these 96 derivations will be built: /nix/store/013b54dpzbclf291zrksw3ffh5r2201d-user-generators.drv /nix/store/hmm2bx0wzw811hrag8g58hj3r5bhd709-X-Restart-Triggers-acme-test.foo.drv /nix/store/v2dkfbyzaflr3vic7zy0dpg1r7zf5sw6-unit-script-acme-test.foo-start.drv /nix/store/1v3vxm3nksax5ha6lgbhxbkyy3dryrln-unit-acme-test.foo.service.drv /nix/store/rdxhp0awj9fb0vdx5srklv00ii428ccq-firewall-start.drv /nix/store/d97jkgjnw0qa3ficf4fi9rd83kkbqd7m-firewall-reload.drv /nix/store/36hmmd9m408dxc87qiq720gdwbzd9s0b-unit-firewall.service.drv /nix/store/lm95giifd0dhq1kdq5mb1znhn6x4p6x7-nixos-tmpfiles.d.drv /nix/store/2gvy9qsk26x5j86hyf97f090dm9r12d2-tmpfiles.d.drv /nix/store/7wymljyza967apf05c1748nk7mczl4bk-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/83l8v7ng5lz88hahqi3q041jllffgfc2-unit-systemd-tmpfiles-resetup.service.drv /nix/store/8w3wfr0x961r4hy2ailivajx4dbg2fvb-unit-acme-renew-test.foo.timer.drv /nix/store/31rj4mgq1nwypvkvdpb0v0gcg51l03xz-acme-postrun.drv /nix/store/pnalsl2s49yjr48wgvnxagmx8lh49m9p-unit-script-acme-order-renew-test.foo-start.drv /nix/store/9pq23bipqykvy0c10a34z06rsm3v6gsl-unit-acme-order-renew-test.foo.service.drv /nix/store/fsr83va6ggycg1gknk7f48598f9jmd1s-system-path.drv /nix/store/k2f30qnc7x8z9m1cnp12wh8ky24h6wli-dbus-1.drv /nix/store/vs4j71wqh7m28bfw4393rzr58y8qh3cf-X-Restart-Triggers-dbus-broker.drv /nix/store/c9wwc0yigaqqz9yq8pqmcq1r52ryj2bk-unit-dbus-broker.service.drv /nix/store/3970p028m49mdxmznsiwlnvhcsk9qa2y-nginx.conf.drv /nix/store/y11askc7lz9w7kxqp7mw1wc5xnhq2n5i-unit-script-nginx-pre-start.drv /nix/store/izpncllpkq760bwhv3rc9ldqk7ls13km-unit-nginx.service.drv /nix/store/lnh2ygxjgqwmhkinkgvvs4cf04s9aakk-unit-nginx-config-reload.service.drv /nix/store/lsyp04hby1xb4dmfmpfvgbxzgh4yl1z6-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/4inmh5fdqgkrzz6qn5pij4h2vf3vzn6h-X-Reload-Triggers-systemd-networkd.drv /nix/store/m5jrjkdvsckhlq58vrfc85h8hkf99fp4-unit-systemd-networkd.service.drv /nix/store/w46mk3zy0zdxbqhsvg8kqa4prnhgrscl-nss-cacert-3.126.drv /nix/store/njlsn3cd3gznlg921hi8d1lwyxvj8ixp-unit-nix-daemon.service.drv /nix/store/wajgh70k44pmyjzlf689zf4v98kpfq0s-acme-setup-privileged.drv /nix/store/zrfg1fd7pkck9wnj2c62mynfwch1hb55-unit-acme-setup.service.drv /nix/store/1889nwcpdlz4g3f8kfkvhnmla6srnf40-system-units.drv /nix/store/8600386bxqaa15pag4dvba7696g9zf2n-extra-hosts.drv /nix/store/3mfjg63hxjhyhkspdbcpqydcyaw0k97h-hosts.drv /nix/store/16lvn0wg72nm8wqfyw1xhinnp780dw84-unit-dbus-broker.service.drv /nix/store/hfv3flqgbxxq2v8an2nji07lmrinb0ah-user-units.drv /nix/store/msvcmqhmajssll92gjai5phf8jw6pyac-vars-check-certificates.drv /nix/store/04682jkknkrx9khzcviy24h88n28ic4d-etc.drv /nix/store/yh7rn816w00yifd5ca1xf58hd9amhgii-system-path.drv /nix/store/92pjxhdbq9bisddsa6khyq7jrc3gnkgr-dbus-1.drv /nix/store/kj76ycy9nzx0jn0rw9z5q9f1bw34i7db-X-Restart-Triggers-dbus-broker.drv /nix/store/957j5jriff0n30ngjx30bws3n48cnasj-unit-dbus-broker.service.drv /nix/store/11chq570ihjj0ns7lqym49ywdn3gswxq-system-units.drv /nix/store/1zyfa4xzwkrj97a2h95n0cppkvimscqf-test-script.drv /nix/store/wm7bhdsgk7maxq6hxb34j1yf9infbqgb-users-groups.json.drv /nix/store/3565qvpsvl50rj114r83jqiz0x5wvvgh-dry-activate.drv /nix/store/v9pdj8yzw36gflaabn8zcajqkz6g77c2-activate.drv /nix/store/g0c87lclwgiqgxal8dfw8r7i4ijy5ip9-nixos-system-server-test.drv /nix/store/7ly3gb7isb5hyiiwcj0kc22q5w0pwhn0-run-server-nspawn.drv /nix/store/bx3crrb9v65rgr20w7nssx5xa61j8mzr-unit-dbus-broker.service.drv /nix/store/3hzf9byn95198xbqkk25rqm6l6kni4ka-user-units.drv /nix/store/kjjxn1q8w1ibsyafz9hwd3lm668h80cd-hosts.drv /nix/store/db5mfh8lv9ry0nfm87md86wpy2w3jjl2-etc.drv /nix/store/5sdwg9ibqv546q7j4jry64nhdgbj2cf6-activate.drv /nix/store/l2bmvnz013frslvgaqchh2j3chd87fkz-nixos-system-client-test.drv /nix/store/irhv4z0cg239xyd7g3qfy0filzy6x49h-run-client-nspawn.drv /nix/store/1qag1wxymr8hvp8par8bmzljj0q86p5j-system-generators.drv /nix/store/5vnvigxqq09gy59j7zngr5pywfl877cz-ca.json.drv /nix/store/av8fv1sm41dfnyywxlqdzfh3mhn2sn0l-system-shutdown.drv /nix/store/c2vk5hsyhphmxmc2fydszkb7a91bv0qq-nginx.conf.drv /nix/store/3z64pz59i9qs2j4ibaxf5cgj128pbpbd-X-Restart-Triggers-acme-ca.foo.drv /nix/store/9ih973wng9cbgnw5yibjnv7v433fdncp-unit-script-acme-ca.foo-start.drv /nix/store/22wdlwnfq80a4gf3q30nmczyzn1br71h-unit-acme-ca.foo.service.drv /nix/store/4dzyy8fmxm5z2a65d2gmg0cfnz0xwcmi-acme-postrun.drv /nix/store/kndwyk76bziyv42hdjc47fy545jcjlhy-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/4fsvs6h1wgd8vrq60phvmg538s3v4sib-unit-acme-order-renew-ca.foo.service.drv /nix/store/dydi92xw73f2xab8lmga6527sjb8yn0w-unit-script-nginx-pre-start.drv /nix/store/6q7250x88n6a86lbx7rwa67r5svpxa9d-unit-nginx.service.drv /nix/store/vjgbv2w3jm2ih9apj9c5wka6qjc7wrz3-system-path.drv /nix/store/nnxn7yfw4xmdr08mj85mp3lijd5wzg91-dbus-1.drv /nix/store/l2m3kxcxhlrl4g64g5x7g059cp8k9qim-X-Restart-Triggers-dbus-broker.drv /nix/store/ihzsj4k9jyp4rvxl0v6c6x6yk62mq5v9-unit-dbus-broker.service.drv /nix/store/lacmwdd44dzgw2x62bsf3j9i2n527pls-unit-nginx-config-reload.service.drv /nix/store/nhcgml3c92azgy1l9g42hk91dkp16pyp-acme-setup-privileged.drv /nix/store/s9km8agrqzqzbcns8xyn4ypw7jjkr7af-unit-acme-setup.service.drv /nix/store/vx4k4ah41xarp8mc8y4wjqi5whmr3g9c-unit-acme-renew-ca.foo.timer.drv /nix/store/ws9p9f1ilid28mxihffhl70mkys7m3wj-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/65cnj4bf2ibpycnjy2v39s3pcmiymdan-X-Restart-Triggers-step-ca.drv /nix/store/xd7l4jfai0sbxsyiw038vbqn5xhpjqpk-unit-step-ca.service.drv /nix/store/f9ra1nfnmgfl2grjndm43552jnihx5h0-system-units.drv /nix/store/ji5z680ajfdb50340zz888kwws981h0l-etc-hostname.drv /nix/store/lnad1cpwsdc1qc9azf0zgx7zjg6625vg-string-hosts.drv /nix/store/x1pznybbws35d4zvijmba9pzq23qg255-hosts.drv /nix/store/dw36hr84igwyzv8ip7cn3mzx194ccff1-unit-dbus-broker.service.drv /nix/store/xj67g54srsv4whsd8jz4zj9nhy2q9jd9-user-units.drv /nix/store/9b0xwh71hwk2wvn1mm4q8acc0gvkixkw-etc.drv /nix/store/g95x9vr6y35z9c0ijprbinn29p5b6f0r-decrypt-age-secrets.drv /nix/store/n3pcql3kxl7qdz8rznx65ba10340ja0j-users-groups.json.drv /nix/store/ay571wbv71j47ly318g75adsgamj7hs5-dry-activate.drv /nix/store/viq76qy32r3f5fmrdfl3kxkd76yf1nsx-activate.drv /nix/store/zqlk5h5hgdivkfzyx8vwzp37jkgxa6wi-nixos-system-ca-test.drv /nix/store/v5a1gpabpcjv9wbc6mv5jwwapss61yqd-run-ca-nspawn.drv /nix/store/ba8a9qxyxd9j6xk6b8s923453aiqbhqs-driverConfiguration.json.drv /nix/store/na23xrpzcyk8hvs34731v4k8yszazwr0-python3.14-nixos-test-lib-1.0.0.drv /nix/store/clblzixq3ld33md200bq8v3cjw6pac7p-nixos-test-driver-1.1.drv /nix/store/lxaqh31566zqj7cr0srv05nkj24k43am-nixos-test-driver-certificates.drv /nix/store/1p2g728k6skfwzvn1ff15vl2qnw0qkxf-container-test-run-certificates.drv this path will be fetched (21.7 MiB download, 72.9 MiB unpacked): /nix/store/51xw1kjjxjyfkljcqsl879nvvh97vxp0-step-ca-0.30.2 building '/nix/store/1zyfa4xzwkrj97a2h95n0cppkvimscqf-test-script.drv' building '/nix/store/fsr83va6ggycg1gknk7f48598f9jmd1s-system-path.drv' building '/nix/store/vjgbv2w3jm2ih9apj9c5wka6qjc7wrz3-system-path.drv' building '/nix/store/yh7rn816w00yifd5ca1xf58hd9amhgii-system-path.drv' building '/nix/store/ji5z680ajfdb50340zz888kwws981h0l-etc-hostname.drv' building '/nix/store/3970p028m49mdxmznsiwlnvhcsk9qa2y-nginx.conf.drv' building '/nix/store/c2vk5hsyhphmxmc2fydszkb7a91bv0qq-nginx.conf.drv' building '/nix/store/8600386bxqaa15pag4dvba7696g9zf2n-extra-hosts.drv' building '/nix/store/lnad1cpwsdc1qc9azf0zgx7zjg6625vg-string-hosts.drv' building '/nix/store/lsyp04hby1xb4dmfmpfvgbxzgh4yl1z6-unit-acme-account-2c44cb477b4787b2cf13.target.drv' nginx.conf> structuredAttrs is enabled nginx.conf> structuredAttrs is enabled system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled building '/nix/store/ws9p9f1ilid28mxihffhl70mkys7m3wj-unit-acme-account-d22a46d9459bf683a338.target.drv' building '/nix/store/vx4k4ah41xarp8mc8y4wjqi5whmr3g9c-unit-acme-renew-ca.foo.timer.drv' building '/nix/store/pnalsl2s49yjr48wgvnxagmx8lh49m9p-unit-script-acme-order-renew-test.foo-start.drv' building '/nix/store/v2dkfbyzaflr3vic7zy0dpg1r7zf5sw6-unit-script-acme-test.foo-start.drv' unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled unit-acme-renew-ca.foo.timer> structuredAttrs is enabled building '/nix/store/3z64pz59i9qs2j4ibaxf5cgj128pbpbd-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/hmm2bx0wzw811hrag8g58hj3r5bhd709-X-Restart-Triggers-acme-test.foo.drv' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/31rj4mgq1nwypvkvdpb0v0gcg51l03xz-acme-postrun.drv' building '/nix/store/4dzyy8fmxm5z2a65d2gmg0cfnz0xwcmi-acme-postrun.drv' building '/nix/store/nhcgml3c92azgy1l9g42hk91dkp16pyp-acme-setup-privileged.drv' building '/nix/store/wajgh70k44pmyjzlf689zf4v98kpfq0s-acme-setup-privileged.drv' building '/nix/store/k2f30qnc7x8z9m1cnp12wh8ky24h6wli-dbus-1.drv' building '/nix/store/rdxhp0awj9fb0vdx5srklv00ii428ccq-firewall-start.drv' building '/nix/store/5vnvigxqq09gy59j7zngr5pywfl877cz-ca.json.drv' building '/nix/store/92pjxhdbq9bisddsa6khyq7jrc3gnkgr-dbus-1.drv' building '/nix/store/nnxn7yfw4xmdr08mj85mp3lijd5wzg91-dbus-1.drv' building '/nix/store/kjjxn1q8w1ibsyafz9hwd3lm668h80cd-hosts.drv' building '/nix/store/x1pznybbws35d4zvijmba9pzq23qg255-hosts.drv' building '/nix/store/lacmwdd44dzgw2x62bsf3j9i2n527pls-unit-nginx-config-reload.service.drv' building '/nix/store/lnh2ygxjgqwmhkinkgvvs4cf04s9aakk-unit-nginx-config-reload.service.drv' building '/nix/store/9ih973wng9cbgnw5yibjnv7v433fdncp-unit-script-acme-ca.foo-start.drv' building '/nix/store/n3pcql3kxl7qdz8rznx65ba10340ja0j-users-groups.json.drv' building '/nix/store/wm7bhdsgk7maxq6hxb34j1yf9infbqgb-users-groups.json.drv' ca.json> structuredAttrs is enabled unit-nginx-config-reload.service> structuredAttrs is enabled unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/9pq23bipqykvy0c10a34z06rsm3v6gsl-unit-acme-order-renew-test.foo.service.drv' building '/nix/store/zrfg1fd7pkck9wnj2c62mynfwch1hb55-unit-acme-setup.service.drv' building '/nix/store/1v3vxm3nksax5ha6lgbhxbkyy3dryrln-unit-acme-test.foo.service.drv' building '/nix/store/y11askc7lz9w7kxqp7mw1wc5xnhq2n5i-unit-script-nginx-pre-start.drv' unit-acme-order-renew-test.foo.service> structuredAttrs is enabled unit-acme-setup.service> structuredAttrs is enabled unit-acme-test.foo.service> structuredAttrs is enabled building '/nix/store/kj76ycy9nzx0jn0rw9z5q9f1bw34i7db-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/l2m3kxcxhlrl4g64g5x7g059cp8k9qim-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/d97jkgjnw0qa3ficf4fi9rd83kkbqd7m-firewall-reload.drv' building '/nix/store/1qag1wxymr8hvp8par8bmzljj0q86p5j-system-generators.drv' building '/nix/store/av8fv1sm41dfnyywxlqdzfh3mhn2sn0l-system-shutdown.drv' building '/nix/store/dydi92xw73f2xab8lmga6527sjb8yn0w-unit-script-nginx-pre-start.drv' building '/nix/store/vs4j71wqh7m28bfw4393rzr58y8qh3cf-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/65cnj4bf2ibpycnjy2v39s3pcmiymdan-X-Restart-Triggers-step-ca.drv' building '/nix/store/3565qvpsvl50rj114r83jqiz0x5wvvgh-dry-activate.drv' building '/nix/store/3mfjg63hxjhyhkspdbcpqydcyaw0k97h-hosts.drv' building '/nix/store/22wdlwnfq80a4gf3q30nmczyzn1br71h-unit-acme-ca.foo.service.drv' building '/nix/store/8w3wfr0x961r4hy2ailivajx4dbg2fvb-unit-acme-renew-test.foo.timer.drv' building '/nix/store/s9km8agrqzqzbcns8xyn4ypw7jjkr7af-unit-acme-setup.service.drv' building '/nix/store/kndwyk76bziyv42hdjc47fy545jcjlhy-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/013b54dpzbclf291zrksw3ffh5r2201d-user-generators.drv' unit-acme-ca.foo.service> structuredAttrs is enabled unit-acme-renew-test.foo.timer> structuredAttrs is enabled unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/957j5jriff0n30ngjx30bws3n48cnasj-unit-dbus-broker.service.drv' building '/nix/store/bx3crrb9v65rgr20w7nssx5xa61j8mzr-unit-dbus-broker.service.drv' building '/nix/store/dw36hr84igwyzv8ip7cn3mzx194ccff1-unit-dbus-broker.service.drv' building '/nix/store/ihzsj4k9jyp4rvxl0v6c6x6yk62mq5v9-unit-dbus-broker.service.drv' building '/nix/store/36hmmd9m408dxc87qiq720gdwbzd9s0b-unit-firewall.service.drv' building '/nix/store/izpncllpkq760bwhv3rc9ldqk7ls13km-unit-nginx.service.drv' building '/nix/store/4fsvs6h1wgd8vrq60phvmg538s3v4sib-unit-acme-order-renew-ca.foo.service.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-firewall.service> structuredAttrs is enabled unit-nginx.service> structuredAttrs is enabled building '/nix/store/16lvn0wg72nm8wqfyw1xhinnp780dw84-unit-dbus-broker.service.drv' building '/nix/store/c9wwc0yigaqqz9yq8pqmcq1r52ryj2bk-unit-dbus-broker.service.drv' building '/nix/store/xd7l4jfai0sbxsyiw038vbqn5xhpjqpk-unit-step-ca.service.drv' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/6q7250x88n6a86lbx7rwa67r5svpxa9d-unit-nginx.service.drv' building '/nix/store/3hzf9byn95198xbqkk25rqm6l6kni4ka-user-units.drv' building '/nix/store/xj67g54srsv4whsd8jz4zj9nhy2q9jd9-user-units.drv' unit-nginx.service> structuredAttrs is enabled unit-step-ca.service> structuredAttrs is enabled building '/nix/store/hfv3flqgbxxq2v8an2nji07lmrinb0ah-user-units.drv' building '/nix/store/g95x9vr6y35z9c0ijprbinn29p5b6f0r-decrypt-age-secrets.drv' building '/nix/store/w46mk3zy0zdxbqhsvg8kqa4prnhgrscl-nss-cacert-3.126.drv' building '/nix/store/msvcmqhmajssll92gjai5phf8jw6pyac-vars-check-certificates.drv' nss-cacert-3.126> structuredAttrs is enabled nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/ay571wbv71j47ly318g75adsgamj7hs5-dry-activate.drv' nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/5pgavqv475f0nyp410wa3vwbb8hakfxi-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/5pgavqv475f0nyp410wa3vwbb8hakfxi-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/5pgavqv475f0nyp410wa3vwbb8hakfxi-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/s6dmnniyccp8azvwm468zmlqixzckysz-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/s6dmnniyccp8azvwm468zmlqixzckysz-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/s6dmnniyccp8azvwm468zmlqixzckysz-nss-cacert-3.126-hashed nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/mvwyjyfdgzrhpmmfirjarnl8lj9ay5bi-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/mvwyjyfdgzrhpmmfirjarnl8lj9ay5bi-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/mvwyjyfdgzrhpmmfirjarnl8lj9ay5bi-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/qdvp8r7s13m0gs727dc2bgak4as4gg13-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/qdvp8r7s13m0gs727dc2bgak4as4gg13-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/qdvp8r7s13m0gs727dc2bgak4as4gg13-nss-cacert-3.126-unbundled building '/nix/store/njlsn3cd3gznlg921hi8d1lwyxvj8ixp-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled building '/nix/store/11chq570ihjj0ns7lqym49ywdn3gswxq-system-units.drv' building '/nix/store/1889nwcpdlz4g3f8kfkvhnmla6srnf40-system-units.drv' building '/nix/store/f9ra1nfnmgfl2grjndm43552jnihx5h0-system-units.drv' building '/nix/store/db5mfh8lv9ry0nfm87md86wpy2w3jjl2-etc.drv' building '/nix/store/04682jkknkrx9khzcviy24h88n28ic4d-etc.drv' building '/nix/store/9b0xwh71hwk2wvn1mm4q8acc0gvkixkw-etc.drv' building '/nix/store/5sdwg9ibqv546q7j4jry64nhdgbj2cf6-activate.drv' building '/nix/store/l2bmvnz013frslvgaqchh2j3chd87fkz-nixos-system-client-test.drv' building '/nix/store/v9pdj8yzw36gflaabn8zcajqkz6g77c2-activate.drv' building '/nix/store/viq76qy32r3f5fmrdfl3kxkd76yf1nsx-activate.drv' nixos-system-client-test> structuredAttrs is enabled building '/nix/store/g0c87lclwgiqgxal8dfw8r7i4ijy5ip9-nixos-system-server-test.drv' building '/nix/store/zqlk5h5hgdivkfzyx8vwzp37jkgxa6wi-nixos-system-ca-test.drv' building '/nix/store/irhv4z0cg239xyd7g3qfy0filzy6x49h-run-client-nspawn.drv' nixos-system-ca-test> structuredAttrs is enabled nixos-system-server-test> structuredAttrs is enabled building '/nix/store/v5a1gpabpcjv9wbc6mv5jwwapss61yqd-run-ca-nspawn.drv' building '/nix/store/7ly3gb7isb5hyiiwcj0kc22q5w0pwhn0-run-server-nspawn.drv' building '/nix/store/ba8a9qxyxd9j6xk6b8s923453aiqbhqs-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/lxaqh31566zqj7cr0srv05nkj24k43am-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! building '/nix/store/1p2g728k6skfwzvn1ff15vl2qnw0qkxf-container-test-run-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/1p2g728k6skfwzvn1ff15vl2qnw0qkxf-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> ca: systemd-nspawn running (pid 53) container-test-run-certificates> client: systemd-nspawn running (pid 54) container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> server: systemd-nspawn running (pid 55) container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> client # [28055.679271] client systemd-journald[69]: Journal started container-test-run-certificates> ca # [28055.683902] ca systemd-journald[78]: Journal started container-test-run-certificates> client # [28055.679306] client systemd-journald[69]: Runtime Journal (/run/log/journal/8fdef1d9f95c4403ad3ff82af7ee99c2) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> ca # [28055.683928] ca systemd-journald[78]: Runtime Journal (/run/log/journal/410b7e9e3cb7420589d51350d49c0226) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> client # [28055.680649] client systemd[1]: Finished Apply Kernel Variables. container-test-run-certificates> ca # [28055.686204] ca systemd[1]: Finished Apply Kernel Variables. container-test-run-certificates> client # [28055.685489] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [28055.689768] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [28055.691285] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [28055.694449] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [28055.691641] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [28055.694790] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [28055.691899] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [28055.695079] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> server # [28055.679204] server systemd-journald[69]: Journal started container-test-run-certificates> client # [28055.696475] client systemd-journald[69]: Time spent on flushing to /var/log/journal/8fdef1d9f95c4403ad3ff82af7ee99c2 is 1.116ms for 7 entries. container-test-run-certificates> server # [28055.679230] server systemd-journald[69]: Runtime Journal (/run/log/journal/9119f7eb025647e482913dc3efdad8b6) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> client # [28055.696475] client systemd-journald[69]: System Journal (/var/log/journal/8fdef1d9f95c4403ad3ff82af7ee99c2) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [28055.685428] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [28055.705076] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [28055.690949] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [28055.705256] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [28055.691302] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [28055.706207] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [28055.691604] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [28055.706258] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [28055.696480] server systemd-journald[69]: Time spent on flushing to /var/log/journal/9119f7eb025647e482913dc3efdad8b6 is 1.294ms for 6 entries. container-test-run-certificates> client # [28055.706690] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [28055.696480] server systemd-journald[69]: System Journal (/var/log/journal/9119f7eb025647e482913dc3efdad8b6) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [28055.706718] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [28055.699718] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [28055.707158] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [28055.699857] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [28055.707515] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [28055.699912] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [28055.707531] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [28055.700479] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [28055.717972] client systemd-tmpfiles[117]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [28055.700512] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [28055.718132] client systemd-tmpfiles[117]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [28055.701066] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [28055.718233] client systemd-tmpfiles[117]: fchmod() of /var/log/journal/8fdef1d9f95c4403ad3ff82af7ee99c2 failed: Operation not permitted container-test-run-certificates> server # [28055.701086] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [28055.718382] client systemd-tmpfiles[117]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [28055.705280] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [28055.719420] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [28055.705790] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [28055.720160] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [28055.715600] server systemd-tmpfiles[114]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [28055.720529] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [28055.715748] server systemd-tmpfiles[114]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [28055.735996] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [28055.715851] server systemd-tmpfiles[114]: fchmod() of /var/log/journal/9119f7eb025647e482913dc3efdad8b6 failed: Operation not permitted container-test-run-certificates> client # [28055.736134] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [28055.716003] server systemd-tmpfiles[114]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [28055.737494] client systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [28055.716887] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [28055.759755] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [28055.717535] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [28055.759875] client systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [28055.717960] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [28055.699116] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/410b7e9e3cb7420589d51350d49c0226 is 986us for 7 entries. container-test-run-certificates> server # [28055.724330] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [28055.699116] ca systemd-journald[78]: System Journal (/var/log/journal/410b7e9e3cb7420589d51350d49c0226) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [28055.736377] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [28055.705305] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [28055.737005] server systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [28055.705470] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [28055.759561] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [28055.771863] client systemd[1]: Finished Firewall. container-test-run-certificates> server # [28055.759692] server systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [28055.771947] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [28055.775727] server systemd[1]: Finished Firewall. container-test-run-certificates> client # [28055.772094] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [28055.775780] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [28055.772672] client systemd[1]: Starting Network Management... container-test-run-certificates> server # [28055.775924] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [28056.030773] client systemd-networkd[183]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [28055.776377] server systemd[1]: Starting Network Management... container-test-run-certificates> client # [28056.030842] client systemd-networkd[183]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [28056.033894] server systemd-networkd[187]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [28056.036783] client systemd-networkd[183]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [28056.033955] server systemd-networkd[187]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [28056.036924] client systemd-networkd[183]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [28056.039064] server systemd-networkd[187]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [28056.036987] client systemd-networkd[183]: lo: Link UP container-test-run-certificates> server # [28056.039207] server systemd-networkd[187]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [28056.036991] client systemd-networkd[183]: lo: Gained carrier container-test-run-certificates> server # [28056.039261] server systemd-networkd[187]: lo: Link UP container-test-run-certificates> client # [28056.037129] client systemd-networkd[183]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [28056.039264] server systemd-networkd[187]: lo: Gained carrier container-test-run-certificates> client # [28056.037340] client systemd[1]: Started Network Management. container-test-run-certificates> server # [28056.039382] server systemd-networkd[187]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [28056.037390] client systemd-networkd[183]: eth1: Link UP container-test-run-certificates> server # [28056.039582] server systemd[1]: Started Network Management. container-test-run-certificates> client # [28056.037526] client systemd-networkd[183]: eth1: Gained carrier container-test-run-certificates> ca # [28055.706133] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [28056.037896] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [28055.706195] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [28056.061134] server systemd-networkd[187]: eth1: Link UP container-test-run-certificates> ca # [28055.706651] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [28056.061137] server systemd-networkd[187]: eth1: Gained carrier container-test-run-certificates> client # [28056.064620] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [28056.061190] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [28056.181228] client systemd-resolved[96]: Positive Trust Anchors: container-test-run-certificates> server # [28056.068298] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [28056.181235] client systemd-resolved[96]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [28055.706677] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [28056.181238] client systemd-resolved[96]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [28055.707089] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [28055.707382] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [28055.707396] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [28055.717258] ca systemd-tmpfiles[121]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [28055.717406] ca systemd-tmpfiles[121]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [28055.717507] ca systemd-tmpfiles[121]: fchmod() of /var/log/journal/410b7e9e3cb7420589d51350d49c0226 failed: Operation not permitted container-test-run-certificates> ca # [28055.717660] ca systemd-tmpfiles[121]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [28055.718552] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [28055.719074] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [28055.719375] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [28055.726284] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [28055.736418] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [28055.737035] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [28055.759715] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [28055.760667] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [28055.782770] ca systemd[1]: Finished Firewall. container-test-run-certificates> ca # [28055.782839] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [28055.782974] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [28055.783565] ca systemd[1]: Starting Network Management... container-test-run-certificates> ca # [28056.039388] ca systemd-networkd[196]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [28056.039447] ca systemd-networkd[196]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [28056.044608] ca systemd-networkd[196]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [28056.044749] ca systemd-networkd[196]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [28056.044801] ca systemd-networkd[196]: lo: Link UP container-test-run-certificates> ca # [28056.044803] ca systemd-networkd[196]: lo: Gained carrier container-test-run-certificates> ca # [28056.044906] ca systemd-networkd[196]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [28056.045114] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [28056.061184] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [28056.061227] ca systemd-networkd[196]: eth1: Link UP container-test-run-certificates> ca # [28056.061395] ca systemd-networkd[196]: eth1: Gained carrier container-test-run-certificates> ca # [28056.074904] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [28056.183108] server systemd-resolved[94]: Positive Trust Anchors: container-test-run-certificates> server # [28056.183114] server systemd-resolved[94]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [28056.183117] server systemd-resolved[94]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [28056.183133] server systemd-resolved[94]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [28056.193995] server systemd-resolved[94]: Using system hostname 'server'. container-test-run-certificates> server # [28056.194846] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [28056.194896] server systemd[1]: Reached target Network. container-test-run-certificates> server # [28056.194926] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [28056.194954] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [28056.195120] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [28056.195138] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [28056.195152] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [28056.195164] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [28056.195243] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [28056.195298] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [28056.195370] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [28056.195380] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [28056.195399] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [28056.196428] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [28056.196868] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [28056.196887] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [28056.197325] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [28056.197975] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [28056.206831] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [28056.263652] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> server # [28056.263652] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [28056.263909] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> server # [28056.265448] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> server # [28056.266338] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [28056.266370] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> server # [28056.266370] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [28056.266370] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> server # [28056.271827] server nsncd[194]: Sep 04 15:04:30.695 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [28056.288965] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [28056.289045] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [28056.289076] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [28056.181252] client systemd-resolved[96]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [28056.182160] ca systemd-resolved[103]: Positive Trust Anchors: container-test-run-certificates> client # [28056.192300] client systemd-resolved[96]: Using system hostname 'client'. container-test-run-certificates> ca # [28056.182166] ca systemd-resolved[103]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [28056.193146] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [28056.182169] ca systemd-resolved[103]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [28056.193184] client systemd[1]: Reached target Network. container-test-run-certificates> ca # [28056.182184] ca systemd-resolved[103]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [28056.193218] client systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [28056.192300] ca systemd-resolved[103]: Using system hostname 'ca'. container-test-run-certificates> client # [28056.193250] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [28056.193139] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [28056.193176] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [28056.193205] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [28056.193231] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [28056.193271] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [28056.193363] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> client # [28056.193282] client systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [28056.193384] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [28056.193366] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [28056.193397] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [28056.193434] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [28056.193407] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [28056.193496] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [28056.193476] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [28056.193507] client systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [28056.193526] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [28056.193584] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [28056.193596] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [28056.193615] ca systemd[1]: Reached target Basic System. container-test-run-certificates> client # [28056.193527] client systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [28056.194250] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> client # [28056.194071] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [28056.194573] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [28056.194439] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [28056.195015] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [28056.194591] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> client # [28056.203861] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [28056.273398] client nsncd[189]: Sep 04 15:04:30.696 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [28056.273437] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [28056.194948] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [28056.195414] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [28056.195983] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [28056.273459] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [28056.204502] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [28056.273486] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [28056.261278] ca acme-setup-privileged[201]: + set -euo pipefail container-test-run-certificates> client # [28056.289644] client systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [28056.261278] ca acme-setup-privileged[201]: + cd /var/lib/acme container-test-run-certificates> client # [28056.290221] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [28056.261278] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [28056.262192] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [28056.262984] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [28056.263006] ca acme-setup-privileged[201]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [28056.263006] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [28056.263006] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [28056.276876] ca nsncd[203]: Sep 04 15:04:30.700 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [28056.276910] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [28056.276939] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [28056.276976] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [28056.289270] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [28056.289676] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [28056.295177] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [28056.295923] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [28056.295951] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [28056.295966] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [28056.340307] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [28056.340873] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [28056.340873] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/4vzgpfm4kzwpgh4dnhh0424yakwryx24-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [28056.341236] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [28056.344780] ca dbus-broker-launch[205]: Ready container-test-run-certificates> client # [28056.295201] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [28056.295594] client systemd[1]: Started Console Getty. container-test-run-certificates> client # [28056.295611] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [28056.295620] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [28056.343326] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [28056.343669] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [28056.343669] client dbus-broker-launch[190]: Invalid user-name in /nix/store/icmxydgsz8d39ksbqbi94w3l6jsf5nzr-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [28056.343875] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [28056.348119] client dbus-broker-launch[190]: Ready container-test-run-certificates> server # [28056.289526] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [28056.289893] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [28056.295157] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [28056.295603] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [28056.295621] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [28056.295631] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [28056.335740] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [28056.336003] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [28056.336003] server dbus-broker-launch[195]: Invalid user-name in /nix/store/8fwk090ldbcg1sqhkr2m0q8vsr6xq7pq-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [28056.336279] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [28056.339511] server dbus-broker-launch[195]: Ready container-test-run-certificates> client # [28056.601288] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [28056.601359] client systemd[1]: Started User Login Management. container-test-run-certificates> client # [28056.601911] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [28056.626415] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [28056.626496] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [28056.626698] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [28056.626778] client systemd[1]: Startup finished in 1.201s. container-test-run-certificates> client # [28056.673043] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [28056.610485] server systemd-logind[219]: New seat seat0. container-test-run-certificates> server # [28056.610565] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [28056.622233] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [28056.630674] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [28056.630743] server systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [28056.641677] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> server # [28056.641677] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> server # [28056.641891] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [28056.648386] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [28056.649217] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server # [28056.672789] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [28056.617634] ca systemd-logind[231]: New seat seat0. container-test-run-certificates> ca # [28056.617719] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [28056.622188] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [28056.630707] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [28056.630770] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [28056.642666] ca acme-setup-start[219]: + set -euo pipefail container-test-run-certificates> ca # [28056.642666] ca acme-setup-start[219]: + test -e ca/key.pem container-test-run-certificates> ca # [28056.642841] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [28056.648632] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [28056.649906] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> ca # [28056.677726] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [28056.739130] ca step-ca[204]: badger 2026/09/04 15:04:31 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [28056.740829] ca step-ca[204]: 2026/09/04 15:04:31 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [28056.742791] ca step-ca[204]: 2026/09/04 15:04:31 Starting Smallstep CA/0.30.2 (linux/amd64) container-test-run-certificates> ca # [28056.742791] ca step-ca[204]: 2026/09/04 15:04:31 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [28056.742791] ca step-ca[204]: 2026/09/04 15:04:31 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [28056.742791] ca step-ca[204]: 2026/09/04 15:04:31 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [28056.742791] ca step-ca[204]: 2026/09/04 15:04:31 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [28056.742791] ca step-ca[204]: 2026/09/04 15:04:31 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [28056.742875] ca step-ca[204]: 2026/09/04 15:04:31 X.509 Root Fingerprint: 34c5eaf7996cc69329be97a5292cb19e2edb9de68f112cb88f7884a81801e378 container-test-run-certificates> ca # [28056.742892] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [28056.743041] ca step-ca[204]: 2026/09/04 15:04:31 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> ca # [28056.990325] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [28056.985087] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [28056.991999] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [28056.986555] server acme-test.foo-start[245]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [28056.991999] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> server # [28056.986596] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> ca # [28056.996217] ca acme-ca.foo-start[283]: + cd ca.foo container-test-run-certificates> server # [28056.990929] server acme-test.foo-start[255]: + cd test.foo container-test-run-certificates> ca # [28056.996382] ca acme-ca.foo-start[283]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [28056.991143] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [28056.997063] ca acme-ca.foo-start[284]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [28056.991782] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [28056.997201] ca acme-ca.foo-start[283]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [28056.991928] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [28056.992783] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [28056.997892] ca acme-ca.foo-start[283]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [28056.992936] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [28056.998035] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [28056.993895] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [28056.999074] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [28056.994813] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [28057.000085] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [28056.995796] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> ca # [28057.001071] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> server # [28056.995824] server acme-test.foo-start[245]: + '[' -d out ']' container-test-run-certificates> ca # [28057.001084] ca acme-ca.foo-start[256]: + '[' -d out ']' container-test-run-certificates> server # [28056.995824] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [28057.001084] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [28056.996801] server acme-test.foo-start[245]: + chown -R acme:nginx out container-test-run-certificates> ca # [28057.001975] ca acme-ca.foo-start[256]: + chown -R acme:nginx out container-test-run-certificates> server # [28056.998410] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> ca # [28057.003508] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> server # [28056.998410] server acme-test.foo-start[245]: + '[' -d certificates ']' container-test-run-certificates> ca # [28057.003508] ca acme-ca.foo-start[256]: + '[' -d certificates ']' container-test-run-certificates> server # [28056.999880] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [28057.000717] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [28057.026127] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [28057.026990] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [28057.217089] ca systemd-networkd[196]: eth1: Gained IPv6LL container-test-run-certificates> server # [28057.370298] server nginx-pre-start[267]: nginx: the configuration file /nix/store/azxra0kwyr9l6lycxi5yqm3sirghcz7b-nginx.conf syntax is ok container-test-run-certificates> server # [28057.370616] server nginx-pre-start[267]: nginx: configuration file /nix/store/azxra0kwyr9l6lycxi5yqm3sirghcz7b-nginx.conf test is successful container-test-run-certificates> server # [28057.373849] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [28057.374082] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [28057.374795] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [28057.433531] ca nginx-pre-start[295]: nginx: the configuration file /nix/store/h4x3ign3zh19y9f280zxnzk3g4ds9pbk-nginx.conf syntax is ok container-test-run-certificates> ca # [28057.433839] ca nginx-pre-start[295]: nginx: configuration file /nix/store/h4x3ign3zh19y9f280zxnzk3g4ds9pbk-nginx.conf test is successful container-test-run-certificates> ca # [28057.436339] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [28057.436554] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [28057.437233] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca # [28057.792646] ca acme-order-renew-ca.foo-start[298]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [28057.794251] ca acme-order-renew-ca.foo-start[298]: + set -euo pipefail container-test-run-certificates> ca # [28057.794291] ca acme-order-renew-ca.foo-start[298]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [28057.794345] ca acme-order-renew-ca.foo-start[298]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [28057.795126] ca acme-order-renew-ca.foo-start[298]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [28057.803104] ca acme-order-renew-ca.foo-start[309]: 2026/09/04 15:04:32 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [28057.803268] ca acme-order-renew-ca.foo-start[309]: 2026/09/04 15:04:32 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [28057.816245] ca step-ca[204]: time="2026-09-04T15:04:32Z" level=info duration="95.881µs" duration-ns=95881 fields.time="2026-09-04T15:04:32Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=e385aa0e-796c-4024-a4b8-3fd861316bb3 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [28057.816558] ca acme-order-renew-ca.foo-start[309]: 2026/09/04 15:04:32 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [28057.826068] ca step-ca[204]: time="2026-09-04T15:04:32Z" level=info duration=9.533125ms duration-ns=9533125 fields.time="2026-09-04T15:04:32Z" method=HEAD name=ca nonce=Vk1JZlBPN0lQNWp4WFRsd3dEdzd1NFlGZzVnVlR1bHE path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=e1ac3473-070e-4803-bf61-2af86bbc8796 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [28057.827425] ca step-ca[204]: time="2026-09-04T15:04:32Z" level=info duration=1.026733ms duration-ns=1026733 fields.time="2026-09-04T15:04:32Z" method=POST name=ca nonce=UXFST25aSm5DTjkxZ00wZEdpYUFOZlZhYVJkZUY5TWc path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=2a2c8b55-64f9-4fa9-a085-c7439f86e7d8 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/BIBnYljVWjwpBztSvCOCxPzGfelGOCn7/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [28057.827542] ca acme-order-renew-ca.foo-start[309]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [28057.827542] ca acme-order-renew-ca.foo-start[309]: Your account credentials have been saved in your container-test-run-certificates> ca # [28057.827542] ca acme-order-renew-ca.foo-start[309]: configuration directory at "accounts". container-test-run-certificates> ca # [28057.827542] ca acme-order-renew-ca.foo-start[309]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [28057.827542] ca acme-order-renew-ca.foo-start[309]: configuration directory will also contain private keys container-test-run-certificates> ca # [28057.827542] ca acme-order-renew-ca.foo-start[309]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [28057.827542] ca acme-order-renew-ca.foo-start[309]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [28057.827625] ca acme-order-renew-ca.foo-start[309]: 2026/09/04 15:04:32 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [28057.829010] ca step-ca[204]: time="2026-09-04T15:04:32Z" level=info duration=1.270132ms duration-ns=1270132 fields.time="2026-09-04T15:04:32Z" method=POST name=ca nonce=S1dBUEp6NkIzS05LTWRHYzl5dWZTTk1Od3ZjT0lOMUs path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=1fc1a635-3512-43de-8e04-19faedc35ac1 response="{\"id\":\"xt3vKRxeDsxEWMf8gAjWFzkd2gblXWY4\",\"status\":\"pending\",\"expires\":\"2026-09-05T15:04:32Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-09-04T15:03:32Z\",\"notAfter\":\"2026-12-03T15:04:32Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/Tf0joFIQ6Ni1P4ZNTV5d11F3x3He71UQ\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/xt3vKRxeDsxEWMf8gAjWFzkd2gblXWY4/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [28057.895226] ca step-ca[204]: time="2026-09-04T15:04:32Z" level=info duration=9.799907ms duration-ns=9799907 fields.time="2026-09-04T15:04:32Z" method=POST name=ca nonce=ZWtReE5DRVFyc0NpSzNyS1NFYkx2R1U5QXBXdkpZcWg path=/acme/acme/authz/Tf0joFIQ6Ni1P4ZNTV5d11F3x3He71UQ protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=570e6d4f-5958-46f5-bff9-47982a10f410 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"dSjwcNHxSJKCIRJtI1tUUHDJkkZr0FuX\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/Tf0joFIQ6Ni1P4ZNTV5d11F3x3He71UQ/Szrhnd2hAmAeJ4zXJhqJiQRZRK9jKRgp\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"dSjwcNHxSJKCIRJtI1tUUHDJkkZr0FuX\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/Tf0joFIQ6Ni1P4ZNTV5d11F3x3He71UQ/lNiOJWWgL3Y6kXnVaDwGz1XNhDCt7eqg\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"dSjwcNHxSJKCIRJtI1tUUHDJkkZr0FuX\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/Tf0joFIQ6Ni1P4ZNTV5d11F3x3He71UQ/IeE1cbRSmH3auE8weUjkdUhPlRABAOU0\"}],\"wildcard\":false,\"expires\":\"2026-09-05T15:04:32Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [28057.895375] ca acme-order-renew-ca.foo-start[309]: 2026/09/04 15:04:32 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/Tf0joFIQ6Ni1P4ZNTV5d11F3x3He71UQ container-test-run-certificates> ca # [28057.895375] ca acme-order-renew-ca.foo-start[309]: 2026/09/04 15:04:32 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [28057.895375] ca acme-order-renew-ca.foo-start[309]: 2026/09/04 15:04:32 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [28057.895375] ca acme-order-renew-ca.foo-start[309]: 2026/09/04 15:04:32 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [28057.897355] ca step-ca[204]: time="2026-09-04T15:04:32Z" level=info duration=1.580096ms duration-ns=1580096 fields.time="2026-09-04T15:04:32Z" method=POST name=ca nonce=YTVWQ2tCTVc0TGcwN092RG1nbXVXNjg3RFg2U0M1Qjk path=/acme/acme/challenge/Tf0joFIQ6Ni1P4ZNTV5d11F3x3He71UQ/lNiOJWWgL3Y6kXnVaDwGz1XNhDCt7eqg protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=93211277-0da9-4089-9482-9d2673e7bae6 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"dSjwcNHxSJKCIRJtI1tUUHDJkkZr0FuX\",\"validated\":\"2026-09-04T15:04:32Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/Tf0joFIQ6Ni1P4ZNTV5d11F3x3He71UQ/lNiOJWWgL3Y6kXnVaDwGz1XNhDCt7eqg\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [28057.897473] ca acme-order-renew-ca.foo-start[309]: 2026/09/04 15:04:32 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [28057.897501] ca acme-order-renew-ca.foo-start[309]: 2026/09/04 15:04:32 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [28057.899854] ca step-ca[204]: time="2026-09-04T15:04:32Z" level=info duration=2.094826ms duration-ns=2094826 fields.time="2026-09-04T15:04:32Z" method=POST name=ca nonce=UUN1bjNqa1phU2lUY1JoWnllaVM3Q3pXaVFpaXpjUGs path=/acme/acme/order/xt3vKRxeDsxEWMf8gAjWFzkd2gblXWY4/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=ba1cff73-bd49-49c7-8b5f-f1c5dbbe7ce7 response="{\"id\":\"xt3vKRxeDsxEWMf8gAjWFzkd2gblXWY4\",\"status\":\"valid\",\"expires\":\"2026-09-05T15:04:32Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-09-04T15:03:32Z\",\"notAfter\":\"2026-12-03T15:04:32Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/Tf0joFIQ6Ni1P4ZNTV5d11F3x3He71UQ\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/xt3vKRxeDsxEWMf8gAjWFzkd2gblXWY4/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/nXimQlER6sh1QIkZ4yiwmt2yUqrhQhme\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [28057.900456] ca step-ca[204]: time="2026-09-04T15:04:32Z" level=info certificate="MIIB1TCCAXqgAwIBAgIRANm+EzfajmgG+tTSl2W68LswCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwOTA0MTUwMzMyWhcNMjYxMjAzMTUwNDMyWjARMQ8wDQYDVQQDEwZjYS5mb28wWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAThZkLKJ9+zz1IKiH9KyRWBmgvbqsH58UTQqAsKTk99kPijptRhUKpPtzdkBzP/wm5CAV+Jr9zfL7ATu11/jJiJo4GkMIGhMA4GA1UdDwEB/wQEAwIHgDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHQYDVR0OBBYEFP2Mp6IbVbGYFEbXTz4I1Uja1KsXMB8GA1UdIwQYMBaAFF0HNHjDUaCZav3Yd2vh89X9O0RjMBEGA1UdEQQKMAiCBmNhLmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSQAwRgIhAPWkftCtLwe/Wo01HzvHnCfr3d9QslfCIvXGTYROVORFAiEAyslDuR7iFtbs75JJG5QqPd1XmwPhL5fHY2dXcGdY/IY=" duration="398.46µs" duration-ns=398460 fields.time="2026-09-04T15:04:32Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=ZllxQjl5UzREV0ZVc1owQTAyRGpqZFlTdTZZYURlTXo path=/acme/acme/certificate/nXimQlER6sh1QIkZ4yiwmt2yUqrhQhme protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=5a3cf811-6a3a-43e2-b60e-0ef987f8edd6 sans="map[dns:[ca.foo]]" serial=289429401279419660198131036988481663163 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-09-04T15:03:32Z" valid-to="2026-12-03T15:04:32Z" container-test-run-certificates> ca # [28057.900537] ca acme-order-renew-ca.foo-start[309]: 2026/09/04 15:04:32 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [28057.903059] ca acme-order-renew-ca.foo-start[298]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [28057.904046] ca acme-order-renew-ca.foo-start[298]: + touch out/acme-success container-test-run-certificates> ca # [28057.904827] ca acme-order-renew-ca.foo-start[298]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [28057.905620] ca acme-order-renew-ca.foo-start[298]: + touch out/renewed container-test-run-certificates> ca # [28057.906336] ca acme-order-renew-ca.foo-start[298]: + echo Installing new certificate container-test-run-certificates> ca # [28057.906336] ca acme-order-renew-ca.foo-start[298]: Installing new certificate container-test-run-certificates> ca # [28057.906360] ca acme-order-renew-ca.foo-start[298]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [28057.907037] ca acme-order-renew-ca.foo-start[331]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [28057.907158] ca acme-order-renew-ca.foo-start[298]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [28057.907810] ca acme-order-renew-ca.foo-start[332]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [28057.907924] ca acme-order-renew-ca.foo-start[298]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [28057.908583] ca acme-order-renew-ca.foo-start[333]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [28057.908700] ca acme-order-renew-ca.foo-start[298]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [28057.909513] ca acme-order-renew-ca.foo-start[298]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [28057.910330] ca acme-order-renew-ca.foo-start[298]: + for fixpath in out certificates container-test-run-certificates> ca # [28057.910330] ca acme-order-renew-ca.foo-start[298]: + '[' -d out ']' container-test-run-certificates> ca # [28057.910364] ca acme-order-renew-ca.foo-start[298]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [28057.911091] ca acme-order-renew-ca.foo-start[298]: + chown -R acme:nginx out container-test-run-certificates> ca # [28057.912324] ca acme-order-renew-ca.foo-start[298]: + for fixpath in out certificates container-test-run-certificates> ca # [28057.912324] ca acme-order-renew-ca.foo-start[298]: + '[' -d certificates ']' container-test-run-certificates> ca # [28057.912356] ca acme-order-renew-ca.foo-start[298]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [28057.913120] ca acme-order-renew-ca.foo-start[298]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [28057.914519] ca acme-order-renew-ca.foo-start[298]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [28057.989505] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [28057.991395] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [28057.991515] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server # [28057.750163] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [28057.751867] server acme-order-renew-test.foo-start[270]: + set -euo pipefail container-test-run-certificates> server # [28057.751908] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [28057.751963] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [28057.752559] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [28057.762033] server acme-order-renew-test.foo-start[281]: 2026/09/04 15:04:32 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [28057.762214] server acme-order-renew-test.foo-start[281]: 2026/09/04 15:04:32 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> client # [28057.984111] client systemd-networkd[183]: eth1: Gained IPv6LL container-test-run-certificates> server # [28058.113102] server systemd-networkd[187]: eth1: Gained IPv6LL container-test-run-certificates> ca # [28058.349493] ca nginx[349]: nginx: the configuration file /nix/store/h4x3ign3zh19y9f280zxnzk3g4ds9pbk-nginx.conf syntax is ok container-test-run-certificates> ca # [28058.349710] ca nginx[349]: nginx: configuration file /nix/store/h4x3ign3zh19y9f280zxnzk3g4ds9pbk-nginx.conf test is successful container-test-run-certificates> ca # [28058.732286] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [28058.732553] ca systemd[1]: Startup finished in 3.298s. container-test-run-certificates> ca # [28058.821789] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> server # [28058.777382] server acme-order-renew-test.foo-start[281]: 2026/09/04 15:04:33 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 2 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [28058.779759] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [28058.779759] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [28058.779911] server acme-order-renew-test.foo-start[270]: + exit 10 container-test-run-certificates> server # [28058.781455] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [28058.781547] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [28058.781740] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [28058.781965] server systemd[1]: Startup finished in 3.353s. container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 1.16 seconds) container-test-run-certificates> ca # [28059.224867] ca acme-order-renew-ca.foo-start[364]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [28059.226491] ca acme-order-renew-ca.foo-start[364]: + set -euo pipefail container-test-run-certificates> ca # [28059.226549] ca acme-order-renew-ca.foo-start[364]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [28059.226568] ca acme-order-renew-ca.foo-start[364]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [28059.227212] ca acme-order-renew-ca.foo-start[364]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [28059.227212] ca acme-order-renew-ca.foo-start[364]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [28059.227400] ca acme-order-renew-ca.foo-start[372]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [28059.228779] ca acme-order-renew-ca.foo-start[364]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [28059.228819] ca acme-order-renew-ca.foo-start[364]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [28059.247201] ca step-ca[204]: time="2026-09-04T15:04:33Z" level=info duration="38.422µs" duration-ns=38422 fields.time="2026-09-04T15:04:33Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=dfbdc433-f8fb-4c78-943d-eaf10a75b43b response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [28059.247441] ca acme-order-renew-ca.foo-start[373]: 2026/09/04 15:04:33 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [28059.247441] ca acme-order-renew-ca.foo-start[373]: 2026/09/04 15:04:33 [INFO] [ca.foo] The certificate expires at 2026-12-03T15:04:32Z, the renewal can be performed in 1439h59m38.329338419s: no renewal. container-test-run-certificates> ca # [28059.247505] ca acme-order-renew-ca.foo-start[364]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [28059.248342] ca acme-order-renew-ca.foo-start[364]: + touch out/acme-success container-test-run-certificates> ca # [28059.249116] ca acme-order-renew-ca.foo-start[364]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [28059.249689] ca acme-order-renew-ca.foo-start[364]: + for fixpath in out certificates container-test-run-certificates> ca # [28059.249699] ca acme-order-renew-ca.foo-start[364]: + '[' -d out ']' container-test-run-certificates> ca # [28059.249699] ca acme-order-renew-ca.foo-start[364]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [28059.250504] ca acme-order-renew-ca.foo-start[364]: + chown -R acme:nginx out container-test-run-certificates> ca # [28059.251708] ca acme-order-renew-ca.foo-start[364]: + for fixpath in out certificates container-test-run-certificates> ca # [28059.251720] ca acme-order-renew-ca.foo-start[364]: + '[' -d certificates ']' container-test-run-certificates> ca # [28059.251720] ca acme-order-renew-ca.foo-start[364]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [28059.252534] ca acme-order-renew-ca.foo-start[364]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [28059.253681] ca acme-order-renew-ca.foo-start[364]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [28059.339617] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [28059.339732] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [28062.346692] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [28062.346774] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [28062.347303] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [28062.348078] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.38 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1011 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 4 15:04:31 2026 GMT container-test-run-certificates> * expire date: Oct 4 15:04:31 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 6be781 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [28062.707859] server acme-test.foo-start[305]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [28062.709239] server acme-test.foo-start[305]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [28062.709239] server acme-test.foo-start[305]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [28062.713855] server acme-test.foo-start[315]: + cd test.foo container-test-run-certificates> server # [28062.714062] server acme-test.foo-start[315]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [28062.714925] server acme-test.foo-start[316]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [28062.715068] server acme-test.foo-start[315]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [28062.715684] server acme-test.foo-start[315]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [28062.715808] server acme-test.foo-start[305]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [28062.716929] server acme-test.foo-start[305]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [28062.717762] server acme-test.foo-start[305]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [28062.718540] server acme-test.foo-start[305]: + for fixpath in out certificates container-test-run-certificates> server # [28062.718550] server acme-test.foo-start[305]: + '[' -d out ']' container-test-run-certificates> server # [28062.718559] server acme-test.foo-start[305]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [28062.719295] server acme-test.foo-start[305]: + chown -R acme:nginx out container-test-run-certificates> server # [28062.720551] server acme-test.foo-start[305]: + for fixpath in out certificates container-test-run-certificates> server # [28062.720562] server acme-test.foo-start[305]: + '[' -d certificates ']' container-test-run-certificates> server # [28062.721896] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [28062.723240] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [28063.099365] ca step-ca[204]: time="2026-09-04T15:04:37Z" level=info duration="33.393µs" duration-ns=33393 fields.time="2026-09-04T15:04:37Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=a67904c5-f85f-441c-acd9-938127113493 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> server # [28063.076369] server acme-order-renew-test.foo-start[323]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [28063.137579] ca step-ca[204]: time="2026-09-04T15:04:37Z" level=info duration=37.082481ms duration-ns=37082481 fields.time="2026-09-04T15:04:37Z" method=HEAD name=ca nonce=OUlLQXhMVzVLZzVmTUtZeGpVUnBsOFVxTmV2NVNuaVA path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=e3b58987-9289-48d8-823c-c0efe49591ac size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> server # [28063.077649] server acme-order-renew-test.foo-start[323]: + set -euo pipefail container-test-run-certificates> ca # [28063.141516] ca step-ca[204]: time="2026-09-04T15:04:37Z" level=info duration=3.030076ms duration-ns=3030076 fields.time="2026-09-04T15:04:37Z" method=POST name=ca nonce=N2dqOUxOb0RPU1Z3Tm1iUEhNclEzSHNmeFdLZDhrdXk path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=84864c4d-9c50-4302-b407-030db490f508 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/r4RAQPQ8Z8wV4sJwarzujPd7aLOhvoHV/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> server # [28063.077688] server acme-order-renew-test.foo-start[323]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> ca # [28063.143821] ca step-ca[204]: time="2026-09-04T15:04:37Z" level=info duration=1.427809ms duration-ns=1427809 fields.time="2026-09-04T15:04:37Z" method=POST name=ca nonce=ZHdGYjA1MjR4RXI0UWJqUmdYOEFvNXJ5czB1OVVlaVI path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=dd1c4bfd-371d-4f5e-90a3-bf6cc704c892 response="{\"id\":\"kbUGM49Tjbq4mfZUwqAbOWaalCaXLPPR\",\"status\":\"pending\",\"expires\":\"2026-09-05T15:04:37Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-09-04T15:03:37Z\",\"notAfter\":\"2026-12-03T15:04:37Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/I5tNXPERXWnlUHOR12inZ9LIZ5KwKhbg\"],\"finalize\":\"https://ca.foo/acme/acme/order/kbUGM49Tjbq4mfZUwqAbOWaalCaXLPPR/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> server # [28063.077739] server acme-order-renew-test.foo-start[323]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [28063.205967] ca step-ca[204]: time="2026-09-04T15:04:37Z" level=info duration=5.089826ms duration-ns=5089826 fields.time="2026-09-04T15:04:37Z" method=POST name=ca nonce=bVZobklKampLcThiZWd6eFRLTjdjNnNrd0FLeVV4cjU path=/acme/acme/authz/I5tNXPERXWnlUHOR12inZ9LIZ5KwKhbg protocol=HTTP/1.1 referer= remote-address="::1" request-id=e6690846-1cd2-4702-bc32-cca78a744094 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"AXn33wJkJp0rIeaACdJAQlarSlxrPFuY\",\"url\":\"https://ca.foo/acme/acme/challenge/I5tNXPERXWnlUHOR12inZ9LIZ5KwKhbg/1leIJ80DXE5HIeyLU2ttyZPv52dZBl4j\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"AXn33wJkJp0rIeaACdJAQlarSlxrPFuY\",\"url\":\"https://ca.foo/acme/acme/challenge/I5tNXPERXWnlUHOR12inZ9LIZ5KwKhbg/pEVIZZvzBih8rQ3onOwJc1I48D8IRjTn\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"AXn33wJkJp0rIeaACdJAQlarSlxrPFuY\",\"url\":\"https://ca.foo/acme/acme/challenge/I5tNXPERXWnlUHOR12inZ9LIZ5KwKhbg/bBya16eJ7eUX7xDt8EsnRqTgkxB0UBHD\"}],\"wildcard\":false,\"expires\":\"2026-09-05T15:04:37Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> server # [28063.078321] server acme-order-renew-test.foo-start[323]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> ca # [28063.208312] ca step-ca[204]: time="2026-09-04T15:04:37Z" level=info duration=1.483264ms duration-ns=1483264 fields.time="2026-09-04T15:04:37Z" method=POST name=ca nonce=VEdNVmk3NzVLZDhJT0lEenkyNDQ3RllYQ29wZUE1dnc path=/acme/acme/challenge/I5tNXPERXWnlUHOR12inZ9LIZ5KwKhbg/pEVIZZvzBih8rQ3onOwJc1I48D8IRjTn protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=0c7af846-592b-4f13-8d27-7119f0a0851f response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"AXn33wJkJp0rIeaACdJAQlarSlxrPFuY\",\"validated\":\"2026-09-04T15:04:37Z\",\"url\":\"https://ca.foo/acme/acme/challenge/I5tNXPERXWnlUHOR12inZ9LIZ5KwKhbg/pEVIZZvzBih8rQ3onOwJc1I48D8IRjTn\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> server # [28063.099561] server acme-order-renew-test.foo-start[331]: 2026/09/04 15:04:37 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [28063.211468] ca step-ca[204]: time="2026-09-04T15:04:37Z" level=info duration=2.253945ms duration-ns=2253945 fields.time="2026-09-04T15:04:37Z" method=POST name=ca nonce=RzJLQTkxNXlkVFBrNUl0V0szOXdqM1hOQVAwUjNlYnE path=/acme/acme/order/kbUGM49Tjbq4mfZUwqAbOWaalCaXLPPR/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=1bb59b67-eea0-43d5-8045-cbfd8eda46ff response="{\"id\":\"kbUGM49Tjbq4mfZUwqAbOWaalCaXLPPR\",\"status\":\"valid\",\"expires\":\"2026-09-05T15:04:37Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-09-04T15:03:37Z\",\"notAfter\":\"2026-12-03T15:04:37Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/I5tNXPERXWnlUHOR12inZ9LIZ5KwKhbg\"],\"finalize\":\"https://ca.foo/acme/acme/order/kbUGM49Tjbq4mfZUwqAbOWaalCaXLPPR/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/Pk48AEeopRiwVejabx1cWChylefJumtd\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> server # [28063.141685] server acme-order-renew-test.foo-start[331]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [28063.212668] ca step-ca[204]: time="2026-09-04T15:04:37Z" level=info certificate="MIIB1zCCAX2gAwIBAgIQXi4nD4X3hgAqKBSd5vVGvDAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA5MDQxNTAzMzdaFw0yNjEyMDMxNTA0MzdaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEJzrjgT+X6ZtvRS1z/wXp0Dz0Mt8Js8k8AsDiU5xAwdRAn9+f1VPviXVzdNsYF2WUi1VklhQo7nkqgEQ2Vs2riaOBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBSVJ5K5DwiNbrvXCqW4IHw6uOXDijAfBgNVHSMEGDAWgBRdBzR4w1GgmWr92Hdr4fPV/TtEYzATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSAAwRQIhAM3QJSiWG3VXHaHhhUsEPPJ0xs+o7SZmRIdQA5AeTGyiAiAwQ+d2ka6O4fYldqEjzgmVZns+rWRMgs1ciS/pmREGmQ==" duration="515.01µs" duration-ns=515010 fields.time="2026-09-04T15:04:37Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=NVNwZ3NQd2tRVEhrb3dtRGNHTWJETkhvcmtCbDh1aHE path=/acme/acme/certificate/Pk48AEeopRiwVejabx1cWChylefJumtd protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=132ba206-842a-4026-a36c-6efe06058a5c sans="map[dns:[test.foo]]" serial=125187069503132418036811977039541520060 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-09-04T15:03:37Z" valid-to="2026-12-03T15:04:37Z" container-test-run-certificates> server # [28063.141685] server acme-order-renew-test.foo-start[331]: Your account credentials have been saved in your container-test-run-certificates> server # [28063.141685] server acme-order-renew-test.foo-start[331]: configuration directory at "accounts". container-test-run-certificates> server # [28063.141685] server acme-order-renew-test.foo-start[331]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [28063.141685] server acme-order-renew-test.foo-start[331]: configuration directory will also contain private keys container-test-run-certificates> server # [28063.141685] server acme-order-renew-test.foo-start[331]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [28063.141685] server acme-order-renew-test.foo-start[331]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [28063.141685] server acme-order-renew-test.foo-start[331]: 2026/09/04 15:04:37 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [28063.206143] server acme-order-renew-test.foo-start[331]: 2026/09/04 15:04:37 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/I5tNXPERXWnlUHOR12inZ9LIZ5KwKhbg container-test-run-certificates> server # [28063.206143] server acme-order-renew-test.foo-start[331]: 2026/09/04 15:04:37 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [28063.206143] server acme-order-renew-test.foo-start[331]: 2026/09/04 15:04:37 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [28063.206220] server acme-order-renew-test.foo-start[331]: 2026/09/04 15:04:37 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [28063.208456] server acme-order-renew-test.foo-start[331]: 2026/09/04 15:04:37 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [28063.208488] server acme-order-renew-test.foo-start[331]: 2026/09/04 15:04:37 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [28063.212791] server acme-order-renew-test.foo-start[331]: 2026/09/04 15:04:37 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [28063.215783] server acme-order-renew-test.foo-start[323]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [28063.216656] server acme-order-renew-test.foo-start[323]: + touch out/acme-success container-test-run-certificates> server # [28063.217415] server acme-order-renew-test.foo-start[323]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [28063.217960] server acme-order-renew-test.foo-start[323]: + touch out/renewed container-test-run-certificates> server # [28063.218658] server acme-order-renew-test.foo-start[323]: + echo Installing new certificate container-test-run-certificates> server # [28063.218658] server acme-order-renew-test.foo-start[323]: Installing new certificate container-test-run-certificates> server # [28063.218680] server acme-order-renew-test.foo-start[323]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [28063.219363] server acme-order-renew-test.foo-start[352]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [28063.219490] server acme-order-renew-test.foo-start[323]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [28063.220156] server acme-order-renew-test.foo-start[353]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [28063.220267] server acme-order-renew-test.foo-start[323]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [28063.220902] server acme-order-renew-test.foo-start[354]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [28063.221016] server acme-order-renew-test.foo-start[323]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [28063.221762] server acme-order-renew-test.foo-start[323]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [28063.222541] server acme-order-renew-test.foo-start[323]: + for fixpath in out certificates container-test-run-certificates> server # [28063.222552] server acme-order-renew-test.foo-start[323]: + '[' -d out ']' container-test-run-certificates> server # [28063.222552] server acme-order-renew-test.foo-start[323]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [28063.223387] server acme-order-renew-test.foo-start[323]: + chown -R acme:nginx out container-test-run-certificates> server # [28063.224582] server acme-order-renew-test.foo-start[323]: + for fixpath in out certificates container-test-run-certificates> server # [28063.224600] server acme-order-renew-test.foo-start[323]: + '[' -d certificates ']' container-test-run-certificates> server # [28063.224600] server acme-order-renew-test.foo-start[323]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [28063.225365] server acme-order-renew-test.foo-start[323]: + chown -R acme:nginx certificates container-test-run-certificates> server # [28063.226856] server acme-order-renew-test.foo-start[323]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> server # [28063.302022] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [28063.303916] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [28063.304013] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1011 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [110 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 4 15:04:31 2026 GMT container-test-run-certificates> * expire date: Oct 4 15:04:31 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 6be781 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [28063.656310] server nginx[370]: nginx: the configuration file /nix/store/azxra0kwyr9l6lycxi5yqm3sirghcz7b-nginx.conf syntax is ok container-test-run-certificates> server # [28063.656589] server nginx[370]: nginx: configuration file /nix/store/azxra0kwyr9l6lycxi5yqm3sirghcz7b-nginx.conf test is successful container-test-run-certificates> server # [28064.016322] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [929 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [80 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 4 15:03:37 2026 GMT container-test-run-certificates> * expire date: Dec 3 15:04:37 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 33732 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 1752 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 2.06 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> 5e:2e:27:0f:85:f7:86:00:2a:28:14:9d:e6:f5:46:bc container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Sep 4 15:03:37 2026 GMT container-test-run-certificates> Not After : Dec 3 15:04:37 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:27:3a:e3:81:3f:97:e9:9b:6f:45:2d:73:ff:05: container-test-run-certificates> e9:d0:3c:f4:32:df:09:b3:c9:3c:02:c0:e2:53:9c: container-test-run-certificates> 40:c1:d4:40:9f:df:9f:d5:53:ef:89:75:73:74:db: container-test-run-certificates> 18:17:65:94:8b:55:64:96:14:28:ee:79:2a:80:44: container-test-run-certificates> 36:56:cd:ab:89 container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> 95:27:92:B9:0F:08:8D:6E:BB:D7:0A:A5:B8:20:7C:3A:B8:E5:C3:8A container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> 5D:07:34:78:C3:51:A0:99:6A:FD:D8:77:6B:E1:F3:D5:FD:3B:44:63 container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:45:02:21:00:cd:d0:25:28:96:1b:75:57:1d:a1:e1:85:4b: container-test-run-certificates> 04:3c:f2:74:c6:cf:a8:ed:26:66:44:87:50:03:90:1e:4c:6c: container-test-run-certificates> a2:02:20:30:43:e7:76:91:ae:8e:e1:f6:25:76:a1:23:ce:09: container-test-run-certificates> 95:66:7b:3e:ad:64:4c:82:cd:5c:89:2f:e9:99:11:06:99 container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.02 seconds) container-test-run-certificates> (finished: run the VM test script, in 9.62 seconds) container-test-run-certificates> test script finished in 11.04s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 53) container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> kill NspawnMachine (pid 55) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> Container server terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.21 seconds) post-build step Upload to niks3: ok time=2026-09-04T15:04:41.187Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-09-04T15:04:41.569Z level=INFO msg="Uploading 1 narinfos" time=2026-09-04T15:04:41.955Z level=INFO msg="Upload complete. (821ms)"