these 98 derivations will be built: /nix/store/hzhyn6p7596aacax0n6il7fx747y543j-system-path.drv /nix/store/l3xzz4s6356ydwb2xakxax2zcz32gyl1-dbus-1.drv /nix/store/106a3bfcask61xpjyzhik8ihyjxgfxsn-X-Restart-Triggers-dbus-broker.drv /nix/store/3970p028m49mdxmznsiwlnvhcsk9qa2y-nginx.conf.drv /nix/store/lm95giifd0dhq1kdq5mb1znhn6x4p6x7-nixos-tmpfiles.d.drv /nix/store/3f21pafjia6ggjsxw17b6bbkw3hwniyi-tmpfiles.d.drv /nix/store/8600386bxqaa15pag4dvba7696g9zf2n-extra-hosts.drv /nix/store/3mfjg63hxjhyhkspdbcpqydcyaw0k97h-hosts.drv /nix/store/hmm2bx0wzw811hrag8g58hj3r5bhd709-X-Restart-Triggers-acme-test.foo.drv /nix/store/v2dkfbyzaflr3vic7zy0dpg1r7zf5sw6-unit-script-acme-test.foo-start.drv /nix/store/1v3vxm3nksax5ha6lgbhxbkyy3dryrln-unit-acme-test.foo.service.drv /nix/store/rdxhp0awj9fb0vdx5srklv00ii428ccq-firewall-start.drv /nix/store/d97jkgjnw0qa3ficf4fi9rd83kkbqd7m-firewall-reload.drv /nix/store/36hmmd9m408dxc87qiq720gdwbzd9s0b-unit-firewall.service.drv /nix/store/sascxnqw22b9adqk1kz81gx72vj5a3xv-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/8bzah42yn3yj3f2jii15n4sqlcsi6s74-unit-systemd-tmpfiles-resetup.service.drv /nix/store/8w3wfr0x961r4hy2ailivajx4dbg2fvb-unit-acme-renew-test.foo.timer.drv /nix/store/31rj4mgq1nwypvkvdpb0v0gcg51l03xz-acme-postrun.drv /nix/store/pnalsl2s49yjr48wgvnxagmx8lh49m9p-unit-script-acme-order-renew-test.foo-start.drv /nix/store/9pq23bipqykvy0c10a34z06rsm3v6gsl-unit-acme-order-renew-test.foo.service.drv /nix/store/y11askc7lz9w7kxqp7mw1wc5xnhq2n5i-unit-script-nginx-pre-start.drv /nix/store/izpncllpkq760bwhv3rc9ldqk7ls13km-unit-nginx.service.drv /nix/store/kpfsx09pgqwnbiarmcjq7k9lig14352a-system-path.drv /nix/store/x7cvq6hp1rlzws915d0z6qs5hxkvwq3c-dbus-1.drv /nix/store/lvyfmf027gnyxj8hp7ryqy585givbbz0-X-Restart-Triggers-dbus-broker.drv /nix/store/jp075pp74n5kparfwa0474hgsjz4wnmb-unit-dbus-broker.service.drv /nix/store/lnh2ygxjgqwmhkinkgvvs4cf04s9aakk-unit-nginx-config-reload.service.drv /nix/store/lsyp04hby1xb4dmfmpfvgbxzgh4yl1z6-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/p125j5y841vij8f2i3nycjnfkja6sqlh-unit-40-eth1.network.drv /nix/store/4inmh5fdqgkrzz6qn5pij4h2vf3vzn6h-X-Reload-Triggers-systemd-networkd.drv /nix/store/m5jrjkdvsckhlq58vrfc85h8hkf99fp4-unit-systemd-networkd.service.drv /nix/store/chfxpbk41jaj1p23w27g7sl8zicxk1rc-cacert-blocklist.txt.drv /nix/store/mjv25sy4hly93mcfjy76lw8npj5wgrnn-cacert-extra-certificates-bundle.crt.drv /nix/store/w46mk3zy0zdxbqhsvg8kqa4prnhgrscl-nss-cacert-3.126.drv /nix/store/yw3xh9jqq6wd5lz3z9a910wl2w4j3ngd-unit-nix-daemon.service.drv /nix/store/wajgh70k44pmyjzlf689zf4v98kpfq0s-acme-setup-privileged.drv /nix/store/zrfg1fd7pkck9wnj2c62mynfwch1hb55-unit-acme-setup.service.drv /nix/store/d8609lyrdpjwk471x97mlvxg5rjpsk3b-system-units.drv /nix/store/v2dn16sis8z9wh6bqr0654m97cxsl31g-unit-dbus-broker.service.drv /nix/store/d90mfjvcalxq611ghwgc6gk793mwhmcv-user-units.drv /nix/store/msvcmqhmajssll92gjai5phf8jw6pyac-vars-check-certificates.drv /nix/store/1bygqnnq7ms5vr8aqdwmh19gj3158i0v-etc.drv /nix/store/5vnvigxqq09gy59j7zngr5pywfl877cz-ca.json.drv /nix/store/ax4ccrgqi8qk5c9ppx4ycm0xm6xviisi-system-path.drv /nix/store/g4c8l8cqa5vxzam9i9pica0x5008z2kk-dbus-1.drv /nix/store/2v1ln30rqzry16bgifhism227bxrsg5l-X-Restart-Triggers-dbus-broker.drv /nix/store/h90nzzi0faylcbdgwr1hc7zwkgzxyv1z-unit-dbus-broker.service.drv /nix/store/86qw7xlfw54gm3zmkfwzkl557av240y4-user-units.drv /nix/store/c2vk5hsyhphmxmc2fydszkb7a91bv0qq-nginx.conf.drv /nix/store/d1fswwvs0xfpn1fjv70mspv1bq2hfjm6-system-shutdown.drv /nix/store/gzlcjzpyd0hsmrchcqa1vicws9smqkmg-user-generators.drv /nix/store/3z64pz59i9qs2j4ibaxf5cgj128pbpbd-X-Restart-Triggers-acme-ca.foo.drv /nix/store/9ih973wng9cbgnw5yibjnv7v433fdncp-unit-script-acme-ca.foo-start.drv /nix/store/22wdlwnfq80a4gf3q30nmczyzn1br71h-unit-acme-ca.foo.service.drv /nix/store/4dzyy8fmxm5z2a65d2gmg0cfnz0xwcmi-acme-postrun.drv /nix/store/kndwyk76bziyv42hdjc47fy545jcjlhy-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/4fsvs6h1wgd8vrq60phvmg538s3v4sib-unit-acme-order-renew-ca.foo.service.drv /nix/store/dydi92xw73f2xab8lmga6527sjb8yn0w-unit-script-nginx-pre-start.drv /nix/store/6q7250x88n6a86lbx7rwa67r5svpxa9d-unit-nginx.service.drv /nix/store/cakxpxv88cbncq32mis7s67bz73ds9ab-unit-dbus-broker.service.drv /nix/store/lacmwdd44dzgw2x62bsf3j9i2n527pls-unit-nginx-config-reload.service.drv /nix/store/nhcgml3c92azgy1l9g42hk91dkp16pyp-acme-setup-privileged.drv /nix/store/s9km8agrqzqzbcns8xyn4ypw7jjkr7af-unit-acme-setup.service.drv /nix/store/vx4k4ah41xarp8mc8y4wjqi5whmr3g9c-unit-acme-renew-ca.foo.timer.drv /nix/store/ws9p9f1ilid28mxihffhl70mkys7m3wj-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/65cnj4bf2ibpycnjy2v39s3pcmiymdan-X-Restart-Triggers-step-ca.drv /nix/store/xd7l4jfai0sbxsyiw038vbqn5xhpjqpk-unit-step-ca.service.drv /nix/store/hra7vinsd4d54aknz2bb0djf52fvighq-system-units.drv /nix/store/ji5z680ajfdb50340zz888kwws981h0l-etc-hostname.drv /nix/store/n14qd3dpmwqhr1lz7y188inbriphna20-system-generators.drv /nix/store/lnad1cpwsdc1qc9azf0zgx7zjg6625vg-string-hosts.drv /nix/store/x1pznybbws35d4zvijmba9pzq23qg255-hosts.drv /nix/store/2cc3fwd1kvis85an056f3b4mzssni9qi-etc.drv /nix/store/g95x9vr6y35z9c0ijprbinn29p5b6f0r-decrypt-age-secrets.drv /nix/store/n3pcql3kxl7qdz8rznx65ba10340ja0j-users-groups.json.drv /nix/store/ay571wbv71j47ly318g75adsgamj7hs5-dry-activate.drv /nix/store/s9dnhk7zvn0x9nwdm9hjw43c13x0b07z-activate.drv /nix/store/yykmql9n5lg74djxi0aznmnp20rjvbjy-nixos-system-ca-test.drv /nix/store/1q8jbfw5iyqg8dfwcvw2gdkj1x56550z-run-ca-nspawn.drv /nix/store/1zyfa4xzwkrj97a2h95n0cppkvimscqf-test-script.drv /nix/store/wm7bhdsgk7maxq6hxb34j1yf9infbqgb-users-groups.json.drv /nix/store/3565qvpsvl50rj114r83jqiz0x5wvvgh-dry-activate.drv /nix/store/6zgwah06s2hnhglgy407pjhviai732fl-unit-dbus-broker.service.drv /nix/store/a03igbrhkwpsarmq03yi47zfj3p6hr2b-system-units.drv /nix/store/kjjxn1q8w1ibsyafz9hwd3lm668h80cd-hosts.drv /nix/store/wnjz9jqqdp1yyhyy3fmzfhs1xfklbdx2-unit-dbus-broker.service.drv /nix/store/y42jdc0khvg45c6vwahscgg62b9588ra-user-units.drv /nix/store/81bwb7vvp1vzndw2fl23514nvmmbm9cp-etc.drv /nix/store/r98kdmm46agpl42bmd4a7hrh4g1w1c15-activate.drv /nix/store/r0hb1aq4z5kvdg411bzd5grhgg4nhji9-nixos-system-client-test.drv /nix/store/6phib4vc0blaii042hfzyh672n2jd540-run-client-nspawn.drv /nix/store/7q552l2hkgmxly08zdv92q567ks2v8ac-activate.drv /nix/store/xrqib8vg0whiqjdy16xm13nfkbs1mrrs-nixos-system-server-test.drv /nix/store/wm62yipid2vwpp9ynpcb48zkr05gn772-run-server-nspawn.drv /nix/store/4jygnk9038dglhapnza3ww20syr4jj2c-driverConfiguration.json.drv /nix/store/a6p7i0sggdy14gdpwin6rkj4q67p6bhf-nixos-test-driver-1.1.drv /nix/store/ljyayf4fhh6pnbpvidyhj7wbaadhw66n-nixos-test-driver-certificates.drv /nix/store/g6aqfnpq3azvc1mgxx5d109p817i0vzv-container-test-run-certificates.drv these 10 paths will be fetched (28.7 MiB download, 89.8 MiB unpacked): /nix/store/ij9zhpn6lsn3h3wvy7vnfck2wdi77bgp-gixy-0.1.21 /nix/store/fhxpg5zzr3f19d1fpcnyk2qc7j7v99qr-nginx-1.30.4 /nix/store/wdk87bf7c74qwfvrx96dqgak75v31hbh-nginx-config-formatter-1.4.0 /nix/store/7ax2mr4fszclbz94ky41ia2n5r6q94jn-openssl-3.6.3-man /nix/store/jc3f2cmnpbc7hsm8jawwsw5sm2n4dcgc-openssl-4.0.2 /nix/store/mabj8vrffrvzhnc1m76awgdm04p9zygr-python3.14-buildcatrust-0.5.1 /nix/store/nkzfxdh0z8sw3xf3c5akfdkrgiryijhy-python3.14-cached-property-2.0.1 /nix/store/3nvx0d90ccnq69n7hp29zcp2lbmlaw6c-python3.14-configargparse-1.7.5 /nix/store/fyx52aj20j4qcgz3mrqrfnpnz26ib55m-python3.14-pyparsing-2.4.7 /nix/store/51xw1kjjxjyfkljcqsl879nvvh97vxp0-step-ca-0.30.2 building '/nix/store/1zyfa4xzwkrj97a2h95n0cppkvimscqf-test-script.drv' building '/nix/store/ji5z680ajfdb50340zz888kwws981h0l-etc-hostname.drv' building '/nix/store/p125j5y841vij8f2i3nycjnfkja6sqlh-unit-40-eth1.network.drv' building '/nix/store/8600386bxqaa15pag4dvba7696g9zf2n-extra-hosts.drv' building '/nix/store/lm95giifd0dhq1kdq5mb1znhn6x4p6x7-nixos-tmpfiles.d.drv' building '/nix/store/lnad1cpwsdc1qc9azf0zgx7zjg6625vg-string-hosts.drv' building '/nix/store/lsyp04hby1xb4dmfmpfvgbxzgh4yl1z6-unit-acme-account-2c44cb477b4787b2cf13.target.drv' building '/nix/store/ws9p9f1ilid28mxihffhl70mkys7m3wj-unit-acme-account-d22a46d9459bf683a338.target.drv' building '/nix/store/vx4k4ah41xarp8mc8y4wjqi5whmr3g9c-unit-acme-renew-ca.foo.timer.drv' building '/nix/store/8w3wfr0x961r4hy2ailivajx4dbg2fvb-unit-acme-renew-test.foo.timer.drv' unit-40-eth1.network> structuredAttrs is enabled unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled unit-acme-renew-ca.foo.timer> structuredAttrs is enabled unit-acme-renew-test.foo.timer> structuredAttrs is enabled building '/nix/store/wajgh70k44pmyjzlf689zf4v98kpfq0s-acme-setup-privileged.drv' building '/nix/store/rdxhp0awj9fb0vdx5srklv00ii428ccq-firewall-start.drv' building '/nix/store/9ih973wng9cbgnw5yibjnv7v433fdncp-unit-script-acme-ca.foo-start.drv' building '/nix/store/kndwyk76bziyv42hdjc47fy545jcjlhy-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/pnalsl2s49yjr48wgvnxagmx8lh49m9p-unit-script-acme-order-renew-test.foo-start.drv' building '/nix/store/3z64pz59i9qs2j4ibaxf5cgj128pbpbd-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/hmm2bx0wzw811hrag8g58hj3r5bhd709-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/31rj4mgq1nwypvkvdpb0v0gcg51l03xz-acme-postrun.drv' building '/nix/store/4dzyy8fmxm5z2a65d2gmg0cfnz0xwcmi-acme-postrun.drv' building '/nix/store/nhcgml3c92azgy1l9g42hk91dkp16pyp-acme-setup-privileged.drv' building '/nix/store/4inmh5fdqgkrzz6qn5pij4h2vf3vzn6h-X-Reload-Triggers-systemd-networkd.drv' building '/nix/store/3mfjg63hxjhyhkspdbcpqydcyaw0k97h-hosts.drv' building '/nix/store/kjjxn1q8w1ibsyafz9hwd3lm668h80cd-hosts.drv' building '/nix/store/x1pznybbws35d4zvijmba9pzq23qg255-hosts.drv' building '/nix/store/3f21pafjia6ggjsxw17b6bbkw3hwniyi-tmpfiles.d.drv' building '/nix/store/lacmwdd44dzgw2x62bsf3j9i2n527pls-unit-nginx-config-reload.service.drv' building '/nix/store/lnh2ygxjgqwmhkinkgvvs4cf04s9aakk-unit-nginx-config-reload.service.drv' building '/nix/store/v2dkfbyzaflr3vic7zy0dpg1r7zf5sw6-unit-script-acme-test.foo-start.drv' building '/nix/store/d97jkgjnw0qa3ficf4fi9rd83kkbqd7m-firewall-reload.drv' unit-nginx-config-reload.service> structuredAttrs is enabled unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/5vnvigxqq09gy59j7zngr5pywfl877cz-ca.json.drv' building '/nix/store/chfxpbk41jaj1p23w27g7sl8zicxk1rc-cacert-blocklist.txt.drv' building '/nix/store/22wdlwnfq80a4gf3q30nmczyzn1br71h-unit-acme-ca.foo.service.drv' building '/nix/store/4fsvs6h1wgd8vrq60phvmg538s3v4sib-unit-acme-order-renew-ca.foo.service.drv' building '/nix/store/9pq23bipqykvy0c10a34z06rsm3v6gsl-unit-acme-order-renew-test.foo.service.drv' building '/nix/store/zrfg1fd7pkck9wnj2c62mynfwch1hb55-unit-acme-setup.service.drv' building '/nix/store/wm7bhdsgk7maxq6hxb34j1yf9infbqgb-users-groups.json.drv' ca.json> structuredAttrs is enabled unit-acme-ca.foo.service> structuredAttrs is enabled unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled unit-acme-order-renew-test.foo.service> structuredAttrs is enabled unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/sascxnqw22b9adqk1kz81gx72vj5a3xv-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' building '/nix/store/mjv25sy4hly93mcfjy76lw8npj5wgrnn-cacert-extra-certificates-bundle.crt.drv' building '/nix/store/s9km8agrqzqzbcns8xyn4ypw7jjkr7af-unit-acme-setup.service.drv' building '/nix/store/n3pcql3kxl7qdz8rznx65ba10340ja0j-users-groups.json.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/1v3vxm3nksax5ha6lgbhxbkyy3dryrln-unit-acme-test.foo.service.drv' building '/nix/store/36hmmd9m408dxc87qiq720gdwbzd9s0b-unit-firewall.service.drv' building '/nix/store/m5jrjkdvsckhlq58vrfc85h8hkf99fp4-unit-systemd-networkd.service.drv' building '/nix/store/65cnj4bf2ibpycnjy2v39s3pcmiymdan-X-Restart-Triggers-step-ca.drv' building '/nix/store/3565qvpsvl50rj114r83jqiz0x5wvvgh-dry-activate.drv' building '/nix/store/8bzah42yn3yj3f2jii15n4sqlcsi6s74-unit-systemd-tmpfiles-resetup.service.drv' building '/nix/store/g95x9vr6y35z9c0ijprbinn29p5b6f0r-decrypt-age-secrets.drv' unit-acme-test.foo.service> structuredAttrs is enabled unit-firewall.service> structuredAttrs is enabled unit-systemd-networkd.service> structuredAttrs is enabled unit-systemd-tmpfiles-resetup.service> structuredAttrs is enabled building '/nix/store/ay571wbv71j47ly318g75adsgamj7hs5-dry-activate.drv' building '/nix/store/w46mk3zy0zdxbqhsvg8kqa4prnhgrscl-nss-cacert-3.126.drv' nss-cacert-3.126> structuredAttrs is enabled nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase building '/nix/store/ax4ccrgqi8qk5c9ppx4ycm0xm6xviisi-system-path.drv' building '/nix/store/hzhyn6p7596aacax0n6il7fx747y543j-system-path.drv' building '/nix/store/kpfsx09pgqwnbiarmcjq7k9lig14352a-system-path.drv' nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/5pgavqv475f0nyp410wa3vwbb8hakfxi-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/5pgavqv475f0nyp410wa3vwbb8hakfxi-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/5pgavqv475f0nyp410wa3vwbb8hakfxi-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/s6dmnniyccp8azvwm468zmlqixzckysz-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/s6dmnniyccp8azvwm468zmlqixzckysz-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/s6dmnniyccp8azvwm468zmlqixzckysz-nss-cacert-3.126-hashed nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/mvwyjyfdgzrhpmmfirjarnl8lj9ay5bi-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/mvwyjyfdgzrhpmmfirjarnl8lj9ay5bi-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/mvwyjyfdgzrhpmmfirjarnl8lj9ay5bi-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/qdvp8r7s13m0gs727dc2bgak4as4gg13-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/qdvp8r7s13m0gs727dc2bgak4as4gg13-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/qdvp8r7s13m0gs727dc2bgak4as4gg13-nss-cacert-3.126-unbundled system-path> structuredAttrs is enabled system-path> structuredAttrs is enabled system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment building '/nix/store/3970p028m49mdxmznsiwlnvhcsk9qa2y-nginx.conf.drv' building '/nix/store/c2vk5hsyhphmxmc2fydszkb7a91bv0qq-nginx.conf.drv' nginx.conf> structuredAttrs is enabled system-path> created 1723 symlinks in user environment nginx.conf> structuredAttrs is enabled system-path> created 1723 symlinks in user environment building '/nix/store/g4c8l8cqa5vxzam9i9pica0x5008z2kk-dbus-1.drv' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/l3xzz4s6356ydwb2xakxax2zcz32gyl1-dbus-1.drv' building '/nix/store/x7cvq6hp1rlzws915d0z6qs5hxkvwq3c-dbus-1.drv' building '/nix/store/2v1ln30rqzry16bgifhism227bxrsg5l-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/yw3xh9jqq6wd5lz3z9a910wl2w4j3ngd-unit-nix-daemon.service.drv' building '/nix/store/dydi92xw73f2xab8lmga6527sjb8yn0w-unit-script-nginx-pre-start.drv' building '/nix/store/y11askc7lz9w7kxqp7mw1wc5xnhq2n5i-unit-script-nginx-pre-start.drv' unit-nix-daemon.service> structuredAttrs is enabled building '/nix/store/106a3bfcask61xpjyzhik8ihyjxgfxsn-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/lvyfmf027gnyxj8hp7ryqy585givbbz0-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/cakxpxv88cbncq32mis7s67bz73ds9ab-unit-dbus-broker.service.drv' building '/nix/store/h90nzzi0faylcbdgwr1hc7zwkgzxyv1z-unit-dbus-broker.service.drv' building '/nix/store/6q7250x88n6a86lbx7rwa67r5svpxa9d-unit-nginx.service.drv' building '/nix/store/izpncllpkq760bwhv3rc9ldqk7ls13km-unit-nginx.service.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-nginx.service> structuredAttrs is enabled building '/nix/store/6zgwah06s2hnhglgy407pjhviai732fl-unit-dbus-broker.service.drv' building '/nix/store/jp075pp74n5kparfwa0474hgsjz4wnmb-unit-dbus-broker.service.drv' building '/nix/store/v2dn16sis8z9wh6bqr0654m97cxsl31g-unit-dbus-broker.service.drv' building '/nix/store/wnjz9jqqdp1yyhyy3fmzfhs1xfklbdx2-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-nginx.service> structuredAttrs is enabled building '/nix/store/msvcmqhmajssll92gjai5phf8jw6pyac-vars-check-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/a03igbrhkwpsarmq03yi47zfj3p6hr2b-system-units.drv' building '/nix/store/d8609lyrdpjwk471x97mlvxg5rjpsk3b-system-units.drv' building '/nix/store/d90mfjvcalxq611ghwgc6gk793mwhmcv-user-units.drv' building '/nix/store/y42jdc0khvg45c6vwahscgg62b9588ra-user-units.drv' building '/nix/store/n14qd3dpmwqhr1lz7y188inbriphna20-system-generators.drv' building '/nix/store/d1fswwvs0xfpn1fjv70mspv1bq2hfjm6-system-shutdown.drv' building '/nix/store/xd7l4jfai0sbxsyiw038vbqn5xhpjqpk-unit-step-ca.service.drv' building '/nix/store/gzlcjzpyd0hsmrchcqa1vicws9smqkmg-user-generators.drv' building '/nix/store/86qw7xlfw54gm3zmkfwzkl557av240y4-user-units.drv' unit-step-ca.service> structuredAttrs is enabled building '/nix/store/hra7vinsd4d54aknz2bb0djf52fvighq-system-units.drv' building '/nix/store/msvcmqhmajssll92gjai5phf8jw6pyac-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/1bygqnnq7ms5vr8aqdwmh19gj3158i0v-etc.drv' building '/nix/store/2cc3fwd1kvis85an056f3b4mzssni9qi-etc.drv' building '/nix/store/81bwb7vvp1vzndw2fl23514nvmmbm9cp-etc.drv' building '/nix/store/7q552l2hkgmxly08zdv92q567ks2v8ac-activate.drv' building '/nix/store/r98kdmm46agpl42bmd4a7hrh4g1w1c15-activate.drv' building '/nix/store/s9dnhk7zvn0x9nwdm9hjw43c13x0b07z-activate.drv' building '/nix/store/xrqib8vg0whiqjdy16xm13nfkbs1mrrs-nixos-system-server-test.drv' building '/nix/store/yykmql9n5lg74djxi0aznmnp20rjvbjy-nixos-system-ca-test.drv' building '/nix/store/r0hb1aq4z5kvdg411bzd5grhgg4nhji9-nixos-system-client-test.drv' nixos-system-ca-test> structuredAttrs is enabled nixos-system-server-test> structuredAttrs is enabled building '/nix/store/wm62yipid2vwpp9ynpcb48zkr05gn772-run-server-nspawn.drv' nixos-system-client-test> structuredAttrs is enabled building '/nix/store/1q8jbfw5iyqg8dfwcvw2gdkj1x56550z-run-ca-nspawn.drv' building '/nix/store/6phib4vc0blaii042hfzyh672n2jd540-run-client-nspawn.drv' building '/nix/store/4jygnk9038dglhapnza3ww20syr4jj2c-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/ljyayf4fhh6pnbpvidyhj7wbaadhw66n-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! building '/nix/store/g6aqfnpq3azvc1mgxx5d109p817i0vzv-container-test-run-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/g6aqfnpq3azvc1mgxx5d109p817i0vzv-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> ca: systemd-nspawn running (pid 53) container-test-run-certificates> client: systemd-nspawn running (pid 54) container-test-run-certificates> server: systemd-nspawn running (pid 55) container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> ca # [8190385.017149] ca systemd-journald[78]: Journal started container-test-run-certificates> ca # [8190385.017181] ca systemd-journald[78]: Runtime Journal (/run/log/journal/b6cebf5d192e4a83859d8a1adbd25494) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> ca # [8190385.018756] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [8190385.024908] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [8190385.025800] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [8190385.026293] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [8190385.032417] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/b6cebf5d192e4a83859d8a1adbd25494 is 1.303ms for 6 entries. container-test-run-certificates> ca # [8190385.032417] ca systemd-journald[78]: System Journal (/var/log/journal/b6cebf5d192e4a83859d8a1adbd25494) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [8190385.045026] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [8190385.045274] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [8190385.046445] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [8190385.046541] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [8190385.047220] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [8190385.047260] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [8190385.047949] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [8190385.048516] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [8190385.048538] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [8190385.061260] ca systemd-tmpfiles[127]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [8190385.061457] ca systemd-tmpfiles[127]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [8190385.061577] ca systemd-tmpfiles[127]: fchmod() of /var/log/journal/b6cebf5d192e4a83859d8a1adbd25494 failed: Operation not permitted container-test-run-certificates> ca # [8190385.061755] ca systemd-tmpfiles[127]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [8190385.063222] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [8190385.064255] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [8190385.064710] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [8190385.071799] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [8190385.080150] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [8190385.080935] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [8190385.086705] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [8190385.132223] ca systemd[1]: Finished Firewall. container-test-run-certificates> ca # [8190385.132356] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [8190385.132500] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [8190385.133106] ca systemd[1]: Starting Network Management... container-test-run-certificates> ca # [8190385.461353] ca systemd-networkd[195]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [8190385.461420] ca systemd-networkd[195]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [8190385.467555] ca systemd-networkd[195]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [8190385.009581] client systemd-journald[69]: Journal started container-test-run-certificates> ca # [8190385.467706] ca systemd-networkd[195]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [8190385.009616] client systemd-journald[69]: Runtime Journal (/run/log/journal/fe2d0c3a8c0f4f1ca0ac2621d790ee4e) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> ca # [8190385.467784] ca systemd-networkd[195]: lo: Link UP container-test-run-certificates> client # [8190385.012817] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [8190385.467787] ca systemd-networkd[195]: lo: Gained carrier container-test-run-certificates> client # [8190385.018817] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [8190385.467943] ca systemd-networkd[195]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [8190385.019186] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [8190385.468263] ca systemd[1]: Started Network Management. container-test-run-certificates> client # [8190385.019487] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [8190385.025502] client systemd-journald[69]: Time spent on flushing to /var/log/journal/fe2d0c3a8c0f4f1ca0ac2621d790ee4e is 1.514ms for 6 entries. container-test-run-certificates> ca # [8190385.468350] ca systemd-networkd[195]: eth1: Link UP container-test-run-certificates> client # [8190385.025502] client systemd-journald[69]: System Journal (/var/log/journal/fe2d0c3a8c0f4f1ca0ac2621d790ee4e) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [8190385.468354] ca systemd-networkd[195]: eth1: Gained carrier container-test-run-certificates> client # [8190385.030464] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [8190385.031157] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [8190385.031237] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [8190385.031810] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [8190385.031843] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [8190385.032524] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [8190385.032547] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [8190385.036136] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [8190385.037357] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [8190385.051217] client systemd-tmpfiles[114]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [8190385.051415] client systemd-tmpfiles[114]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [8190385.051554] client systemd-tmpfiles[114]: fchmod() of /var/log/journal/fe2d0c3a8c0f4f1ca0ac2621d790ee4e failed: Operation not permitted container-test-run-certificates> client # [8190385.051731] client systemd-tmpfiles[114]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [8190385.053210] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [8190385.054142] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [8190385.054854] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> client # [8190385.061713] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [8190385.071514] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [8190385.072057] client systemd[1]: Starting Update is Completed... container-test-run-certificates> client # [8190385.077636] client systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [8190385.114400] client systemd[1]: Finished Firewall. container-test-run-certificates> client # [8190385.114521] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [8190385.114706] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [8190385.115551] client systemd[1]: Starting Network Management... container-test-run-certificates> client # [8190385.461103] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [8190385.461210] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [8190385.467859] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [8190385.468032] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [8190385.468139] client systemd-networkd[182]: lo: Link UP container-test-run-certificates> client # [8190385.468142] client systemd-networkd[182]: lo: Gained carrier container-test-run-certificates> client # [8190385.468637] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [8190385.468942] client systemd[1]: Started Network Management. container-test-run-certificates> client # [8190385.468963] client systemd-networkd[182]: eth1: Link UP container-test-run-certificates> client # [8190385.469100] client systemd-networkd[182]: eth1: Gained carrier container-test-run-certificates> server # [8190385.017568] server systemd-journald[69]: Journal started container-test-run-certificates> server # [8190385.017608] server systemd-journald[69]: Runtime Journal (/run/log/journal/f40c194bf99e4c2b9e6de7e7b02cd0f1) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> server # [8190385.018586] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> server # [8190385.024446] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> server # [8190385.024942] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> server # [8190385.025317] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> server # [8190385.029851] server systemd-journald[69]: Time spent on flushing to /var/log/journal/f40c194bf99e4c2b9e6de7e7b02cd0f1 is 1.392ms for 6 entries. container-test-run-certificates> server # [8190385.029851] server systemd-journald[69]: System Journal (/var/log/journal/f40c194bf99e4c2b9e6de7e7b02cd0f1) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [8190385.038052] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [8190385.038250] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [8190385.039081] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [8190385.039186] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [8190385.039754] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [8190385.039800] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [8190385.040388] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [8190385.040919] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [8190385.040941] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [8190385.052551] server systemd-tmpfiles[111]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [8190385.052733] server systemd-tmpfiles[111]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [8190385.052858] server systemd-tmpfiles[111]: fchmod() of /var/log/journal/f40c194bf99e4c2b9e6de7e7b02cd0f1 failed: Operation not permitted container-test-run-certificates> server # [8190385.053071] server systemd-tmpfiles[111]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [8190385.054273] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [8190385.055095] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [8190385.055490] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [8190385.062569] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [8190385.069778] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [8190385.070350] server systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [8190385.077503] server systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [8190385.132258] server systemd[1]: Finished Firewall. container-test-run-certificates> server # [8190385.132414] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [8190385.132579] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [8190385.133297] server systemd[1]: Starting Network Management... container-test-run-certificates> server # [8190385.467235] server systemd-networkd[186]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [8190385.467312] server systemd-networkd[186]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [8190385.472695] server systemd-networkd[186]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [8190385.472842] server systemd-networkd[186]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [8190385.472911] server systemd-networkd[186]: lo: Link UP container-test-run-certificates> server # [8190385.472914] server systemd-networkd[186]: lo: Gained carrier container-test-run-certificates> server # [8190385.473037] server systemd-networkd[186]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [8190385.473282] server systemd[1]: Started Network Management. container-test-run-certificates> server # [8190385.489175] server systemd-networkd[186]: eth1: Link UP container-test-run-certificates> server # [8190385.489209] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [8190385.489356] server systemd-networkd[186]: eth1: Gained carrier container-test-run-certificates> server # [8190385.505716] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [8190385.558449] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [8190385.635800] server systemd-resolved[93]: Positive Trust Anchors: container-test-run-certificates> server # [8190385.635810] server systemd-resolved[93]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [8190385.635813] server systemd-resolved[93]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [8190385.635835] server systemd-resolved[93]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [8190385.648586] server systemd-resolved[93]: Using system hostname 'server'. container-test-run-certificates> server # [8190385.649595] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [8190385.649658] server systemd[1]: Reached target Network. container-test-run-certificates> server # [8190385.649694] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [8190385.649724] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [8190385.649874] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [8190385.649892] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [8190385.649905] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [8190385.649918] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [8190385.650006] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [8190385.650078] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [8190385.650154] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [8190385.650172] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [8190385.650199] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [8190385.651079] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [8190385.651570] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [8190385.651590] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [8190385.652074] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [8190385.652757] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [8190385.657201] server systemd[1]: lastlog2-import.service: Failed to spawn executor: No such file or directory container-test-run-certificates> server # [8190385.657212] server systemd[1]: lastlog2-import.service: Failed to spawn 'start-post' task: No such file or directory container-test-run-certificates> server # [8190385.657238] server systemd[1]: lastlog2-import.service: Failed with result 'resources'. container-test-run-certificates> server # [8190385.657271] server systemd[1]: Failed to start Import lastlog data into lastlog2 database. container-test-run-certificates> server # [8190385.722477] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> server # [8190385.722477] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [8190385.722477] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [8190385.469177] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [8190385.494440] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [8190385.558090] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [8190385.612513] ca systemd-resolved[103]: Positive Trust Anchors: container-test-run-certificates> ca # [8190385.612522] ca systemd-resolved[103]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [8190385.612525] ca systemd-resolved[103]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [8190385.612548] ca systemd-resolved[103]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [8190385.625125] ca systemd-resolved[103]: Using system hostname 'ca'. container-test-run-certificates> ca # [8190385.626007] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [8190385.626060] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [8190385.626095] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [8190385.626127] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [8190385.626264] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [8190385.626288] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [8190385.626302] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [8190385.626312] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [8190385.626399] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [8190385.626471] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [8190385.626633] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [8190385.626665] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [8190385.626695] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [8190385.627522] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [8190385.627855] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [8190385.627874] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [8190385.628320] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [8190385.628896] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [8190385.629536] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [8190385.655811] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [8190385.727245] ca acme-setup-privileged[201]: + set -euo pipefail container-test-run-certificates> ca # [8190385.727245] ca acme-setup-privileged[201]: + cd /var/lib/acme container-test-run-certificates> ca # [8190385.727245] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> client # [8190385.469789] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [8190385.494424] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [8190385.557960] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [8190385.621577] client systemd-resolved[93]: Positive Trust Anchors: container-test-run-certificates> client # [8190385.621586] client systemd-resolved[93]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [8190385.621589] client systemd-resolved[93]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [8190385.621606] client systemd-resolved[93]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [8190385.634343] client systemd-resolved[93]: Using system hostname 'client'. container-test-run-certificates> client # [8190385.635313] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [8190385.635379] client systemd[1]: Reached target Network. container-test-run-certificates> client # [8190385.635423] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [8190385.635461] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [8190385.635483] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [8190385.635496] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [8190385.635594] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [8190385.635675] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [8190385.635764] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [8190385.635780] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [8190385.635809] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [8190385.646250] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [8190385.646961] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [8190385.647738] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [8190385.656978] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [8190385.731601] client nsncd[189]: Sep 03 05:07:23.097 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [8190385.731662] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [8190385.731709] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [8190385.731742] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [8190385.743657] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [8190385.744177] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [8190385.750305] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [8190385.751019] client systemd[1]: Started Console Getty. container-test-run-certificates> client # [8190385.751051] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [8190385.751064] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [8190385.833316] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [8190385.833826] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [8190385.833826] client dbus-broker-launch[190]: Invalid user-name in /nix/store/91l6d2rr3446jkw7ll0r95z9ca8qijjq-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [8190385.834227] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [8190385.838395] client dbus-broker-launch[190]: Ready container-test-run-certificates> server # [8190385.723249] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [8190385.728225] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts container-test-run-certificates> server # [8190385.724452] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> ca # [8190385.729313] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> server # [8190385.724507] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> ca # [8190385.729313] ca acme-setup-privileged[201]: + '[' -d ca.foo ']' container-test-run-certificates> server # [8190385.724507] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> ca # [8190385.729313] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> server # [8190385.724507] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> ca # [8190385.729313] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> server # [8190385.739977] server nsncd[194]: Sep 03 05:07:23.105 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [8190385.743018] ca nsncd[203]: Sep 03 05:07:23.108 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [8190385.740029] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [8190385.743665] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [8190385.740085] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [8190385.743766] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [8190385.740120] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [8190385.743631] server systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [8190385.743811] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [8190385.744228] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [8190385.751060] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [8190385.751647] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [8190385.751667] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [8190385.751678] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [8190385.829266] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [8190385.829780] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [8190385.829780] server dbus-broker-launch[195]: Invalid user-name in /nix/store/0pgc9air17alr427hx1lc5x9wnyi4fv0-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [8190385.830051] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [8190385.835428] server dbus-broker-launch[195]: Ready container-test-run-certificates> server # [8190386.009340] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [8190385.744499] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [8190385.744864] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [8190385.752589] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [8190385.753588] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [8190385.753612] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [8190385.753623] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [8190385.840523] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [8190385.840963] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [8190385.840963] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/gpdxpznvl5s3x1lll78m5sc9cdp1kx2s-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [8190385.841285] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [8190385.845693] ca dbus-broker-launch[205]: Ready container-test-run-certificates> ca # [8190386.009348] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [8190386.121558] server systemd-logind[218]: New seat seat0. container-test-run-certificates> server # [8190386.121738] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [8190386.122856] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [8190386.146119] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [8190386.146241] server systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [8190386.177685] server acme-setup-start[206]: + set -euo pipefail container-test-run-certificates> server # [8190386.177685] server acme-setup-start[206]: + test -e ca/key.pem container-test-run-certificates> server # [8190386.177954] server acme-setup-start[206]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [8190386.184685] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [8190386.185556] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> ca # [8190386.130197] ca systemd-logind[230]: New seat seat0. container-test-run-certificates> ca # [8190386.130386] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [8190386.139293] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [8190386.147759] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [8190386.147832] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [8190386.171032] ca acme-setup-start[219]: + set -euo pipefail container-test-run-certificates> ca # [8190386.171032] ca acme-setup-start[219]: + test -e ca/key.pem container-test-run-certificates> ca # [8190386.171032] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [8190386.179966] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [8190386.180965] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> client # [8190386.001580] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> client # [8190386.133027] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [8190386.133190] client systemd[1]: Started User Login Management. container-test-run-certificates> client # [8190386.139293] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [8190386.147463] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [8190386.147543] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [8190386.147883] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [8190386.148016] client systemd[1]: Startup finished in 1.400s. container-test-run-certificates> ca # [8190386.326641] ca step-ca[204]: badger 2026/09/03 05:07:23 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [8190386.328407] ca step-ca[204]: 2026/09/03 05:07:23 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [8190386.330636] ca step-ca[204]: 2026/09/03 05:07:23 Starting Smallstep CA/0.30.2 (linux/amd64) container-test-run-certificates> ca # [8190386.330636] ca step-ca[204]: 2026/09/03 05:07:23 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [8190386.330664] ca step-ca[204]: 2026/09/03 05:07:23 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [8190386.330664] ca step-ca[204]: 2026/09/03 05:07:23 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [8190386.330664] ca step-ca[204]: 2026/09/03 05:07:23 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [8190386.330664] ca step-ca[204]: 2026/09/03 05:07:23 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [8190386.330664] ca step-ca[204]: 2026/09/03 05:07:23 X.509 Root Fingerprint: 34c5eaf7996cc69329be97a5292cb19e2edb9de68f112cb88f7884a81801e378 container-test-run-certificates> ca # [8190386.330814] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [8190386.330851] ca step-ca[204]: 2026/09/03 05:07:23 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> ca # [8190386.539669] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [8190386.541025] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [8190386.541061] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [8190386.546056] ca acme-ca.foo-start[283]: + cd ca.foo container-test-run-certificates> ca # [8190386.546264] ca acme-ca.foo-start[283]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [8190386.546870] ca acme-ca.foo-start[284]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [8190386.547017] ca acme-ca.foo-start[283]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [8190386.547717] ca acme-ca.foo-start[283]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [8190386.547892] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [8190386.548824] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [8190386.549810] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [8190386.550575] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [8190386.550589] ca acme-ca.foo-start[256]: + '[' -d out ']' container-test-run-certificates> ca # [8190386.550589] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [8190386.551465] ca acme-ca.foo-start[256]: + chown -R acme:nginx out container-test-run-certificates> ca # [8190386.552963] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [8190386.552963] ca acme-ca.foo-start[256]: + '[' -d certificates ']' container-test-run-certificates> ca # [8190386.554657] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [8190386.555566] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> server # [8190386.539583] server acme-test.foo-start[243]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [8190386.541362] server acme-test.foo-start[243]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [8190386.541362] server acme-test.foo-start[243]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [8190386.546742] server acme-test.foo-start[253]: + cd test.foo container-test-run-certificates> server # [8190386.546973] server acme-test.foo-start[253]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [8190386.547530] server acme-test.foo-start[254]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [8190386.547673] server acme-test.foo-start[253]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [8190386.548389] server acme-test.foo-start[253]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [8190386.548561] server acme-test.foo-start[243]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [8190386.549562] server acme-test.foo-start[243]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [8190386.550408] server acme-test.foo-start[243]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [8190386.551360] server acme-test.foo-start[243]: + for fixpath in out certificates container-test-run-certificates> server # [8190386.551381] server acme-test.foo-start[243]: + '[' -d out ']' container-test-run-certificates> server # [8190386.551381] server acme-test.foo-start[243]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [8190386.552234] server acme-test.foo-start[243]: + chown -R acme:nginx out container-test-run-certificates> server # [8190386.554038] server acme-test.foo-start[243]: + for fixpath in out certificates container-test-run-certificates> server # [8190386.554038] server acme-test.foo-start[243]: + '[' -d certificates ']' container-test-run-certificates> server # [8190386.555901] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [8190386.556628] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [8190386.907501] ca nginx-pre-start[295]: nginx: the configuration file /nix/store/h4x3ign3zh19y9f280zxnzk3g4ds9pbk-nginx.conf syntax is ok container-test-run-certificates> ca # [8190386.907748] ca nginx-pre-start[295]: nginx: configuration file /nix/store/h4x3ign3zh19y9f280zxnzk3g4ds9pbk-nginx.conf test is successful container-test-run-certificates> ca # [8190386.925202] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [8190386.925469] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [8190386.926225] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> client # [8190386.878109] client systemd-networkd[182]: eth1: Gained IPv6LL container-test-run-certificates> server # [8190386.900864] server nginx-pre-start[265]: nginx: the configuration file /nix/store/azxra0kwyr9l6lycxi5yqm3sirghcz7b-nginx.conf syntax is ok container-test-run-certificates> server # [8190386.901124] server nginx-pre-start[265]: nginx: configuration file /nix/store/azxra0kwyr9l6lycxi5yqm3sirghcz7b-nginx.conf test is successful container-test-run-certificates> server # [8190386.903111] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [8190386.903672] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [8190386.904298] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> server # [8190387.261104] server systemd-networkd[186]: eth1: Gained IPv6LL container-test-run-certificates> server # [8190387.357662] server acme-order-renew-test.foo-start[268]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [8190387.359350] server acme-order-renew-test.foo-start[268]: + set -euo pipefail container-test-run-certificates> server # [8190387.359407] server acme-order-renew-test.foo-start[268]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [8190387.359488] server acme-order-renew-test.foo-start[268]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [8190387.360153] server acme-order-renew-test.foo-start[268]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [8190387.369317] server acme-order-renew-test.foo-start[280]: 2026/09/03 05:07:24 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [8190387.369560] server acme-order-renew-test.foo-start[280]: 2026/09/03 05:07:24 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> server # [8190387.388044] server acme-order-renew-test.foo-start[280]: 2026/09/03 05:07:24 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [8190387.391653] server acme-order-renew-test.foo-start[268]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [8190387.391653] server acme-order-renew-test.foo-start[268]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [8190387.391653] server acme-order-renew-test.foo-start[268]: + exit 10 container-test-run-certificates> server # [8190387.394050] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [8190387.394160] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [8190387.394431] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [8190387.394772] server systemd[1]: Startup finished in 2.646s. container-test-run-certificates> ca # [8190387.363522] ca acme-order-renew-ca.foo-start[298]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [8190387.364931] ca acme-order-renew-ca.foo-start[298]: + set -euo pipefail container-test-run-certificates> ca # [8190387.364969] ca acme-order-renew-ca.foo-start[298]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [8190387.365031] ca acme-order-renew-ca.foo-start[298]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [8190387.365620] ca acme-order-renew-ca.foo-start[298]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [8190387.374384] ca acme-order-renew-ca.foo-start[310]: 2026/09/03 05:07:24 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [8190387.374661] ca acme-order-renew-ca.foo-start[310]: 2026/09/03 05:07:24 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [8190387.389122] ca step-ca[204]: time="2026-09-03T05:07:24Z" level=info duration="113.794µs" duration-ns=113794 fields.time="2026-09-03T05:07:24Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=a3cc3501-7caa-44db-80f9-834f723cc89b response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [8190387.389526] ca acme-order-renew-ca.foo-start[310]: 2026/09/03 05:07:24 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [8190387.398705] ca step-ca[204]: time="2026-09-03T05:07:24Z" level=info duration=9.234832ms duration-ns=9234832 fields.time="2026-09-03T05:07:24Z" method=HEAD name=ca nonce=SFg3RFdQbmh5VXZuQURBN2F3aGhnTkJUdXNjcTNJQXQ path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=3494046a-9ea7-47cd-81fe-5025b3be2a04 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [8190387.400637] ca step-ca[204]: time="2026-09-03T05:07:24Z" level=info duration=1.630901ms duration-ns=1630901 fields.time="2026-09-03T05:07:24Z" method=POST name=ca nonce=S1JFbEphbExxNzJCckUwT1dSdDBPSTAweUpVajhHU24 path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=e23fe463-4c05-4684-b84e-530cac92010a response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/Ojs7NPNR5XwCr3B3v9tF0VC2dsrMhJqq/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [8190387.400807] ca acme-order-renew-ca.foo-start[310]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [8190387.400807] ca acme-order-renew-ca.foo-start[310]: Your account credentials have been saved in your container-test-run-certificates> ca # [8190387.400807] ca acme-order-renew-ca.foo-start[310]: configuration directory at "accounts". container-test-run-certificates> ca # [8190387.400807] ca acme-order-renew-ca.foo-start[310]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [8190387.400807] ca acme-order-renew-ca.foo-start[310]: configuration directory will also contain private keys container-test-run-certificates> ca # [8190387.400807] ca acme-order-renew-ca.foo-start[310]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [8190387.400807] ca acme-order-renew-ca.foo-start[310]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [8190387.400980] ca acme-order-renew-ca.foo-start[310]: 2026/09/03 05:07:24 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [8190387.409548] ca step-ca[204]: time="2026-09-03T05:07:24Z" level=info duration=8.451407ms duration-ns=8451407 fields.time="2026-09-03T05:07:24Z" method=POST name=ca nonce=Wmoya24wRURqY3hySXJZRjFCRUd1M2c5ZU4wN2VUWVM path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=7fc73cb1-61e6-4bb9-8c12-23249d507f36 response="{\"id\":\"RV0dq5t8UYQaGBBD2lJ870xLDdObPf4J\",\"status\":\"pending\",\"expires\":\"2026-09-04T05:07:24Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-09-03T05:06:24Z\",\"notAfter\":\"2026-12-02T05:07:24Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/fjvM40umhSaNJY2adL7ykyXX4K1Dfxae\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/RV0dq5t8UYQaGBBD2lJ870xLDdObPf4J/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [8190387.454159] ca systemd-networkd[195]: eth1: Gained IPv6LL container-test-run-certificates> ca # [8190387.471325] ca step-ca[204]: time="2026-09-03T05:07:24Z" level=info duration=4.989737ms duration-ns=4989737 fields.time="2026-09-03T05:07:24Z" method=POST name=ca nonce=M2J1bDNVYkhyOHlvZVFoWEJUcTlGT0lPZUxac1FLMVI path=/acme/acme/authz/fjvM40umhSaNJY2adL7ykyXX4K1Dfxae protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=8cc15d53-bd9a-43a1-816f-7d8d0203dce3 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"qs5Lav27urnqOncKExWIOSUf4GsjQPoH\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/fjvM40umhSaNJY2adL7ykyXX4K1Dfxae/mJqf3cJHYHi5CjVkN74Xb6bPsgJx1nBG\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"qs5Lav27urnqOncKExWIOSUf4GsjQPoH\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/fjvM40umhSaNJY2adL7ykyXX4K1Dfxae/b2wdBOrdta25c0Nt0wFUzQMU8u5KwFUr\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"qs5Lav27urnqOncKExWIOSUf4GsjQPoH\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/fjvM40umhSaNJY2adL7ykyXX4K1Dfxae/yGKM8QbXzkNjBV2cNxBeIbfOvp3YguEC\"}],\"wildcard\":false,\"expires\":\"2026-09-04T05:07:24Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [8190387.471580] ca acme-order-renew-ca.foo-start[310]: 2026/09/03 05:07:24 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/fjvM40umhSaNJY2adL7ykyXX4K1Dfxae container-test-run-certificates> ca # [8190387.471580] ca acme-order-renew-ca.foo-start[310]: 2026/09/03 05:07:24 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [8190387.471630] ca acme-order-renew-ca.foo-start[310]: 2026/09/03 05:07:24 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [8190387.471630] ca acme-order-renew-ca.foo-start[310]: 2026/09/03 05:07:24 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [8190387.474692] ca step-ca[204]: time="2026-09-03T05:07:24Z" level=info duration=2.747214ms duration-ns=2747214 fields.time="2026-09-03T05:07:24Z" method=POST name=ca nonce=RnJCTVR6WnA5R24wazh0ZnE3UVZ3MUR6TTl3aElEdXY path=/acme/acme/challenge/fjvM40umhSaNJY2adL7ykyXX4K1Dfxae/b2wdBOrdta25c0Nt0wFUzQMU8u5KwFUr protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=7211ba80-994f-4684-a728-f9c9c6bce3c5 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"qs5Lav27urnqOncKExWIOSUf4GsjQPoH\",\"validated\":\"2026-09-03T05:07:24Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/fjvM40umhSaNJY2adL7ykyXX4K1Dfxae/b2wdBOrdta25c0Nt0wFUzQMU8u5KwFUr\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [8190387.474837] ca acme-order-renew-ca.foo-start[310]: 2026/09/03 05:07:24 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [8190387.474890] ca acme-order-renew-ca.foo-start[310]: 2026/09/03 05:07:24 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [8190387.478512] ca step-ca[204]: time="2026-09-03T05:07:24Z" level=info duration=3.185068ms duration-ns=3185068 fields.time="2026-09-03T05:07:24Z" method=POST name=ca nonce=eFY0TFY2R0JnRnIwM0kxeXg2WkNYOFYyZEZITzhaV0Q path=/acme/acme/order/RV0dq5t8UYQaGBBD2lJ870xLDdObPf4J/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=fceb6baa-aa06-471a-a816-8aac71eacbf5 response="{\"id\":\"RV0dq5t8UYQaGBBD2lJ870xLDdObPf4J\",\"status\":\"valid\",\"expires\":\"2026-09-04T05:07:24Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-09-03T05:06:24Z\",\"notAfter\":\"2026-12-02T05:07:24Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/fjvM40umhSaNJY2adL7ykyXX4K1Dfxae\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/RV0dq5t8UYQaGBBD2lJ870xLDdObPf4J/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/2YEZTWuqFaosFbAWjvQX2LnEt5tLUeAu\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [8190387.479517] ca step-ca[204]: time="2026-09-03T05:07:24Z" level=info certificate="MIIB1DCCAXmgAwIBAgIQf2x9XYbDXMY8Zk/8YGexSjAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA5MDMwNTA2MjRaFw0yNjEyMDIwNTA3MjRaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABAxS528YhAM8TWrFcutsnOl6PXgigFzUrjqes69Ohx7KA3CYv/vnI2AJAAaaDYULu78s7EvCRm+W2ypQWjakyb+jgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUx93L1TYM6aaysXwa3yvd3KCw4qMwHwYDVR0jBBgwFoAUXQc0eMNRoJlq/dh3a+Hz1f07RGMwEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNJADBGAiEA+TluPAOSWX/wivrC3zC0O3rXBPJwdu4noytwOZYG8TMCIQCixH8j+k+RufXbMFOKmJwppi12iA3MoQvZlueyfpfrvw==" duration="607.123µs" duration-ns=607123 fields.time="2026-09-03T05:07:24Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=cmdncVVBUUFSMXZ5dzJoaWFKY0RPdnpYbHNlMVVDRzM path=/acme/acme/certificate/2YEZTWuqFaosFbAWjvQX2LnEt5tLUeAu protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=31315f19-7a8b-49a6-9a3a-705f52a15ed9 sans="map[dns:[ca.foo]]" serial=169375266236532817493460276400464834890 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-09-03T05:06:24Z" valid-to="2026-12-02T05:07:24Z" container-test-run-certificates> ca # [8190387.479626] ca acme-order-renew-ca.foo-start[310]: 2026/09/03 05:07:24 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [8190387.483306] ca acme-order-renew-ca.foo-start[298]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [8190387.484620] ca acme-order-renew-ca.foo-start[298]: + touch out/acme-success container-test-run-certificates> ca # [8190387.485485] ca acme-order-renew-ca.foo-start[298]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [8190387.486182] ca acme-order-renew-ca.foo-start[298]: + touch out/renewed container-test-run-certificates> ca # [8190387.487018] ca acme-order-renew-ca.foo-start[298]: + echo Installing new certificate container-test-run-certificates> ca # [8190387.487018] ca acme-order-renew-ca.foo-start[298]: Installing new certificate container-test-run-certificates> ca # [8190387.487073] ca acme-order-renew-ca.foo-start[298]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [8190387.487964] ca acme-order-renew-ca.foo-start[330]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [8190387.488204] ca acme-order-renew-ca.foo-start[298]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [8190387.489267] ca acme-order-renew-ca.foo-start[331]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [8190387.489454] ca acme-order-renew-ca.foo-start[298]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [8190387.490282] ca acme-order-renew-ca.foo-start[332]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [8190387.490418] ca acme-order-renew-ca.foo-start[298]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [8190387.491242] ca acme-order-renew-ca.foo-start[298]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [8190387.492148] ca acme-order-renew-ca.foo-start[298]: + for fixpath in out certificates container-test-run-certificates> ca # [8190387.492174] ca acme-order-renew-ca.foo-start[298]: + '[' -d out ']' container-test-run-certificates> ca # [8190387.492174] ca acme-order-renew-ca.foo-start[298]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [8190387.493490] ca acme-order-renew-ca.foo-start[298]: + chown -R acme:nginx out container-test-run-certificates> ca # [8190387.495507] ca acme-order-renew-ca.foo-start[298]: + for fixpath in out certificates container-test-run-certificates> ca # [8190387.495507] ca acme-order-renew-ca.foo-start[298]: + '[' -d certificates ']' container-test-run-certificates> ca # [8190387.495507] ca acme-order-renew-ca.foo-start[298]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [8190387.496807] ca acme-order-renew-ca.foo-start[298]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [8190387.498796] ca acme-order-renew-ca.foo-start[298]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [8190387.583742] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [8190387.586306] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [8190387.586421] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca # [8190388.037627] ca nginx[348]: nginx: the configuration file /nix/store/h4x3ign3zh19y9f280zxnzk3g4ds9pbk-nginx.conf syntax is ok container-test-run-certificates> ca # [8190388.037947] ca nginx[348]: nginx: configuration file /nix/store/h4x3ign3zh19y9f280zxnzk3g4ds9pbk-nginx.conf test is successful container-test-run-certificates> ca # [8190388.653576] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [8190388.653856] ca systemd[1]: Startup finished in 3.899s. container-test-run-certificates> ca # [8190389.111474] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 2.47 seconds) container-test-run-certificates> ca # [8190389.754315] ca acme-order-renew-ca.foo-start[363]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [8190389.757112] ca acme-order-renew-ca.foo-start[363]: + set -euo pipefail container-test-run-certificates> ca # [8190389.757179] ca acme-order-renew-ca.foo-start[363]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [8190389.757214] ca acme-order-renew-ca.foo-start[363]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [8190389.758144] ca acme-order-renew-ca.foo-start[363]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [8190389.758144] ca acme-order-renew-ca.foo-start[363]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [8190389.758325] ca acme-order-renew-ca.foo-start[371]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [8190389.760214] ca acme-order-renew-ca.foo-start[363]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [8190389.760214] ca acme-order-renew-ca.foo-start[363]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [8190389.791671] ca step-ca[204]: time="2026-09-03T05:07:27Z" level=info duration="48.231µs" duration-ns=48231 fields.time="2026-09-03T05:07:27Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=713fda92-4680-46c3-abd6-8355f56b6d64 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [8190389.792102] ca acme-order-renew-ca.foo-start[372]: 2026/09/03 05:07:27 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [8190389.792102] ca acme-order-renew-ca.foo-start[372]: 2026/09/03 05:07:27 [INFO] [ca.foo] The certificate expires at 2026-12-02T05:07:24Z, the renewal can be performed in 1439h59m36.842369107s: no renewal. container-test-run-certificates> ca # [8190389.792286] ca acme-order-renew-ca.foo-start[363]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [8190389.794180] ca acme-order-renew-ca.foo-start[363]: + touch out/acme-success container-test-run-certificates> ca # [8190389.795503] ca acme-order-renew-ca.foo-start[363]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [8190389.796573] ca acme-order-renew-ca.foo-start[363]: + for fixpath in out certificates container-test-run-certificates> ca # [8190389.796617] ca acme-order-renew-ca.foo-start[363]: + '[' -d out ']' container-test-run-certificates> ca # [8190389.796617] ca acme-order-renew-ca.foo-start[363]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [8190389.798277] ca acme-order-renew-ca.foo-start[363]: + chown -R acme:nginx out container-test-run-certificates> ca # [8190389.801488] ca acme-order-renew-ca.foo-start[363]: + for fixpath in out certificates container-test-run-certificates> ca # [8190389.801488] ca acme-order-renew-ca.foo-start[363]: + '[' -d certificates ']' container-test-run-certificates> ca # [8190389.801538] ca acme-order-renew-ca.foo-start[363]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [8190389.802741] ca acme-order-renew-ca.foo-start[363]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [8190389.804666] ca acme-order-renew-ca.foo-start[363]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [8190389.932032] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [8190389.932249] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [8190392.947432] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [8190392.947572] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [8190392.948490] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [8190392.950154] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.63 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 3 05:07:23 2026 GMT container-test-run-certificates> * expire date: Oct 3 05:07:23 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 66ee30 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [8190393.541284] server acme-test.foo-start[301]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [8190393.544609] server acme-test.foo-start[301]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [8190393.544609] server acme-test.foo-start[301]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [8190393.551044] server acme-test.foo-start[311]: + cd test.foo container-test-run-certificates> server # [8190393.551501] server acme-test.foo-start[311]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [8190393.552501] server acme-test.foo-start[312]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [8190393.552696] server acme-test.foo-start[311]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [8190393.553692] server acme-test.foo-start[311]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [8190393.555486] server acme-test.foo-start[301]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [8190393.557269] server acme-test.foo-start[301]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [8190393.558583] server acme-test.foo-start[301]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [8190393.561127] server acme-test.foo-start[301]: + for fixpath in out certificates container-test-run-certificates> server # [8190393.561127] server acme-test.foo-start[301]: + '[' -d out ']' container-test-run-certificates> server # [8190393.561127] server acme-test.foo-start[301]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [8190393.561358] server acme-test.foo-start[301]: + chown -R acme:nginx out container-test-run-certificates> server # [8190393.564928] server acme-test.foo-start[301]: + for fixpath in out certificates container-test-run-certificates> server # [8190393.564928] server acme-test.foo-start[301]: + '[' -d certificates ']' container-test-run-certificates> server # [8190393.567434] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [8190393.577571] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [8190393.961650] server acme-order-renew-test.foo-start[319]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [8190393.963336] server acme-order-renew-test.foo-start[319]: + set -euo pipefail container-test-run-certificates> server # [8190393.963404] server acme-order-renew-test.foo-start[319]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [8190393.963431] server acme-order-renew-test.foo-start[319]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [8190393.964041] server acme-order-renew-test.foo-start[319]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [8190393.987691] server acme-order-renew-test.foo-start[327]: 2026/09/03 05:07:31 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [8190393.998730] server acme-order-renew-test.foo-start[327]: !!!! HEADS UP !!!! container-test-run-certificates> server # [8190393.998730] server acme-order-renew-test.foo-start[327]: Your account credentials have been saved in your container-test-run-certificates> server # [8190393.998730] server acme-order-renew-test.foo-start[327]: configuration directory at "accounts". container-test-run-certificates> server # [8190393.998730] server acme-order-renew-test.foo-start[327]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [8190393.998730] server acme-order-renew-test.foo-start[327]: configuration directory will also contain private keys container-test-run-certificates> server # [8190393.998730] server acme-order-renew-test.foo-start[327]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [8190393.998730] server acme-order-renew-test.foo-start[327]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [8190393.998869] server acme-order-renew-test.foo-start[327]: 2026/09/03 05:07:31 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [8190394.059039] server acme-order-renew-test.foo-start[327]: 2026/09/03 05:07:31 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/Rgf8cNicL55xXrXHeZMJzYLu29lLRISr container-test-run-certificates> server # [8190394.059039] server acme-order-renew-test.foo-start[327]: 2026/09/03 05:07:31 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [8190394.059039] server acme-order-renew-test.foo-start[327]: 2026/09/03 05:07:31 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [8190394.059039] server acme-order-renew-test.foo-start[327]: 2026/09/03 05:07:31 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [8190394.061244] server acme-order-renew-test.foo-start[327]: 2026/09/03 05:07:31 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [8190394.061305] server acme-order-renew-test.foo-start[327]: 2026/09/03 05:07:31 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [8190394.065195] server acme-order-renew-test.foo-start[327]: 2026/09/03 05:07:31 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [8190394.068103] server acme-order-renew-test.foo-start[319]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [8190394.069200] server acme-order-renew-test.foo-start[319]: + touch out/acme-success container-test-run-certificates> server # [8190394.070297] server acme-order-renew-test.foo-start[319]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [8190394.070959] server acme-order-renew-test.foo-start[319]: + touch out/renewed container-test-run-certificates> server # [8190394.071861] server acme-order-renew-test.foo-start[319]: + echo Installing new certificate container-test-run-certificates> server # [8190394.071861] server acme-order-renew-test.foo-start[319]: Installing new certificate container-test-run-certificates> server # [8190394.071861] server acme-order-renew-test.foo-start[319]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [8190394.072853] server acme-order-renew-test.foo-start[348]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [8190394.073014] server acme-order-renew-test.foo-start[319]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [8190394.073786] server acme-order-renew-test.foo-start[349]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [8190394.073911] server acme-order-renew-test.foo-start[319]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [8190394.074775] server acme-order-renew-test.foo-start[350]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [8190394.074901] server acme-order-renew-test.foo-start[319]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [8190394.075783] server acme-order-renew-test.foo-start[319]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [8190394.076691] server acme-order-renew-test.foo-start[319]: + for fixpath in out certificates container-test-run-certificates> server # [8190394.076704] server acme-order-renew-test.foo-start[319]: + '[' -d out ']' container-test-run-certificates> server # [8190394.076704] server acme-order-renew-test.foo-start[319]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [8190394.077548] server acme-order-renew-test.foo-start[319]: + chown -R acme:nginx out container-test-run-certificates> server # [8190394.079441] server acme-order-renew-test.foo-start[319]: + for fixpath in out certificates container-test-run-certificates> server # [8190394.079441] server acme-order-renew-test.foo-start[319]: + '[' -d certificates ']' container-test-run-certificates> server # [8190394.079499] server acme-order-renew-test.foo-start[319]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [8190394.080485] server acme-order-renew-test.foo-start[319]: + chown -R acme:nginx certificates container-test-run-certificates> server # [8190394.082034] server acme-order-renew-test.foo-start[319]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> server # [8190394.165596] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [8190394.168165] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [8190394.168292] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> ca # [8190393.987425] ca step-ca[204]: time="2026-09-03T05:07:31Z" level=info duration="40.947µs" duration-ns=40947 fields.time="2026-09-03T05:07:31Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=946771e4-f2f0-40c6-84db-4193bf838a02 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [8190393.996813] ca step-ca[204]: time="2026-09-03T05:07:31Z" level=info duration=8.295593ms duration-ns=8295593 fields.time="2026-09-03T05:07:31Z" method=HEAD name=ca nonce=V0xKeTBSSHY5blFlTUMwVWpxUU9XbWt3M05FNklYRmc path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=6364a4a5-8dfa-4ff2-ab63-942c758f509d size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [8190393.998525] ca step-ca[204]: time="2026-09-03T05:07:31Z" level=info duration="675.462µs" duration-ns=675462 fields.time="2026-09-03T05:07:31Z" method=POST name=ca nonce=U2l4VVBPQlNMZ2MwSW82Y1dwanBRcm1JSm40cDZuRzc path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=c0b7b0e6-4a27-4832-90e3-d97c42b057c3 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/CCptnkeIj57VDfKtjMgzPHzZ56N1g2oc/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [8190394.000566] ca step-ca[204]: time="2026-09-03T05:07:31Z" level=info duration=1.132522ms duration-ns=1132522 fields.time="2026-09-03T05:07:31Z" method=POST name=ca nonce=amQ0aTBWMGc5R2hLNmpkWFF5TWhDeHhyR3BvekxIWnU path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=65f75f1e-0083-4023-baac-149cfd5fed0b response="{\"id\":\"ijTHtoR0rcFw7tsACn9ggdKaEXg6ajKp\",\"status\":\"pending\",\"expires\":\"2026-09-04T05:07:31Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-09-03T05:06:31Z\",\"notAfter\":\"2026-12-02T05:07:31Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/Rgf8cNicL55xXrXHeZMJzYLu29lLRISr\"],\"finalize\":\"https://ca.foo/acme/acme/order/ijTHtoR0rcFw7tsACn9ggdKaEXg6ajKp/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [8190394.058820] ca step-ca[204]: time="2026-09-03T05:07:31Z" level=info duration="739.142µs" duration-ns=739142 fields.time="2026-09-03T05:07:31Z" method=POST name=ca nonce=QVg2dDNUamVybHNQZjdLYkZnaU1wbDlBV29ZdTRFVTU path=/acme/acme/authz/Rgf8cNicL55xXrXHeZMJzYLu29lLRISr protocol=HTTP/1.1 referer= remote-address="::1" request-id=34291fcc-6149-4444-a088-2c2ae539cfbd response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"nXsnJJQWxFb76AglbLAla8BZnSzldnNN\",\"url\":\"https://ca.foo/acme/acme/challenge/Rgf8cNicL55xXrXHeZMJzYLu29lLRISr/z1WeHhv0NPTN8Wmu7jjynlxaSvC97N5Q\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"nXsnJJQWxFb76AglbLAla8BZnSzldnNN\",\"url\":\"https://ca.foo/acme/acme/challenge/Rgf8cNicL55xXrXHeZMJzYLu29lLRISr/N3olQ1JrfuYCSoOUajpS3iDAE3H14oPQ\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"nXsnJJQWxFb76AglbLAla8BZnSzldnNN\",\"url\":\"https://ca.foo/acme/acme/challenge/Rgf8cNicL55xXrXHeZMJzYLu29lLRISr/IuE4RRJ0v1CE6dorkFcsK4hDGM2NJXyP\"}],\"wildcard\":false,\"expires\":\"2026-09-04T05:07:31Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [8190394.061075] ca step-ca[204]: time="2026-09-03T05:07:31Z" level=info duration=1.333972ms duration-ns=1333972 fields.time="2026-09-03T05:07:31Z" method=POST name=ca nonce=R05UTm1LN2dJVmp4T3F5M3FQYjhtWklPV3lDMFBmTkM path=/acme/acme/challenge/Rgf8cNicL55xXrXHeZMJzYLu29lLRISr/N3olQ1JrfuYCSoOUajpS3iDAE3H14oPQ protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=373b8959-fb9a-42de-8059-62b37d7262e9 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"nXsnJJQWxFb76AglbLAla8BZnSzldnNN\",\"validated\":\"2026-09-03T05:07:31Z\",\"url\":\"https://ca.foo/acme/acme/challenge/Rgf8cNicL55xXrXHeZMJzYLu29lLRISr/N3olQ1JrfuYCSoOUajpS3iDAE3H14oPQ\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [8190394.063742] ca step-ca[204]: time="2026-09-03T05:07:31Z" level=info duration=1.678982ms duration-ns=1678982 fields.time="2026-09-03T05:07:31Z" method=POST name=ca nonce=RWx0RnNJV3lCd2VLbWl1RE1ZRTZVYzdWYTBUSm5HY0Q path=/acme/acme/order/ijTHtoR0rcFw7tsACn9ggdKaEXg6ajKp/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=062ad6e1-efc1-4f40-848c-548b82561a49 response="{\"id\":\"ijTHtoR0rcFw7tsACn9ggdKaEXg6ajKp\",\"status\":\"valid\",\"expires\":\"2026-09-04T05:07:31Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-09-03T05:06:31Z\",\"notAfter\":\"2026-12-02T05:07:31Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/Rgf8cNicL55xXrXHeZMJzYLu29lLRISr\"],\"finalize\":\"https://ca.foo/acme/acme/order/ijTHtoR0rcFw7tsACn9ggdKaEXg6ajKp/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/cDJzGfixGVSYC0lWgvdvn8hAZKCFpJGG\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [8190394.064989] ca step-ca[204]: time="2026-09-03T05:07:31Z" level=info certificate="MIIB2DCCAX6gAwIBAgIRANa9vclGsg0uMC1Bfc5fWk0wCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwOTAzMDUwNjMxWhcNMjYxMjAyMDUwNzMxWjATMREwDwYDVQQDEwh0ZXN0LmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABFMTx/+oSrGFATYTCaII6DGqYI65A0h4c0EFXnZdMBe3BLhQpWjkEx9926Jqg7P2bMzxsB361R0SQtrhPTad+qajgaYwgaMwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUDo087agLwtC6XO0HUAGOOMRxbAUwHwYDVR0jBBgwFoAUXQc0eMNRoJlq/dh3a+Hz1f07RGMwEwYDVR0RBAwwCoIIdGVzdC5mb28wHQYMKwYBBAGCpGTGKEABBA0wCwIBBgQEYWNtZQQAMAoGCCqGSM49BAMCA0gAMEUCIGrtIyxiHpHgSK7oHc/bnIJzssjJOuMr5A2u8kUCk/i8AiEAtS1WpT5xAXGjphNp5uKJq/SgslnjyNnXgIN+RRff0Nc=" duration="459.957µs" duration-ns=459957 fields.time="2026-09-03T05:07:31Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=bmJnaGp5TG9STVdMeklnOG4xUjRHSkRjUFYzdTdqeHI path=/acme/acme/certificate/cDJzGfixGVSYC0lWgvdvn8hAZKCFpJGG protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=29bb8f24-c16f-4bec-b79e-2eb13879a184 sans="map[dns:[test.foo]]" serial=285439984526390036482220523435264531021 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-09-03T05:06:31Z" valid-to="2026-12-02T05:07:31Z" container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 3 05:07:23 2026 GMT container-test-run-certificates> * expire date: Oct 3 05:07:23 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 66ee30 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [8190394.535645] server nginx[366]: nginx: the configuration file /nix/store/azxra0kwyr9l6lycxi5yqm3sirghcz7b-nginx.conf syntax is ok container-test-run-certificates> server # [8190394.535871] server nginx[366]: nginx: configuration file /nix/store/azxra0kwyr9l6lycxi5yqm3sirghcz7b-nginx.conf test is successful container-test-run-certificates> server # [8190394.884260] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [930 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [80 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 3 05:06:31 2026 GMT container-test-run-certificates> * expire date: Dec 2 05:07:31 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 59348 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 1753 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 2.07 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> d6:bd:bd:c9:46:b2:0d:2e:30:2d:41:7d:ce:5f:5a:4d container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Sep 3 05:06:31 2026 GMT container-test-run-certificates> Not After : Dec 2 05:07:31 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:53:13:c7:ff:a8:4a:b1:85:01:36:13:09:a2:08: container-test-run-certificates> e8:31:aa:60:8e:b9:03:48:78:73:41:05:5e:76:5d: container-test-run-certificates> 30:17:b7:04:b8:50:a5:68:e4:13:1f:7d:db:a2:6a: container-test-run-certificates> 83:b3:f6:6c:cc:f1:b0:1d:fa:d5:1d:12:42:da:e1: container-test-run-certificates> 3d:36:9d:fa:a6 container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> 0E:8D:3C:ED:A8:0B:C2:D0:BA:5C:ED:07:50:01:8E:38:C4:71:6C:05 container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> 5D:07:34:78:C3:51:A0:99:6A:FD:D8:77:6B:E1:F3:D5:FD:3B:44:63 container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:45:02:20:6a:ed:23:2c:62:1e:91:e0:48:ae:e8:1d:cf:db: container-test-run-certificates> 9c:82:73:b2:c8:c9:3a:e3:2b:e4:0d:ae:f2:45:02:93:f8:bc: container-test-run-certificates> 02:21:00:b5:2d:56:a5:3e:71:01:71:a3:a6:13:69:e6:e2:89: container-test-run-certificates> ab:f4:a0:b2:59:e3:c8:d9:d7:80:83:7e:45:17:df:d0:d7 container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.02 seconds) container-test-run-certificates> (finished: run the VM test script, in 11.19 seconds) container-test-run-certificates> test script finished in 12.11s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 53) container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> kill NspawnMachine (pid 55) container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> Container server terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.29 seconds) post-build step Upload to niks3: ok time=2026-09-03T05:07:34.609Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-09-03T05:07:34.972Z level=INFO msg="Uploading 1 narinfos" time=2026-09-03T05:07:35.177Z level=INFO msg="Upload complete. (667ms)"