup finished in 5.057s. container-test-run-certificates> ca # [7451237.254430] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 3.35 seconds) container-test-run-certificates> ca # [7451237.750180] ca acme-order-renew-ca.foo-start[386]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [7451237.752797] ca acme-order-renew-ca.foo-start[386]: + set -euo pipefail container-test-run-certificates> ca # [7451237.752908] ca acme-order-renew-ca.foo-start[386]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [7451237.753001] ca acme-order-renew-ca.foo-start[386]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [7451237.754345] ca acme-order-renew-ca.foo-start[386]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [7451237.754345] ca acme-order-renew-ca.foo-start[386]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [7451237.754818] ca acme-order-renew-ca.foo-start[394]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [7451237.757870] ca acme-order-renew-ca.foo-start[386]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [7451237.757990] ca acme-order-renew-ca.foo-start[386]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [7451237.800102] ca step-ca[204]: time="2026-09-03T05:11:03Z" level=info duration="54.801µs" duration-ns=54801 fields.time="2026-09-03T05:11:03Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=9ec383a3-030d-43a0-8af3-ad62ce7635fa response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7451237.800819] ca acme-order-renew-ca.foo-start[395]: 2026/09/03 05:11:03 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [7451237.800819] ca acme-order-renew-ca.foo-start[395]: 2026/09/03 05:11:03 [INFO] [ca.foo] The certificate expires at 2026-12-02T05:11:01Z, the renewal can be performed in 1439h59m37.14636626s: no renewal. container-test-run-certificates> ca # [7451237.801111] ca acme-order-renew-ca.foo-start[386]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [7451237.802756] ca acme-order-renew-ca.foo-start[386]: + touch out/acme-success container-test-run-certificates> ca # [7451237.804482] ca acme-order-renew-ca.foo-start[386]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [7451237.805465] ca acme-order-renew-ca.foo-start[386]: + for fixpath in out certificates container-test-run-certificates> ca # [7451237.805465] ca acme-order-renew-ca.foo-start[386]: + '[' -d out ']' container-test-run-certificates> ca # [7451237.805568] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [7451237.807292] ca acme-order-renew-ca.foo-start[386]: + chown -R acme:nginx out container-test-run-certificates> ca # [7451237.810455] ca acme-order-renew-ca.foo-start[386]: + for fixpath in out certificates container-test-run-certificates> ca # [7451237.810455] ca acme-order-renew-ca.foo-start[386]: + '[' -d certificates ']' container-test-run-certificates> ca # [7451237.810557] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [7451237.812191] ca acme-order-renew-ca.foo-start[386]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [7451237.815104] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [7451237.930468] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [7451237.930643] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [7451240.960463] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [7451240.960634] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [7451240.961462] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [7451240.963104] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.55 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1010 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [110 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 3 05:11:00 2026 GMT container-test-run-certificates> * expire date: Oct 3 05:11:00 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 1480b6 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [7451241.462392] server acme-test.foo-start[316]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7451241.464765] server acme-test.foo-start[316]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [7451241.464765] server acme-test.foo-start[316]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [7451241.478682] server acme-test.foo-start[326]: + cd test.foo container-test-run-certificates> server # [7451241.479110] server acme-test.foo-start[326]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [7451241.480486] server acme-test.foo-start[327]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [7451241.480788] server acme-test.foo-start[326]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [7451241.482220] server acme-test.foo-start[326]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [7451241.482461] server acme-test.foo-start[316]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [7451241.484170] server acme-test.foo-start[316]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [7451241.486094] server acme-test.foo-start[316]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [7451241.487847] server acme-test.foo-start[316]: + for fixpath in out certificates container-test-run-certificates> server # [7451241.487847] server acme-test.foo-start[316]: + '[' -d out ']' container-test-run-certificates> server # [7451241.487937] server acme-test.foo-start[316]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [7451241.489649] server acme-test.foo-start[316]: + chown -R acme:nginx out container-test-run-certificates> server # [7451241.492846] server acme-test.foo-start[316]: + for fixpath in out certificates container-test-run-certificates> server # [7451241.492846] server acme-test.foo-start[316]: + '[' -d certificates ']' container-test-run-certificates> server # [7451241.496437] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [7451241.501054] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [7451242.167365] server acme-order-renew-test.foo-start[334]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7451242.169788] server acme-order-renew-test.foo-start[334]: + set -euo pipefail container-test-run-certificates> server # [7451242.169865] server acme-order-renew-test.foo-start[334]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [7451242.169977] server acme-order-renew-test.foo-start[334]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [7451242.171302] server acme-order-renew-test.foo-start[334]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [7451242.219212] server acme-order-renew-test.foo-start[342]: 2026/09/03 05:11:08 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [7451242.237748] server acme-order-renew-test.foo-start[342]: !!!! HEADS UP !!!! container-test-run-certificates> server # [7451242.237748] server acme-order-renew-test.foo-start[342]: Your account credentials have been saved in your container-test-run-certificates> server # [7451242.237748] server acme-order-renew-test.foo-start[342]: configuration directory at "accounts". container-test-run-certificates> server # [7451242.237748] server acme-order-renew-test.foo-start[342]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [7451242.237748] server acme-order-renew-test.foo-start[342]: configuration directory will also contain private keys container-test-run-certificates> server # [7451242.237748] server acme-order-renew-test.foo-start[342]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [7451242.237748] server acme-order-renew-test.foo-start[342]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [7451242.237889] server acme-order-renew-test.foo-start[342]: 2026/09/03 05:11:08 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [7451242.314519] server acme-order-renew-test.foo-start[342]: 2026/09/03 05:11:08 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/qVbyTx2vvUJ6SQvvqHsjvXUO8DKsCeyV container-test-run-certificates> server # [7451242.314519] server acme-order-renew-test.foo-start[342]: 2026/09/03 05:11:08 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [7451242.314519] server acme-order-renew-test.foo-start[342]: 2026/09/03 05:11:08 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [7451242.314519] server acme-order-renew-test.foo-start[342]: 2026/09/03 05:11:08 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [7451242.323259] server acme-order-renew-test.foo-start[342]: 2026/09/03 05:11:08 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [7451242.323388] server acme-order-renew-test.foo-start[342]: 2026/09/03 05:11:08 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [7451242.341648] server acme-order-renew-test.foo-start[342]: 2026/09/03 05:11:08 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [7451242.346669] server acme-order-renew-test.foo-start[334]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [7451242.348303] server acme-order-renew-test.foo-start[334]: + touch out/acme-success container-test-run-certificates> server # [7451242.350062] server acme-order-renew-test.foo-start[334]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [7451242.351346] server acme-order-renew-test.foo-start[334]: + touch out/renewed container-test-run-certificates> server # [7451242.352891] server acme-order-renew-test.foo-start[334]: + echo Installing new certificate container-test-run-certificates> server # [7451242.352891] server acme-order-renew-test.foo-start[334]: Installing new certificate container-test-run-certificates> server # [7451242.352891] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [7451242.354384] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [7451242.354725] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [7451242.355895] server acme-order-renew-test.foo-start[375]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [7451242.356240] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [7451242.357598] server acme-order-renew-test.foo-start[376]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [7451242.357891] server acme-order-renew-test.foo-start[334]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [7451242.359339] server acme-order-renew-test.foo-start[334]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [7451242.361470] server acme-order-renew-test.foo-start[334]: + for fixpath in out certificates container-test-run-certificates> server # [7451242.361470] server acme-order-renew-test.foo-start[334]: + '[' -d out ']' container-test-run-certificates> server # [7451242.361566] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [7451242.363098] server acme-order-renew-test.foo-start[334]: + chown -R acme:nginx out container-test-run-certificates> server # [7451242.366742] server acme-order-renew-test.foo-start[334]: + for fixpath in out certificates container-test-run-certificates> server # [7451242.366742] server acme-order-renew-test.foo-start[334]: + '[' -d certificates ']' container-test-run-certificates> server # [7451242.366884] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [7451242.368344] server acme-order-renew-test.foo-start[334]: + chown -R acme:nginx certificates container-test-run-certificates> server # [7451242.371426] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [7451242.218610] ca step-ca[204]: time="2026-09-03T05:11:08Z" level=info duration="51.4µs" duration-ns=51400 fields.time="2026-09-03T05:11:08Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=3e32d53e-3cc1-4b35-848e-024ec879ffd4 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7451242.228306] ca step-ca[204]: time="2026-09-03T05:11:08Z" level=info duration=5.433233ms duration-ns=5433233 fields.time="2026-09-03T05:11:08Z" method=HEAD name=ca nonce=RE14OWoxb0QwOU1TbloxcnhMak1HMVlRWmxYQ3B6eE4 path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=c0ff5433-78cd-4500-bb53-d5a84ef3e521 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7451242.236905] ca step-ca[204]: time="2026-09-03T05:11:08Z" level=info duration=3.983453ms duration-ns=3983453 fields.time="2026-09-03T05:11:08Z" method=POST name=ca nonce=dXA5VzdYVVdTenFZREo3RnJBdW0zNGttM1pUR0Nnbzc path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=d7105e00-d50b-43b2-a122-aec566ee1158 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/gRpKFXMHo2ZmVfzmAHA7YZZbvVdpuvn4/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7451242.246005] ca step-ca[204]: time="2026-09-03T05:11:08Z" level=info duration=5.155389ms duration-ns=5155389 fields.time="2026-09-03T05:11:08Z" method=POST name=ca nonce=dGtJM3JoMXlkSTlxMWJ3QkV5dWRmekdnNUVqQVpPWGk path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=42e6590a-4b95-43af-ab5f-14194861a9e1 response="{\"id\":\"J20uWfPq3JYlFfmiZ6jtLge9EfUB93RN\",\"status\":\"pending\",\"expires\":\"2026-09-04T05:11:08Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-09-03T05:10:08Z\",\"notAfter\":\"2026-12-02T05:11:08Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/qVbyTx2vvUJ6SQvvqHsjvXUO8DKsCeyV\"],\"finalize\":\"https://ca.foo/acme/acme/order/J20uWfPq3JYlFfmiZ6jtLge9EfUB93RN/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7451242.313932] ca step-ca[204]: time="2026-09-03T05:11:08Z" level=info duration=7.407539ms duration-ns=7407539 fields.time="2026-09-03T05:11:08Z" method=POST name=ca nonce=Wjh4bzV6MjRDc3gzOUREbGNXVHdSVE9sdzNQZDR3M0I path=/acme/acme/authz/qVbyTx2vvUJ6SQvvqHsjvXUO8DKsCeyV protocol=HTTP/1.1 referer= remote-address="::1" request-id=f08ad928-7c14-4fe6-9d9d-937b864d7e53 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"wAaxPIbS78tRzVA5zYMHzq2GHwKSNkWx\",\"url\":\"https://ca.foo/acme/acme/challenge/qVbyTx2vvUJ6SQvvqHsjvXUO8DKsCeyV/BUuVvbydgbaT6160sQyEV6GRDHwUKuHZ\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"wAaxPIbS78tRzVA5zYMHzq2GHwKSNkWx\",\"url\":\"https://ca.foo/acme/acme/challenge/qVbyTx2vvUJ6SQvvqHsjvXUO8DKsCeyV/SrNTAXmsIK60RwxTVuYj9BhXFU0vIvdO\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"wAaxPIbS78tRzVA5zYMHzq2GHwKSNkWx\",\"url\":\"https://ca.foo/acme/acme/challenge/qVbyTx2vvUJ6SQvvqHsjvXUO8DKsCeyV/xCFO8Ve4n5Zg49ehLmAFvXULLHV7WHaT\"}],\"wildcard\":false,\"expires\":\"2026-09-04T05:11:08Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7451242.322718] ca step-ca[204]: time="2026-09-03T05:11:08Z" level=info duration=4.570021ms duration-ns=4570021 fields.time="2026-09-03T05:11:08Z" method=POST name=ca nonce=a2ptcTZ3SWh6cE5lenBKV2JuOUdYVFo4ZDdqQlYwbzc path=/acme/acme/challenge/qVbyTx2vvUJ6SQvvqHsjvXUO8DKsCeyV/SrNTAXmsIK60RwxTVuYj9BhXFU0vIvdO protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=5b4533c1-e044-4f1f-8a68-320a671b57c5 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"wAaxPIbS78tRzVA5zYMHzq2GHwKSNkWx\",\"validated\":\"2026-09-03T05:11:08Z\",\"url\":\"https://ca.foo/acme/acme/challenge/qVbyTx2vvUJ6SQvvqHsjvXUO8DKsCeyV/SrNTAXmsIK60RwxTVuYj9BhXFU0vIvdO\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7451242.334525] ca step-ca[204]: time="2026-09-03T05:11:08Z" level=info duration=6.337365ms duration-ns=6337365 fields.time="2026-09-03T05:11:08Z" method=POST name=ca nonce=cW5hTGcwNFRUd0J4SzlWdzV1SGFhVDNDaExVbW94MXI path=/acme/acme/order/J20uWfPq3JYlFfmiZ6jtLge9EfUB93RN/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=5164d96d-b6b4-46c7-a8bb-101d3f8f3fa5 response="{\"id\":\"J20uWfPq3JYlFfmiZ6jtLge9EfUB93RN\",\"status\":\"valid\",\"expires\":\"2026-09-04T05:11:08Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-09-03T05:10:08Z\",\"notAfter\":\"2026-12-02T05:11:08Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/qVbyTx2vvUJ6SQvvqHsjvXUO8DKsCeyV\"],\"finalize\":\"https://ca.foo/acme/acme/order/J20uWfPq3JYlFfmiZ6jtLge9EfUB93RN/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/y6SHXouKt2XSMlxRkWyTmoyIH0lOwwIl\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7451242.341037] ca step-ca[204]: time="2026-09-03T05:11:08Z" level=info certificate="MIIB2DCCAX2gAwIBAgIQTLePU8qKtLQwV2nIsFaNUTAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA5MDMwNTEwMDhaFw0yNjEyMDIwNTExMDhaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEcbCDe1XlW9zXeSsSRn6se3qPFulGfn1lEE3WjQrhGhjKE90147A8x+hh0nQsC1P8q7o+fY3T271FElG5WzAOiKOBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBR3SX//Iyo8OyWXYnHkoM9/pP/OtTAfBgNVHSMEGDAWgBTRakSdQQcvzMwKLx3Sj+nB3UidEjATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSQAwRgIhANiUjvyo3tGlmTYdHZRZKHPw39bIqyTuGXN13elVtmN5AiEAvuZkg2Hs82COslcphTVZtjwawnsdh29kVX2Y58pUCSM=" duration=1.845784ms duration-ns=1845784 fields.time="2026-09-03T05:11:08Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=VnpxQlVlMHNpMU9wRVc5ODUxTDVCelFUN2d1QmhacmQ path=/acme/acme/certificate/y6SHXouKt2XSMlxRkWyTmoyIH0lOwwIl protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=ec173e81-d3aa-41c4-85e1-4937c97ed810 sans="map[dns:[test.foo]]" serial=101974425027959947766403803790475431249 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-09-03T05:10:08Z" valid-to="2026-12-02T05:11:08Z" container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1010 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 3 05:11:00 2026 GMT container-test-run-certificates> * expire date: Oct 3 05:11:00 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 1480b6 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [7451242.508711] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [7451242.513619] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [7451242.513954] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [7451243.076752] server nginx[392]: nginx: the configuration file /nix/store/1hcqj3qwgk1l5wg86fhwxyq6ddsn1ggy-nginx.conf syntax is ok container-test-run-certificates> server # [7451243.077129] server nginx[392]: nginx: configuration file /nix/store/1hcqj3qwgk1l5wg86fhwxyq6ddsn1ggy-nginx.conf test is successful container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1010 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [110 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 3 05:11:00 2026 GMT container-test-run-certificates> * expire date: Oct 3 05:11:00 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 1480b6 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [7451243.588556] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [932 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [80 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 3 05:10:08 2026 GMT container-test-run-certificates> * expire date: Dec 2 05:11:08 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 56748 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 727 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 3.19 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> 4c:b7:8f:53:ca:8a:b4:b4:30:57:69:c8:b0:56:8d:51 container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Sep 3 05:10:08 2026 GMT container-test-run-certificates> Not After : Dec 2 05:11:08 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:71:b0:83:7b:55:e5:5b:dc:d7:79:2b:12:46:7e: container-test-run-certificates> ac:7b:7a:8f:16:e9:46:7e:7d:65:10:4d:d6:8d:0a: container-test-run-certificates> e1:1a:18:ca:13:dd:35:e3:b0:3c:c7:e8:61:d2:74: container-test-run-certificates> 2c:0b:53:fc:ab:ba:3e:7d:8d:d3:db:bd:45:12:51: container-test-run-certificates> b9:5b:30:0e:88 container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> 77:49:7F:FF:23:2A:3C:3B:25:97:62:71:E4:A0:CF:7F:A4:FF:CE:B5 container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> D1:6A:44:9D:41:07:2F:CC:CC:0A:2F:1D:D2:8F:E9:C1:DD:48:9D:12 container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:46:02:21:00:d8:94:8e:fc:a8:de:d1:a5:99:36:1d:1d:94: container-test-run-certificates> 59:28:73:f0:df:d6:c8:ab:24:ee:19:73:75:dd:e9:55:b6:63: container-test-run-certificates> 79:02:21:00:be:e6:64:83:61:ec:f3:60:8e:b2:57:29:85:35: container-test-run-certificates> 59:b6:3c:1a:c2:7b:1d:87:6f:64:55:7d:98:e7:ca:54:09:23 container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.04 seconds) container-test-run-certificates> (finished: run the VM test script, in 13.14 seconds) container-test-run-certificates> test script finished in 13.25s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 53) container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> kill NspawnMachine (pid 56) container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> Container server terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.49 seconds) post-build step Upload to niks3: ok time=2026-09-03T05:11:11.978Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-09-03T05:11:12.552Z level=INFO msg="Uploading 1 narinfos" time=2026-09-03T05:11:12.626Z level=INFO msg="Upload complete. (709ms)"