these 174 derivations will be built: /nix/store/07182vp9nm48fkgibfn911dbhlvs6isg-vars-check-certificates.drv /nix/store/10cjbryhq5paprzm1glmzihlq892wip3-etc-hostname.drv /nix/store/206g7s9riiy6lv7v18s759skhyssvl7h-etc-os-release.drv /nix/store/791h9g6qz4m9cfn07nwzi3aghnz7fc9w-cacert-blocklist.txt.drv /nix/store/v6gnvpsqg2zy7lh9z4y7mrpi1fw5dgw4-cacert-extra-certificates-bundle.crt.drv /nix/store/2pm80dga301pgylh97w7105mrj0br1s3-nss-cacert-3.126.drv /nix/store/0c327af2fd5cnkww69224q282fhqif1m-nixos-version.drv /nix/store/7cnvsby4x32q8ln7gh7hjc9dgwkg9fll-system-path.drv /nix/store/yll0q6ljy9rfnnphbg1m0vnbpsmvm3q1-dbus-1.drv /nix/store/46ciwslw4lnhil7v9q4h1p1gppfrbj41-X-Restart-Triggers-dbus-broker.drv /nix/store/0nx9bnyx7j795swlzd32k0hd83nyvxj7-unit-dbus-broker.service.drv /nix/store/1nk8gzqdwcbys8cscgg83vgibcwy841s-unit-acme-renew-test.foo.timer.drv /nix/store/di1sgdiyzlm65p5kpam2px5qrwg223hx-acme-postrun.drv /nix/store/w7nqaqnlj2zf8lbzf5qy6i2yx8hrw8hs-unit-script-acme-order-renew-test.foo-start.drv /nix/store/35a5msij0380fgxm7ckwqrc2hd9rg2za-unit-acme-order-renew-test.foo.service.drv /nix/store/41akw2ffnkpsxh6ns0nvpbv9h8122q3m-unit-systemd-timedated.service.drv /nix/store/4c69mj6pj2q8zv6g1hr9w9hxjnm5skkk-unit-systemd-fsck-.service.drv /nix/store/3sa3xcmqapmjqbib7w953639g4pschv1-X-Restart-Triggers-systemd-networkd.drv /nix/store/xhhbkra230h3h37sfmjzrx9pry9wyrd0-unit-40-eth1.network.drv /nix/store/509xd8748dnlngc6nf21aggssb5s0swr-X-Reload-Triggers-systemd-networkd.drv /nix/store/5g0i3ihpykv6r1fx4mw25gs5fs6fgwhb-unit-systemd-networkd.service.drv /nix/store/bjj3534h4wyky0f37a7m2d7n964w54wh-acme-setup-privileged.drv /nix/store/gawjnj6ywdqsjb33sfpdn87jjwh4x030-unit-script-acme-setup-start.drv /nix/store/5h5ima3fyiinwyj2xb2bq3y2dba3lij3-unit-acme-setup.service.drv /nix/store/61vgapasj8nxhaqk3sk97194mj3hg0nj-unit-nginx-config-reload.service.drv /nix/store/6ldnq6arjyd9r09a9mbjyb1g5glhlycm-unit-console-getty.service.drv /nix/store/mkryfxz2pfh6gr8rhncv3clg33q5mgai-etc-systemd-journald.conf.drv /nix/store/fjma41d7rl9wp8jx7vnqish2fvp0l65y-X-Restart-Triggers-systemd-journald-.drv /nix/store/701afl0wgr66w3j89vhin5g2pdikc5sm-unit-systemd-journald-.service.drv /nix/store/5mg2klpahqbhhj18pc86bzcjzwryrqag-nixos-tmpfiles.d.drv /nix/store/rv9gkiwp80lshzgggldij33s91qcbhz3-10-acme.conf.drv /nix/store/kgrkxjg75x766c8hhwn7jxg7nn0l3j9m-tmpfiles.d.drv /nix/store/k9azhkcqcv57qjfkz6q9pmlp7w0mkq04-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/78w96nms9z36n2z4h2a49cd705aisvq8-unit-systemd-tmpfiles-resetup.service.drv /nix/store/p47hngn6zbdrmdwc5prb4iy0kaw2f2kp-firewall-start.drv /nix/store/1z3aifsiz4y9cs7rbjl3m6bx31jn97b2-firewall-reload.drv /nix/store/7yik6sfchavysp6hdgfdqy5f3px4n50d-unit-firewall.service.drv /nix/store/3qbzpkzqfykrppymh72m1ifiswms94iv-X-Restart-Triggers-acme-test.foo.drv /nix/store/b235wnldakyza7759nqsqcqnswaglih7-unit-script-acme-test.foo-start.drv /nix/store/9wqw1c35dyazfkqk1mb0asw40q50qr0b-unit-acme-test.foo.service.drv /nix/store/s1q4g3njblrv12v29als39vvg4f753rk-nginx.conf.drv /nix/store/w142xcnwysmrw2pjqis19jg1ikmia9jp-unit-script-nginx-pre-start.drv /nix/store/blvbi6ql6710rbyd771j2s09b3dfd1j8-unit-nginx.service.drv /nix/store/ck3idjnbv8mdwy53vxzvw4nks8qb4b7r-unit-serial-getty-ttyAMA0.service-disabled.drv /nix/store/zrlrzqqfagjz0jcz42yvi1cj0lw3mjmj-etc-systemd-resolved.conf.drv /nix/store/204dxl6q98aagw0i8wfjp7dag8l7c4kh-X-Reload-Triggers-systemd-resolved.drv /nix/store/cya14f0ilf8j8xqw8hr52g1k19qggbxj-unit-systemd-resolved.service.drv /nix/store/gsypd4p0iypxmf53bh23b9hyda2kdj15-etc-sysctl.d-60-nixos.conf.drv /nix/store/47flc519dahv34nbbw8kifxgdfvjcdwg-X-Restart-Triggers-systemd-sysctl.drv /nix/store/flkfj59gdkzn377j4vx8j3hz0yfyysy0-unit-systemd-sysctl.service.drv /nix/store/p4nwmvczbf1aramqjbp8g0c1gy66vi7d-shutdown-ramfs-contents.json.drv /nix/store/fx2936y2z43mv5k4anjsbrly8nh8xw93-unit-generate-shutdown-ramfs.service.drv /nix/store/a2bvbd17bachsijl4c82ykfhz4kl364q-nix.conf.drv /nix/store/b56kr6jp2kbmx38pp7zy4ccnmq77446n-X-Restart-Triggers-nix-daemon.drv /nix/store/j3ffiywirypq8p4g08jam9mqk5q8r5bw-unit-nix-daemon.service.drv /nix/store/j92r1clnb7bbnf8hdj2r8k7sfrk0drnd-unit-nix-optimise.service.drv /nix/store/lg4q0w5rxy73klw02s88fhzr904mmsfh-unit-serial-getty-.service.drv /nix/store/lmhxk40mj9hm6fqxssbrv692r9n6lqbk-unit-resolvconf.service-disabled.drv /nix/store/mwc5c1h7kc7s9yd2kpg9jpah3k92q0j8-unit-serial-getty-hvc0.service-disabled.drv /nix/store/nb6pmnhsmblmjl22yzlv69gpcz1ilb8k-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/nfsb6wnspim9z90liacbz5d5ivf3hvka-unit-suid-sgid-wrappers.service-disabled.drv /nix/store/grr6h5lhv5x38x5v4qr1mkls6a76rr8r-unit-script-nix-gc-start.drv /nix/store/nszfkjz4qq4qg3fgwp8c83mh9zi1wllq-unit-nix-gc.service.drv /nix/store/pghpah75x548w51shvbilx2by5khmw4d-unit-systemd-makefs-.service.drv /nix/store/mvd322wkjibcc0jzgssc54ggfkc1avvh-X-Restart-Triggers-systemd-journald.drv /nix/store/r84kbdywm1rz4cylkhmdg18h42fkrahi-unit-systemd-journald.service.drv /nix/store/3qd5ryggl8pfnikd88045i0hznn2dp3c-system-units.drv /nix/store/6w49gzpshs71lyvgsdjs7pjq6md86kla-issue.drv /nix/store/7f78x2fmrsc9klkk2bnfp2wycywk8rmn-etc-shells.drv /nix/store/89vwpz3bz4fz4damgb9ynfkw7whg8s7p-etc-ssh-ssh_config.drv /nix/store/g8q751dagdaxa2ljj43b6c9agzfq245j-fontconfig-etc.drv /nix/store/h2nswfhm1dlk7xk4z8k9c5ddgbr8a69x-etc-systemd-system.conf.drv /nix/store/xrhb93sk5vaxqsd5p0kpsy0npnhb66ix-set-environment.drv /nix/store/ixfd32bzms4lnna1mnfvdjg3fsk86x02-etc-profile.drv /nix/store/jwsj8l7jnx6i89xg8dqvsyqa1mrnyp6j-useradd.drv /nix/store/n3ppy744kf9khg1vvzv4qfgylgc32zws-etc-systemd-sleep.conf.drv /nix/store/ri012zg7hplgcrszi2sw51y9i5k5hjzn-etc-pam-environment.drv /nix/store/gnxzvcgqp1rar2dmfzcidlnsgjc00834-unit-dbus-broker.service.drv /nix/store/sc565ssdx5949bi7h3r8136nr23db5da-user-units.drv /nix/store/svx4s645mc3j5nfhi30d6sv6lgifv4ny-etc-fstab.drv /nix/store/avlwy5jy9zv3hhg6afzphr9drn1ry34q-extra-hosts.drv /nix/store/f1fz88a2dr2nxbc1qz3212629xhprw00-localhost-hosts.drv /nix/store/ngmx324ppgdy1kkqnbc6jjmj2qxp726f-string-hosts.drv /nix/store/vp9kqhkx48jvrr07a7j93914h0njf5jb-hosts.drv /nix/store/vq7y4hrging6m8zivlly08lzk1bdd6sd-etc-systemd-user.conf.drv /nix/store/y45g5n9jahbf13da7nnvn0isalxx9k1v-etc-lvm-lvm.conf.drv /nix/store/y68j8f7ylr7dqq735kv2q9yh6lgzshhz-etc-ssh-ssh_known_hosts.drv /nix/store/yj48gb9bf7a5xmra8d86r67yr0ziafkf-etc-nix-registry.json.drv /nix/store/z5767hi6a200q7kai4ag4a06c6d2lv91-etc-bashrc.drv /nix/store/3s1yapapgfca8fm5hvfa80gm10i4cnfj-etc.drv /nix/store/aablpnhbgk1rgyyikmjz9h0b21kkcpbb-ensure-all-wrappers-paths-exist.drv /nix/store/79wgv1358924zi13p4q1kdh7v81cm9ww-mounts.sh.drv /nix/store/khgs7ihg3g7vh72ix6dxh9ia91y4hjx3-mount-secret-fs.drv /nix/store/9k8c6rc9g9wyv9qw0019g4lbql8pr088-decrypt-age-secrets.drv /nix/store/yaq1v5mpwvwcmlxjmd2l8xdpbwz0wa70-hashed-password.root.drv /nix/store/znkkq5v4lfmsl9a3bjahlhlrw5d9vrxw-users-groups.json.drv /nix/store/p95mh1zv1paiwlfpp720b566cqx196w2-activate.drv /nix/store/rv3573hrr5mdx1flkrli0b7ywchdw8dc-stage-2-init.sh.drv /nix/store/ynfyapp5cancgb9wh78nfp5pzxpbjjxn-dry-activate.drv /nix/store/02v39zvc9mnyn9r6zyqz550gcg0rfx2x-nixos-system-server-test.drv /nix/store/036blsc4zrqllkxan7f78dh9gd9ch2zr-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/0sggpnpx0hb7ps7mipz1v6p0j50j74f9-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/0zdzqh8g7k3r2bwrjb5s1dj9xvfzj537-etc-hostname.drv /nix/store/nkmcxp3a6fc4ddajmj6v2glyjzq33blh-string-hosts.drv /nix/store/17212vlrjfmvkqaswkiz14msw9an4lhv-hosts.drv /nix/store/1qpr37x364y6lmlbrq9dy5idrbw2hp3w-decrypt-age-secrets.drv /nix/store/3v4bg9a3qamb0bm2ziqm6cc7bzf4issj-user-generators.drv /nix/store/3x9q456fy4k9p5j89dji9y9mpl6qpj0b-unit-40-eth1.network.drv /nix/store/4jmsfw3k4gmpf29v59xiy8lg5jj2g454-unit-40-eth1.network.drv /nix/store/6a9hs49cq4s7md9ny7pri0g713id1s6b-system-generators.drv /nix/store/6x8vlzfw6a1jwykqww188jzl2wgvirva-unit-nginx-config-reload.service.drv /nix/store/97m1jalfv4s1y5mvy3z6dj0xv0m1zvng-unit-acme-renew-ca.foo.timer.drv /nix/store/9f6p9w5xf1g9a8rmdvn87z28xqfbjsjr-X-Restart-Triggers-acme-ca.foo.drv /nix/store/j06h07j5hl1jqwhfrjy1bd3dm5y6ypr3-unit-script-acme-ca.foo-start.drv /nix/store/h7c9v4lnmls01zx9587yy0wvdr953bvn-unit-acme-ca.foo.service.drv /nix/store/qhjp8r9fvamgbhsi2vllmi94vh41kmhb-nginx-recommended-proxy_set_header-headers.conf.drv /nix/store/fhwhwps2pwd8p9i5hcr9xznmv6flqjay-nginx.conf.drv /nix/store/yvc88bz8v05gz09kvddiskr5ggp0frdh-unit-script-nginx-pre-start.drv /nix/store/lflg4r0ap2yf9jda4l448w3005m0h6y8-unit-nginx.service.drv /nix/store/msls07dxbgpvjl2kwx2mn55rxsds8h0p-system-path.drv /nix/store/sgrskgjgz27hz6l3ywf9nni9m6nns2js-dbus-1.drv /nix/store/a6333yi6qpkvlh16v27ii4x89h5g7fhl-X-Restart-Triggers-dbus-broker.drv /nix/store/m6xvyg09j9w4qg6qql39r5pc9hiyp4wv-unit-dbus-broker.service.drv /nix/store/y898rkhm36am6993pvcnnaa5laap4y5a-acme-postrun.drv /nix/store/p3bvivbjsggzi4ffpblddgslgf0f7qc2-unit-acme-order-renew-ca.foo.service.drv /nix/store/ppcmml1d42bis7nzxsyx769ahv8b25fb-acme-setup-privileged.drv /nix/store/rql21w9n48yizvh0qwz5z9cqwcan37m4-unit-acme-setup.service.drv /nix/store/y0x0lwllnwk37hwx9mll4ffa5ccinshy-ca.json.drv /nix/store/jxvqzdp8a2b4ws6zywim6ll9094y2s0a-X-Restart-Triggers-step-ca.drv /nix/store/xhd18nm006r6si4qrlpl548nc9v6ywrw-unit-step-ca.service.drv /nix/store/qby0arlghmjjb4r1vy6qw0pz9bmir7p5-X-Reload-Triggers-systemd-networkd.drv /nix/store/xxvrywgz666irh40lbw4m2jd7q1nxkdf-unit-systemd-networkd.service.drv /nix/store/9kx4mpyn06bd3cv6wk6ffwpfrv69782z-system-units.drv /nix/store/r8k75xgw7bjkw7mshn2w19kl52a9vmjc-unit-dbus-broker.service.drv /nix/store/hyz198np31gbamdizdi0qba1b6zvh6x7-user-units.drv /nix/store/i2dj4hz76ic7bsjdifxs6ck848im76kx-string-hosts.drv /nix/store/qbsv3xqikz30whfw55dx28jgb2pxkglf-hosts.drv /nix/store/w0a13fr2fv59hg246hmdlf3nhavsd0gg-system-shutdown.drv /nix/store/4wcxx6a03d5nbkld3ynbdj0f7l2div9j-etc.drv /nix/store/5pq2kh3b44ymqkr3f1gbfhaywadf1lrc-system-path.drv /nix/store/qmyis2dzw5mgw8xrk10l8p0yr3v98z34-users-groups.json.drv /nix/store/7cv835y8lfj1ahd75a2kl0gwg1igckv8-dry-activate.drv /nix/store/lsmdqplqyqqsad0jad6fiwpp6cn3y7az-X-Reload-Triggers-systemd-networkd.drv /nix/store/98fx6s8m7rp3sp8y3xrcr43pcn5hkbps-unit-systemd-networkd.service.drv /nix/store/a81mpbiqm92g20mwibkkmdz498mmmk65-run-server-nspawn.drv /nix/store/w66s8vv18l5y1f78fn2lj78zwq10zmqc-dbus-1.drv /nix/store/asb33lr6cjwwnz7zf9grxnvh64xyiqfr-X-Restart-Triggers-dbus-broker.drv /nix/store/gya49ya05hxgyjmw0q3zhv5jqgrqa1iy-nixos-tmpfiles.d.drv /nix/store/x0raav55fd1vcwk6jafn32j04kmk6yk6-tmpfiles.d.drv /nix/store/in0x3b8kic30gfz93gw9cxmxkmb5bvqr-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/hcchgqpbb1avbb1cxkrji253g152dwkn-unit-systemd-tmpfiles-resetup.service.drv /nix/store/s25zfsar9afmppnmhr5p97sa0gvfmn7f-firewall-start.drv /nix/store/mxm71xxx5yfvkwmwi771pmw6iz44nl4y-firewall-reload.drv /nix/store/n8af5xibzvhqggjmph1wbpwbmlc6nsnr-unit-firewall.service.drv /nix/store/pvk1lyf80mdav3shkaxfyzhfrka5zkfq-unit-dbus-broker.service.drv /nix/store/c4p7rv6a3pvs9y2amnki9ivfb1k1w3qh-system-units.drv /nix/store/iz06l0qnliwjxriy68zhlzz32y9ldpxf-etc-hostname.drv /nix/store/idgp8qkb88ni10wl7i2s8ayn3w2qdi90-unit-dbus-broker.service.drv /nix/store/xqh0da2c97vz8adfxd4r9nlh7z1jgj8c-user-units.drv /nix/store/b87vsafqnb5ypskdsby4wk7z5hs28185-etc.drv /nix/store/d3my8hip65hjhcx0myar3s96bf2k4sxx-python3.14-nixos-test-lib-1.0.0.drv /nix/store/laiy4wdfcimms3cl04fm3sn937fal9qp-users-groups.json.drv /nix/store/dbrr037mlzshr0lj6arfikaphlcd1m68-activate.drv /nix/store/q9mkm8m38d5p63m033dch4zvaai3qlkv-activate.drv /nix/store/hv1x3fqiz0h1wrlnchgsnq2h0dbnxfi3-nixos-system-ca-test.drv /nix/store/fbfrjc9zzhhjdjkfk1q08y81hvva4rsk-run-ca-nspawn.drv /nix/store/xlb36ixss5wsrxhlz65s5615fpa8vnsm-dry-activate.drv /nix/store/mn96zcacnq4ysljv4z2cla3sa53a97dn-nixos-system-client-test.drv /nix/store/g6hskmkb8ab9sl0f3qgdw0zx4m6s26sv-run-client-nspawn.drv /nix/store/qc93adsfvqp1ykah9sj9gzshblp1lcmb-test-script.drv /nix/store/f8hkca5alw5992qkb1dgxpr6gjadsb3q-driverConfiguration.json.drv /nix/store/kzmbyrp2y9hr0x04lx7qk6g8gnb4q1p8-nixos-test-driver-1.1.drv /nix/store/g6bvl5w8w2rgic175dlspzs95vlznpzz-nixos-test-driver-certificates.drv /nix/store/mpgpswv82gmxlgj772d9i5j3ifkz526f-container-test-run-certificates.drv these 16 paths will be fetched (45.5 MiB download, 150.3 MiB unpacked): /nix/store/3dasan0q8dfvh9k9w38h1h67d37y7h9l-flock-0.4.0 /nix/store/aakb43z0k7gywf8xqz7lw4ashd7xkv6b-gixy-0.1.21 /nix/store/m83jgn44gl01c0jc9n7a4zkmpdl821zp-lego-4.35.2 /nix/store/15s822ngb5ik60b2q50317iqz3shq46v-minica-1.1.0 /nix/store/wrwy4axlscwvcmbpb3yf536d3d00f2gy-nginx-1.30.4 /nix/store/i63i6lmhrzq0fwg8fxid2hnfavb8i3d2-nginx-config-formatter-1.4.0 /nix/store/w40l43ygihy9q79nmvq1nk26rd7qqv7n-nginx-mod-moreheaders-0.40 /nix/store/gyhchka2gri0p0360xiz89wqa15dkn7q-nginx-mod-rtmp-1.2.2 /nix/store/g00jzi34lq18jqfalq12s2psxr9ln9k6-openssl-3.6.3-man /nix/store/qln5hn3b0knfv7bapb9cx915mqyysfrf-openssl-4.0.2 /nix/store/rg795q2f38r1mmdfi3qbzv8si8iab1l7-python3.14-buildcatrust-0.5.1 /nix/store/09655jj6sbfrjyxa317qjczdm6ir577x-python3.14-cached-property-2.0.1 /nix/store/qzlwxl8a118rw7zal6s7c4xy9baga4hq-python3.14-configargparse-1.7.5 /nix/store/bmx919fsx8i1l6hak9nwbhvdwdili3rj-python3.14-pyparsing-2.4.7 /nix/store/3ahxigmadhbxwr2fx33x5qwwfs0aj1kb-step-ca-0.30.2 /nix/store/h9avm2x8xacpq4fp0skz2aiqkcz8l5ff-zlib-ng-2.3.3 building '/nix/store/qc93adsfvqp1ykah9sj9gzshblp1lcmb-test-script.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0zdzqh8g7k3r2bwrjb5s1dj9xvfzj537-etc-hostname.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/iz06l0qnliwjxriy68zhlzz32y9ldpxf-etc-hostname.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/s1q4g3njblrv12v29als39vvg4f753rk-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6a9hs49cq4s7md9ny7pri0g713id1s6b-system-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rv9gkiwp80lshzgggldij33s91qcbhz3-10-acme.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/9f6p9w5xf1g9a8rmdvn87z28xqfbjsjr-X-Restart-Triggers-acme-ca.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3qbzpkzqfykrppymh72m1ifiswms94iv-X-Restart-Triggers-acme-test.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qc93adsfvqp1ykah9sj9gzshblp1lcmb-test-script.drv' building '/nix/store/iz06l0qnliwjxriy68zhlzz32y9ldpxf-etc-hostname.drv' building '/nix/store/0zdzqh8g7k3r2bwrjb5s1dj9xvfzj537-etc-hostname.drv' building '/nix/store/s1q4g3njblrv12v29als39vvg4f753rk-nginx.conf.drv' nginx.conf> structuredAttrs is enabled building '/nix/store/di1sgdiyzlm65p5kpam2px5qrwg223hx-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y898rkhm36am6993pvcnnaa5laap4y5a-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/6a9hs49cq4s7md9ny7pri0g713id1s6b-system-generators.drv' building '/nix/store/rv9gkiwp80lshzgggldij33s91qcbhz3-10-acme.conf.drv' building '/nix/store/61vgapasj8nxhaqk3sk97194mj3hg0nj-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6x8vlzfw6a1jwykqww188jzl2wgvirva-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/j92r1clnb7bbnf8hdj2r8k7sfrk0drnd-unit-nix-optimise.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/lmhxk40mj9hm6fqxssbrv692r9n6lqbk-unit-resolvconf.service-disabled.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/j06h07j5hl1jqwhfrjy1bd3dm5y6ypr3-unit-script-acme-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/036blsc4zrqllkxan7f78dh9gd9ch2zr-unit-script-acme-order-renew-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/9f6p9w5xf1g9a8rmdvn87z28xqfbjsjr-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/3qbzpkzqfykrppymh72m1ifiswms94iv-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/bjj3534h4wyky0f37a7m2d7n964w54wh-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/di1sgdiyzlm65p5kpam2px5qrwg223hx-acme-postrun.drv' building '/nix/store/y898rkhm36am6993pvcnnaa5laap4y5a-acme-postrun.drv' building '/nix/store/j06h07j5hl1jqwhfrjy1bd3dm5y6ypr3-unit-script-acme-ca.foo-start.drv' building '/nix/store/61vgapasj8nxhaqk3sk97194mj3hg0nj-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/lmhxk40mj9hm6fqxssbrv692r9n6lqbk-unit-resolvconf.service-disabled.drv' building '/nix/store/h7c9v4lnmls01zx9587yy0wvdr953bvn-unit-acme-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6x8vlzfw6a1jwykqww188jzl2wgvirva-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/j92r1clnb7bbnf8hdj2r8k7sfrk0drnd-unit-nix-optimise.service.drv' unit-nix-optimise.service> structuredAttrs is enabled building '/nix/store/036blsc4zrqllkxan7f78dh9gd9ch2zr-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/p3bvivbjsggzi4ffpblddgslgf0f7qc2-unit-acme-order-renew-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ppcmml1d42bis7nzxsyx769ahv8b25fb-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y0x0lwllnwk37hwx9mll4ffa5ccinshy-ca.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/avlwy5jy9zv3hhg6afzphr9drn1ry34q-extra-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p47hngn6zbdrmdwc5prb4iy0kaw2f2kp-firewall-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qhjp8r9fvamgbhsi2vllmi94vh41kmhb-nginx-recommended-proxy_set_header-headers.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5mg2klpahqbhhj18pc86bzcjzwryrqag-nixos-tmpfiles.d.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/2pm80dga301pgylh97w7105mrj0br1s3-nss-cacert-3.126.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/bjj3534h4wyky0f37a7m2d7n964w54wh-acme-setup-privileged.drv' building '/nix/store/1qpr37x364y6lmlbrq9dy5idrbw2hp3w-decrypt-age-secrets.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/i2dj4hz76ic7bsjdifxs6ck848im76kx-string-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5pq2kh3b44ymqkr3f1gbfhaywadf1lrc-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7cnvsby4x32q8ln7gh7hjc9dgwkg9fll-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/msls07dxbgpvjl2kwx2mn55rxsds8h0p-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/w0a13fr2fv59hg246hmdlf3nhavsd0gg-system-shutdown.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/h7c9v4lnmls01zx9587yy0wvdr953bvn-unit-acme-ca.foo.service.drv' unit-acme-ca.foo.service> structuredAttrs is enabled building '/nix/store/ppcmml1d42bis7nzxsyx769ahv8b25fb-acme-setup-privileged.drv' building '/nix/store/p3bvivbjsggzi4ffpblddgslgf0f7qc2-unit-acme-order-renew-ca.foo.service.drv' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled building '/nix/store/y0x0lwllnwk37hwx9mll4ffa5ccinshy-ca.json.drv' ca.json> structuredAttrs is enabled building '/nix/store/avlwy5jy9zv3hhg6afzphr9drn1ry34q-extra-hosts.drv' building '/nix/store/qhjp8r9fvamgbhsi2vllmi94vh41kmhb-nginx-recommended-proxy_set_header-headers.conf.drv' building '/nix/store/5mg2klpahqbhhj18pc86bzcjzwryrqag-nixos-tmpfiles.d.drv' building '/nix/store/jxvqzdp8a2b4ws6zywim6ll9094y2s0a-X-Restart-Triggers-step-ca.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/17212vlrjfmvkqaswkiz14msw9an4lhv-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vp9kqhkx48jvrr07a7j93914h0njf5jb-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/fhwhwps2pwd8p9i5hcr9xznmv6flqjay-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p47hngn6zbdrmdwc5prb4iy0kaw2f2kp-firewall-start.drv' building '/nix/store/xhhbkra230h3h37sfmjzrx9pry9wyrd0-unit-40-eth1.network.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/nb6pmnhsmblmjl22yzlv69gpcz1ilb8k-unit-acme-account-2c44cb477b4787b2cf13.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0sggpnpx0hb7ps7mipz1v6p0j50j74f9-unit-acme-account-d22a46d9459bf683a338.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/2pm80dga301pgylh97w7105mrj0br1s3-nss-cacert-3.126.drv' nss-cacert-3.126> structuredAttrs is enabled nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/g01kyvp9mhhmqbgvzmvfmb80ibva3lky-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/g01kyvp9mhhmqbgvzmvfmb80ibva3lky-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/g01kyvp9mhhmqbgvzmvfmb80ibva3lky-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/gddncja5kjdmqy5izqixzlyp6cc96kvl-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/gddncja5kjdmqy5izqixzlyp6cc96kvl-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/gddncja5kjdmqy5izqixzlyp6cc96kvl-nss-cacert-3.126-hashed nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/gfi4p1xaw9z0x86dn73bmcb4556zhbkb-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/gfi4p1xaw9z0x86dn73bmcb4556zhbkb-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/gfi4p1xaw9z0x86dn73bmcb4556zhbkb-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/wjh8wdc9gdzlgrv6m77qilrj0y6li0fg-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/wjh8wdc9gdzlgrv6m77qilrj0y6li0fg-nss-cacert-3.126-unbundled... warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy nss-cacert-3.126> patching script interpreter paths in /nix/store/wjh8wdc9gdzlgrv6m77qilrj0y6li0fg-nss-cacert-3.126-unbundled building '/nix/store/i2dj4hz76ic7bsjdifxs6ck848im76kx-string-hosts.drv' building '/nix/store/7cnvsby4x32q8ln7gh7hjc9dgwkg9fll-system-path.drv' system-path> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy system-path> created 1718 symlinks in user environment building '/nix/store/5pq2kh3b44ymqkr3f1gbfhaywadf1lrc-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/1qpr37x364y6lmlbrq9dy5idrbw2hp3w-decrypt-age-secrets.drv' building '/nix/store/j3ffiywirypq8p4g08jam9mqk5q8r5bw-unit-nix-daemon.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/qbsv3xqikz30whfw55dx28jgb2pxkglf-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/msls07dxbgpvjl2kwx2mn55rxsds8h0p-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/w66s8vv18l5y1f78fn2lj78zwq10zmqc-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/w0a13fr2fv59hg246hmdlf3nhavsd0gg-system-shutdown.drv' building '/nix/store/1z3aifsiz4y9cs7rbjl3m6bx31jn97b2-firewall-reload.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kgrkxjg75x766c8hhwn7jxg7nn0l3j9m-tmpfiles.d.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/97m1jalfv4s1y5mvy3z6dj0xv0m1zvng-unit-acme-renew-ca.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/sgrskgjgz27hz6l3ywf9nni9m6nns2js-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/17212vlrjfmvkqaswkiz14msw9an4lhv-hosts.drv' building '/nix/store/jxvqzdp8a2b4ws6zywim6ll9094y2s0a-X-Restart-Triggers-step-ca.drv' building '/nix/store/xhhbkra230h3h37sfmjzrx9pry9wyrd0-unit-40-eth1.network.drv' unit-40-eth1.network> structuredAttrs is enabled building '/nix/store/xhd18nm006r6si4qrlpl548nc9v6ywrw-unit-step-ca.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vp9kqhkx48jvrr07a7j93914h0njf5jb-hosts.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/0sggpnpx0hb7ps7mipz1v6p0j50j74f9-unit-acme-account-d22a46d9459bf683a338.target.drv' unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled building '/nix/store/j3ffiywirypq8p4g08jam9mqk5q8r5bw-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled building '/nix/store/fhwhwps2pwd8p9i5hcr9xznmv6flqjay-nginx.conf.drv' nginx.conf> structuredAttrs is enabled nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/nb6pmnhsmblmjl22yzlv69gpcz1ilb8k-unit-acme-account-2c44cb477b4787b2cf13.target.drv' unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled building '/nix/store/yvc88bz8v05gz09kvddiskr5ggp0frdh-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qbsv3xqikz30whfw55dx28jgb2pxkglf-hosts.drv' building '/nix/store/w66s8vv18l5y1f78fn2lj78zwq10zmqc-dbus-1.drv' building '/nix/store/asb33lr6cjwwnz7zf9grxnvh64xyiqfr-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/1z3aifsiz4y9cs7rbjl3m6bx31jn97b2-firewall-reload.drv' building '/nix/store/7yik6sfchavysp6hdgfdqy5f3px4n50d-unit-firewall.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/97m1jalfv4s1y5mvy3z6dj0xv0m1zvng-unit-acme-renew-ca.foo.timer.drv' unit-acme-renew-ca.foo.timer> structuredAttrs is enabled building '/nix/store/kgrkxjg75x766c8hhwn7jxg7nn0l3j9m-tmpfiles.d.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/k9azhkcqcv57qjfkz6q9pmlp7w0mkq04-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/xhd18nm006r6si4qrlpl548nc9v6ywrw-unit-step-ca.service.drv' unit-step-ca.service> structuredAttrs is enabled building '/nix/store/sgrskgjgz27hz6l3ywf9nni9m6nns2js-dbus-1.drv' building '/nix/store/a6333yi6qpkvlh16v27ii4x89h5g7fhl-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/yvc88bz8v05gz09kvddiskr5ggp0frdh-unit-script-nginx-pre-start.drv' building '/nix/store/lflg4r0ap2yf9jda4l448w3005m0h6y8-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/509xd8748dnlngc6nf21aggssb5s0swr-X-Reload-Triggers-systemd-networkd.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/yll0q6ljy9rfnnphbg1m0vnbpsmvm3q1-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/k9azhkcqcv57qjfkz6q9pmlp7w0mkq04-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' building '/nix/store/7yik6sfchavysp6hdgfdqy5f3px4n50d-unit-firewall.service.drv' unit-firewall.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/78w96nms9z36n2z4h2a49cd705aisvq8-unit-systemd-tmpfiles-resetup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/asb33lr6cjwwnz7zf9grxnvh64xyiqfr-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/a6333yi6qpkvlh16v27ii4x89h5g7fhl-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/idgp8qkb88ni10wl7i2s8ayn3w2qdi90-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/pvk1lyf80mdav3shkaxfyzhfrka5zkfq-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/m6xvyg09j9w4qg6qql39r5pc9hiyp4wv-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/r8k75xgw7bjkw7mshn2w19kl52a9vmjc-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/lflg4r0ap2yf9jda4l448w3005m0h6y8-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/1nk8gzqdwcbys8cscgg83vgibcwy841s-unit-acme-renew-test.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/w7nqaqnlj2zf8lbzf5qy6i2yx8hrw8hs-unit-script-acme-order-renew-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/gawjnj6ywdqsjb33sfpdn87jjwh4x030-unit-script-acme-setup-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/509xd8748dnlngc6nf21aggssb5s0swr-X-Reload-Triggers-systemd-networkd.drv' building '/nix/store/yll0q6ljy9rfnnphbg1m0vnbpsmvm3q1-dbus-1.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/pvk1lyf80mdav3shkaxfyzhfrka5zkfq-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/m6xvyg09j9w4qg6qql39r5pc9hiyp4wv-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/c4p7rv6a3pvs9y2amnki9ivfb1k1w3qh-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/idgp8qkb88ni10wl7i2s8ayn3w2qdi90-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/5g0i3ihpykv6r1fx4mw25gs5fs6fgwhb-unit-systemd-networkd.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/46ciwslw4lnhil7v9q4h1p1gppfrbj41-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/b235wnldakyza7759nqsqcqnswaglih7-unit-script-acme-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/w142xcnwysmrw2pjqis19jg1ikmia9jp-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3v4bg9a3qamb0bm2ziqm6cc7bzf4issj-user-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qmyis2dzw5mgw8xrk10l8p0yr3v98z34-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/78w96nms9z36n2z4h2a49cd705aisvq8-unit-systemd-tmpfiles-resetup.service.drv' unit-systemd-tmpfiles-resetup.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/r8k75xgw7bjkw7mshn2w19kl52a9vmjc-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/1nk8gzqdwcbys8cscgg83vgibcwy841s-unit-acme-renew-test.foo.timer.drv' unit-acme-renew-test.foo.timer> structuredAttrs is enabled building '/nix/store/hyz198np31gbamdizdi0qba1b6zvh6x7-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/gawjnj6ywdqsjb33sfpdn87jjwh4x030-unit-script-acme-setup-start.drv' building '/nix/store/w7nqaqnlj2zf8lbzf5qy6i2yx8hrw8hs-unit-script-acme-order-renew-test.foo-start.drv' building '/nix/store/5h5ima3fyiinwyj2xb2bq3y2dba3lij3-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rql21w9n48yizvh0qwz5z9cqwcan37m4-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/w142xcnwysmrw2pjqis19jg1ikmia9jp-unit-script-nginx-pre-start.drv' building '/nix/store/46ciwslw4lnhil7v9q4h1p1gppfrbj41-X-Restart-Triggers-dbus-broker.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/blvbi6ql6710rbyd771j2s09b3dfd1j8-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0nx9bnyx7j795swlzd32k0hd83nyvxj7-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/gnxzvcgqp1rar2dmfzcidlnsgjc00834-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/xqh0da2c97vz8adfxd4r9nlh7z1jgj8c-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/znkkq5v4lfmsl9a3bjahlhlrw5d9vrxw-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/07182vp9nm48fkgibfn911dbhlvs6isg-vars-check-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/35a5msij0380fgxm7ckwqrc2hd9rg2za-unit-acme-order-renew-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/b235wnldakyza7759nqsqcqnswaglih7-unit-script-acme-test.foo-start.drv' building '/nix/store/9wqw1c35dyazfkqk1mb0asw40q50qr0b-unit-acme-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5g0i3ihpykv6r1fx4mw25gs5fs6fgwhb-unit-systemd-networkd.service.drv' unit-systemd-networkd.service> structuredAttrs is enabled building '/nix/store/c4p7rv6a3pvs9y2amnki9ivfb1k1w3qh-system-units.drv' building '/nix/store/qmyis2dzw5mgw8xrk10l8p0yr3v98z34-users-groups.json.drv' building '/nix/store/3v4bg9a3qamb0bm2ziqm6cc7bzf4issj-user-generators.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/7cv835y8lfj1ahd75a2kl0gwg1igckv8-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hyz198np31gbamdizdi0qba1b6zvh6x7-user-units.drv' building '/nix/store/rql21w9n48yizvh0qwz5z9cqwcan37m4-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/blvbi6ql6710rbyd771j2s09b3dfd1j8-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/5h5ima3fyiinwyj2xb2bq3y2dba3lij3-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/0nx9bnyx7j795swlzd32k0hd83nyvxj7-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/xqh0da2c97vz8adfxd4r9nlh7z1jgj8c-user-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/znkkq5v4lfmsl9a3bjahlhlrw5d9vrxw-users-groups.json.drv' building '/nix/store/07182vp9nm48fkgibfn911dbhlvs6isg-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/9wqw1c35dyazfkqk1mb0asw40q50qr0b-unit-acme-test.foo.service.drv' unit-acme-test.foo.service> structuredAttrs is enabled building '/nix/store/gnxzvcgqp1rar2dmfzcidlnsgjc00834-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/35a5msij0380fgxm7ckwqrc2hd9rg2za-unit-acme-order-renew-test.foo.service.drv' unit-acme-order-renew-test.foo.service> structuredAttrs is enabled building '/nix/store/b87vsafqnb5ypskdsby4wk7z5hs28185-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ynfyapp5cancgb9wh78nfp5pzxpbjjxn-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/9kx4mpyn06bd3cv6wk6ffwpfrv69782z-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/7cv835y8lfj1ahd75a2kl0gwg1igckv8-dry-activate.drv' building '/nix/store/3qd5ryggl8pfnikd88045i0hznn2dp3c-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/sc565ssdx5949bi7h3r8136nr23db5da-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ynfyapp5cancgb9wh78nfp5pzxpbjjxn-dry-activate.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/sc565ssdx5949bi7h3r8136nr23db5da-user-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/9kx4mpyn06bd3cv6wk6ffwpfrv69782z-system-units.drv' building '/nix/store/3qd5ryggl8pfnikd88045i0hznn2dp3c-system-units.drv' building '/nix/store/b87vsafqnb5ypskdsby4wk7z5hs28185-etc.drv' building '/nix/store/4wcxx6a03d5nbkld3ynbdj0f7l2div9j-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3s1yapapgfca8fm5hvfa80gm10i4cnfj-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dbrr037mlzshr0lj6arfikaphlcd1m68-activate.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/3s1yapapgfca8fm5hvfa80gm10i4cnfj-etc.drv' building '/nix/store/dbrr037mlzshr0lj6arfikaphlcd1m68-activate.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/4wcxx6a03d5nbkld3ynbdj0f7l2div9j-etc.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/mn96zcacnq4ysljv4z2cla3sa53a97dn-nixos-system-client-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/q9mkm8m38d5p63m033dch4zvaai3qlkv-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p95mh1zv1paiwlfpp720b566cqx196w2-activate.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/mn96zcacnq4ysljv4z2cla3sa53a97dn-nixos-system-client-test.drv' nixos-system-client-test> structuredAttrs is enabled building '/nix/store/q9mkm8m38d5p63m033dch4zvaai3qlkv-activate.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/g6hskmkb8ab9sl0f3qgdw0zx4m6s26sv-run-client-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/hv1x3fqiz0h1wrlnchgsnq2h0dbnxfi3-nixos-system-ca-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/g6hskmkb8ab9sl0f3qgdw0zx4m6s26sv-run-client-nspawn.drv' building '/nix/store/p95mh1zv1paiwlfpp720b566cqx196w2-activate.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/02v39zvc9mnyn9r6zyqz550gcg0rfx2x-nixos-system-server-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hv1x3fqiz0h1wrlnchgsnq2h0dbnxfi3-nixos-system-ca-test.drv' nixos-system-ca-test> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/02v39zvc9mnyn9r6zyqz550gcg0rfx2x-nixos-system-server-test.drv' nixos-system-server-test> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/fbfrjc9zzhhjdjkfk1q08y81hvva4rsk-run-ca-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/a81mpbiqm92g20mwibkkmdz498mmmk65-run-server-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/a81mpbiqm92g20mwibkkmdz498mmmk65-run-server-nspawn.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/fbfrjc9zzhhjdjkfk1q08y81hvva4rsk-run-ca-nspawn.drv' building '/nix/store/f8hkca5alw5992qkb1dgxpr6gjadsb3q-driverConfiguration.json.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/f8hkca5alw5992qkb1dgxpr6gjadsb3q-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/g6bvl5w8w2rgic175dlspzs95vlznpzz-nixos-test-driver-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/g6bvl5w8w2rgic175dlspzs95vlznpzz-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/mpgpswv82gmxlgj772d9i5j3ifkz526f-container-test-run-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/mpgpswv82gmxlgj772d9i5j3ifkz526f-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> client: systemd-nspawn running (pid 53) container-test-run-certificates> ca: systemd-nspawn running (pid 54) container-test-run-certificates> server: systemd-nspawn running (pid 55) container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> client # [94522.519837] client systemd-journald[69]: Journal started container-test-run-certificates> client # [94522.519894] client systemd-journald[69]: Runtime Journal (/run/log/journal/30d9af31efb74cc696e87c47a69a0254) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> client # [94522.523518] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [94522.532609] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [94522.533413] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [94522.534079] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [94522.542593] client systemd-journald[69]: Time spent on flushing to /var/log/journal/30d9af31efb74cc696e87c47a69a0254 is 2.004ms for 6 entries. container-test-run-certificates> client # [94522.542593] client systemd-journald[69]: System Journal (/var/log/journal/30d9af31efb74cc696e87c47a69a0254) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [94522.547109] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [94522.547336] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [94522.547425] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [94522.548177] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [94522.548225] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [94522.549024] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [94522.549066] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [94522.570418] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [94522.571369] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [94522.588409] client systemd-tmpfiles[120]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [94522.588619] client systemd-tmpfiles[120]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [94522.588775] client systemd-tmpfiles[120]: fchmod() of /var/log/journal/30d9af31efb74cc696e87c47a69a0254 failed: Operation not permitted container-test-run-certificates> client # [94522.589011] client systemd-tmpfiles[120]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [94522.590326] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [94522.592929] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [94522.593798] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> client # [94522.596141] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [94522.606516] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [94522.504269] server systemd-journald[69]: Journal started container-test-run-certificates> server # [94522.504321] server systemd-journald[69]: Runtime Journal (/run/log/journal/40defbdee95c4eb4a101a9d81ba86b1a) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> server # [94522.508281] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> server # [94522.516812] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> server # [94522.517688] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> server # [94522.518717] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> server # [94522.526798] server systemd-journald[69]: Time spent on flushing to /var/log/journal/40defbdee95c4eb4a101a9d81ba86b1a is 1.657ms for 6 entries. container-test-run-certificates> server # [94522.526798] server systemd-journald[69]: System Journal (/var/log/journal/40defbdee95c4eb4a101a9d81ba86b1a) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [94522.539300] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [94522.539445] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [94522.539531] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [94522.540309] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [94522.540352] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [94522.541183] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [94522.541219] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [94522.569381] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [94522.571762] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [94522.594287] server systemd-tmpfiles[125]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [94522.594608] server systemd-tmpfiles[125]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [94522.594792] server systemd-tmpfiles[125]: fchmod() of /var/log/journal/40defbdee95c4eb4a101a9d81ba86b1a failed: Operation not permitted container-test-run-certificates> server # [94522.594819] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [94522.595027] server systemd-tmpfiles[125]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [94522.596631] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [94522.597739] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [94522.598482] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [94522.610226] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [94522.504453] ca systemd-journald[78]: Journal started container-test-run-certificates> ca # [94522.504503] ca systemd-journald[78]: Runtime Journal (/run/log/journal/b2f1164fd02c424f86cff80b8c52e3b2) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> ca # [94522.508320] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [94522.516799] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [94522.517691] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [94522.520259] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [94522.526358] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/b2f1164fd02c424f86cff80b8c52e3b2 is 2.213ms for 6 entries. container-test-run-certificates> ca # [94522.526358] ca systemd-journald[78]: System Journal (/var/log/journal/b2f1164fd02c424f86cff80b8c52e3b2) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [94522.539275] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [94522.539979] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [94522.540136] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [94522.540986] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [94522.541033] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [94522.541885] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [94522.541922] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [94522.569491] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [94522.571353] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [94522.586440] ca systemd-tmpfiles[135]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [94522.586628] ca systemd-tmpfiles[135]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [94522.586749] ca systemd-tmpfiles[135]: fchmod() of /var/log/journal/b2f1164fd02c424f86cff80b8c52e3b2 failed: Operation not permitted container-test-run-certificates> ca # [94522.586931] ca systemd-tmpfiles[135]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [94522.588773] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [94522.589916] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [94522.590664] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [94522.596779] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [94522.602493] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [94522.609567] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [94522.611158] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [94522.621303] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [94522.669914] ca systemd[1]: Finished Firewall. container-test-run-certificates> ca # [94522.670082] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [94522.670292] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [94522.671316] ca systemd[1]: Starting Network Management... container-test-run-certificates> server # [94522.620513] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [94522.621539] server systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [94522.631345] server systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [94522.666801] server systemd[1]: Finished Firewall. container-test-run-certificates> server # [94522.666961] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [94522.667196] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [94522.668336] server systemd[1]: Starting Network Management... container-test-run-certificates> client # [94522.616950] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [94522.617972] client systemd[1]: Starting Update is Completed... container-test-run-certificates> client # [94522.627551] client systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [94522.665144] client systemd[1]: Finished Firewall. container-test-run-certificates> client # [94522.665309] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [94522.665529] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [94522.666561] client systemd[1]: Starting Network Management... container-test-run-certificates> ca # [94523.056835] ca systemd-networkd[196]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [94523.056922] ca systemd-networkd[196]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [94523.063681] ca systemd-networkd[196]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [94523.063849] ca systemd-networkd[196]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [94523.063997] ca systemd-networkd[196]: lo: Link UP container-test-run-certificates> ca # [94523.064010] ca systemd-networkd[196]: lo: Gained carrier container-test-run-certificates> ca # [94523.064203] ca systemd-networkd[196]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [94523.064565] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [94523.100277] ca systemd-networkd[196]: eth1: Link UP container-test-run-certificates> ca # [94523.100699] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [94523.100890] ca systemd-networkd[196]: eth1: Gained carrier container-test-run-certificates> ca # [94523.150864] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [94523.186122] ca systemd-resolved[101]: Positive Trust Anchors: container-test-run-certificates> ca # [94523.186134] ca systemd-resolved[101]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [94523.186137] ca systemd-resolved[101]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [94523.186173] ca systemd-resolved[101]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [94523.208818] ca systemd-resolved[101]: Using system hostname 'ca'. container-test-run-certificates> ca # [94523.210278] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [94523.210413] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [94523.210541] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [94523.210633] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [94523.211047] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [94523.211125] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [94523.211171] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [94523.211212] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [94523.211453] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [94523.211655] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [94523.211878] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [94523.211931] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [94523.212034] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [94523.244806] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [94523.246484] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [94523.246570] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [94523.248231] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [94523.249686] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [94523.251305] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [94523.268969] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [94523.049809] client systemd-networkd[183]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [94523.058570] server systemd-networkd[187]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [94523.049901] client systemd-networkd[183]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [94523.058658] server systemd-networkd[187]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [94523.056708] client systemd-networkd[183]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [94523.065486] server systemd-networkd[187]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [94523.056875] client systemd-networkd[183]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [94523.065653] server systemd-networkd[187]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [94523.057033] client systemd-networkd[183]: lo: Link UP container-test-run-certificates> server # [94523.065801] server systemd-networkd[187]: lo: Link UP container-test-run-certificates> client # [94523.057038] client systemd-networkd[183]: lo: Gained carrier container-test-run-certificates> server # [94523.065805] server systemd-networkd[187]: lo: Gained carrier container-test-run-certificates> client # [94523.057229] client systemd-networkd[183]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [94523.065983] server systemd-networkd[187]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [94523.057603] client systemd[1]: Started Network Management. container-test-run-certificates> server # [94523.066388] server systemd[1]: Started Network Management. container-test-run-certificates> client # [94523.057691] client systemd-networkd[183]: eth1: Link UP container-test-run-certificates> server # [94523.100462] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [94523.058025] client systemd-networkd[183]: eth1: Gained carrier container-test-run-certificates> server # [94523.100531] server systemd-networkd[187]: eth1: Link UP container-test-run-certificates> client # [94523.059072] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [94523.100937] server systemd-networkd[187]: eth1: Gained carrier container-test-run-certificates> client # [94523.110548] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [94523.134076] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [94523.180809] client systemd-resolved[95]: Positive Trust Anchors: container-test-run-certificates> server # [94523.176706] server systemd-resolved[91]: Positive Trust Anchors: container-test-run-certificates> server # [94523.176717] server systemd-resolved[91]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [94523.180820] client systemd-resolved[95]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [94523.176721] server systemd-resolved[91]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [94523.180825] client systemd-resolved[95]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [94523.176757] server systemd-resolved[91]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [94523.180859] client systemd-resolved[95]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [94523.199547] server systemd-resolved[91]: Using system hostname 'server'. container-test-run-certificates> client # [94523.203641] client systemd-resolved[95]: Using system hostname 'client'. container-test-run-certificates> server # [94523.200946] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [94523.205042] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [94523.201045] server systemd[1]: Reached target Network. container-test-run-certificates> client # [94523.205133] client systemd[1]: Reached target Network. container-test-run-certificates> server # [94523.201118] server systemd[1]: Reached target Network is Online. container-test-run-certificates> client # [94523.205215] client systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [94523.201171] server systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [94523.205279] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [94523.201424] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> client # [94523.205316] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [94523.201459] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [94523.205340] client systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [94523.201486] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [94523.205495] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [94523.201513] server systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [94523.205638] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [94523.201656] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [94523.205779] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [94523.201781] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [94523.205816] client systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [94523.201909] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [94523.205867] client systemd[1]: Reached target Basic System. container-test-run-certificates> server # [94523.201937] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [94523.201979] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [94523.203568] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [94523.204513] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [94523.204558] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [94523.205598] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [94523.207089] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [94523.262160] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [94523.207191] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [94523.208331] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [94523.244420] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [94523.263479] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [94523.430232] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> server # [94523.430232] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [94523.430578] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> server # [94523.431802] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> server # [94523.433688] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [94523.433726] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> server # [94523.433726] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [94523.433726] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> server # [94523.454978] server nsncd[194]: Sep 05 09:42:23.440 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [94523.455333] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [94523.455452] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [94523.455580] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [94523.497667] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [94523.499242] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [94523.520583] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [94523.523089] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [94523.526074] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [94523.526124] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [94523.526144] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [94523.634712] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [94523.635506] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [94523.635506] server dbus-broker-launch[195]: Invalid user-name in /nix/store/xamxpwkpq9pj51cyi13j1rn4cfjsvpj5-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [94523.635937] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [94523.643439] server dbus-broker-launch[195]: Ready container-test-run-certificates> ca # [94523.450699] ca acme-setup-privileged[201]: + set -euo pipefail container-test-run-certificates> ca # [94523.450699] ca acme-setup-privileged[201]: + cd /var/lib/acme container-test-run-certificates> ca # [94523.450699] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [94523.452655] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [94523.454402] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [94523.454478] ca acme-setup-privileged[201]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [94523.454478] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [94523.454478] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [94523.475008] ca nsncd[203]: Sep 05 09:42:23.460 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [94523.507226] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [94523.508260] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [94523.508814] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [94523.508904] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [94523.510237] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [94523.511084] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [94523.523833] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [94523.525824] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [94523.525899] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [94523.525942] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [94523.634917] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [94523.635953] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [94523.635953] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/kb2b8z8qy8fbf7i5cavy9vvn05jlnfay-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [94523.636391] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [94523.643453] ca dbus-broker-launch[205]: Ready container-test-run-certificates> client # [94523.505775] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> client # [94523.523672] client nsncd[189]: Sep 05 09:42:23.509 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [94523.523849] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [94523.523910] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [94523.523967] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [94523.525386] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [94523.526169] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [94523.537683] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [94523.538952] client systemd[1]: Started Console Getty. container-test-run-certificates> client # [94523.538998] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [94523.539018] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [94523.613883] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [94523.614749] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [94523.614749] client dbus-broker-launch[190]: Invalid user-name in /nix/store/hcmnwjy5lp6bjqw8pvq2l5h1hh90qrh4-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [94523.615204] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [94523.622737] client dbus-broker-launch[190]: Ready container-test-run-certificates> server # [94524.191790] server systemd-logind[221]: New seat seat0. container-test-run-certificates> server # [94524.191919] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [94524.193101] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [94524.206256] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [94524.206342] server systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [94524.286254] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> server # [94524.286254] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> server # [94524.286670] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [94524.306031] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [94524.307804] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> client # [94524.189224] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [94524.189448] client systemd[1]: Started User Login Management. container-test-run-certificates> client # [94524.190864] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [94524.205947] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [94524.206146] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [94524.206569] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [94524.206807] client systemd[1]: Startup finished in 2.123s. container-test-run-certificates> ca # [94524.212241] ca systemd-logind[230]: New seat seat0. container-test-run-certificates> ca # [94524.212497] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [94524.214125] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [94524.226215] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [94524.226421] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [94524.283784] ca acme-setup-start[219]: + set -euo pipefail container-test-run-certificates> ca # [94524.283784] ca acme-setup-start[219]: + test -e ca/key.pem container-test-run-certificates> ca # [94524.284244] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [94524.307304] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [94524.309103] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> ca # [94524.411044] ca step-ca[204]: badger 2026/09/05 09:42:24 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [94524.414878] ca step-ca[204]: 2026/09/05 09:42:24 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [94524.421151] ca step-ca[204]: 2026/09/05 09:42:24 Starting Smallstep CA/0.30.2 (linux/arm64) container-test-run-certificates> ca # [94524.421151] ca step-ca[204]: 2026/09/05 09:42:24 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [94524.421151] ca step-ca[204]: 2026/09/05 09:42:24 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [94524.421151] ca step-ca[204]: 2026/09/05 09:42:24 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [94524.421250] ca step-ca[204]: 2026/09/05 09:42:24 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [94524.421250] ca step-ca[204]: 2026/09/05 09:42:24 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [94524.421250] ca step-ca[204]: 2026/09/05 09:42:24 X.509 Root Fingerprint: 07e8995268151c19fdd7d1dde4cbd6192e296c668641ad8c500bca3c5fe4f667 container-test-run-certificates> ca # [94524.421817] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [94524.422132] ca step-ca[204]: 2026/09/05 09:42:24 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> server # [94524.484200] server systemd-networkd[187]: eth1: Gained IPv6LL container-test-run-certificates> ca # [94524.900132] ca systemd-networkd[196]: eth1: Gained IPv6LL container-test-run-certificates> ca # [94524.933606] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [94524.936702] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [94524.936787] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [94524.951927] ca acme-ca.foo-start[294]: + cd ca.foo container-test-run-certificates> ca # [94524.952275] ca acme-ca.foo-start[294]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [94524.953381] ca acme-ca.foo-start[295]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [94524.953582] ca acme-ca.foo-start[294]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [94524.955028] ca acme-ca.foo-start[294]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [94524.955279] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [94524.957519] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [94524.959212] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [94524.960708] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [94524.960747] ca acme-ca.foo-start[256]: + '[' -d out ']' container-test-run-certificates> ca # [94524.960747] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [94524.962313] ca acme-ca.foo-start[256]: + chown -R acme:nginx out container-test-run-certificates> ca # [94524.965547] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [94524.965590] ca acme-ca.foo-start[256]: + '[' -d certificates ']' container-test-run-certificates> ca # [94525.012593] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [94525.014530] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> server # [94524.911881] server acme-test.foo-start[244]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [94524.915070] server acme-test.foo-start[244]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [94524.915137] server acme-test.foo-start[244]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [94524.929563] server acme-test.foo-start[254]: + cd test.foo container-test-run-certificates> server # [94524.929902] server acme-test.foo-start[254]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [94524.931366] server acme-test.foo-start[255]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [94524.931663] server acme-test.foo-start[254]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [94524.933087] server acme-test.foo-start[254]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [94524.933353] server acme-test.foo-start[244]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [94524.935751] server acme-test.foo-start[244]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [94524.937726] server acme-test.foo-start[244]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [94524.939587] server acme-test.foo-start[244]: + for fixpath in out certificates container-test-run-certificates> server # [94524.939627] server acme-test.foo-start[244]: + '[' -d out ']' container-test-run-certificates> server # [94524.939627] server acme-test.foo-start[244]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [94524.940975] server acme-test.foo-start[244]: + chown -R acme:nginx out container-test-run-certificates> server # [94524.943799] server acme-test.foo-start[244]: + for fixpath in out certificates container-test-run-certificates> server # [94524.943833] server acme-test.foo-start[244]: + '[' -d certificates ']' container-test-run-certificates> server # [94524.947619] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [94524.950224] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> client # [94524.996233] client systemd-networkd[183]: eth1: Gained IPv6LL container-test-run-certificates> server # [94525.556037] server nginx-pre-start[266]: nginx: the configuration file /nix/store/1hcqj3qwgk1l5wg86fhwxyq6ddsn1ggy-nginx.conf syntax is ok container-test-run-certificates> ca # [94525.531994] ca nginx-pre-start[306]: nginx: the configuration file /nix/store/k9srfa7ii17ghl9acb5c7df33yr41ysz-nginx.conf syntax is ok container-test-run-certificates> server # [94525.556437] server nginx-pre-start[266]: nginx: configuration file /nix/store/1hcqj3qwgk1l5wg86fhwxyq6ddsn1ggy-nginx.conf test is successful container-test-run-certificates> ca # [94525.532417] ca nginx-pre-start[306]: nginx: configuration file /nix/store/k9srfa7ii17ghl9acb5c7df33yr41ysz-nginx.conf test is successful container-test-run-certificates> server # [94525.561038] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [94525.561474] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [94525.562770] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [94525.537021] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [94525.537458] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [94525.538706] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca # [94526.121010] ca acme-order-renew-ca.foo-start[309]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [94526.124726] ca acme-order-renew-ca.foo-start[309]: + set -euo pipefail container-test-run-certificates> ca # [94526.124853] ca acme-order-renew-ca.foo-start[309]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [94526.124937] ca acme-order-renew-ca.foo-start[309]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [94526.126012] ca acme-order-renew-ca.foo-start[309]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [94526.155126] ca acme-order-renew-ca.foo-start[320]: 2026/09/05 09:42:26 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [94526.155458] ca acme-order-renew-ca.foo-start[320]: 2026/09/05 09:42:26 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [94526.179248] ca step-ca[204]: time="2026-09-05T09:42:26Z" level=info duration="90.481µs" duration-ns=90481 fields.time="2026-09-05T09:42:26Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=aa47d62e-b0a3-4987-8824-b12ec7ea3d15 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [94526.179870] ca acme-order-renew-ca.foo-start[320]: 2026/09/05 09:42:26 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [94526.180614] ca step-ca[204]: time="2026-09-05T09:42:26Z" level=info duration="569.607µs" duration-ns=569607 fields.time="2026-09-05T09:42:26Z" method=HEAD name=ca nonce=cDNPamo1WFlqYXBZNDNYdm9Yd3ozMmNoVFdsQmFhMlU path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=6bfe01b5-b3e0-4db0-8fc4-25c7e2962564 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [94526.183638] ca step-ca[204]: time="2026-09-05T09:42:26Z" level=info duration=2.508715ms duration-ns=2508715 fields.time="2026-09-05T09:42:26Z" method=POST name=ca nonce=bDBRRmRONlRSb3FCcHZ0QTVpYU4yRVI4U3p5d0laMGY path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=9dcd9cbc-3013-46df-8582-763ded53d836 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/doqmLfVlldxjUAqkW9DKC2DfnsgfBLtm/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [94526.184152] ca acme-order-renew-ca.foo-start[320]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [94526.184152] ca acme-order-renew-ca.foo-start[320]: Your account credentials have been saved in your container-test-run-certificates> ca # [94526.184152] ca acme-order-renew-ca.foo-start[320]: configuration directory at "accounts". container-test-run-certificates> ca # [94526.184152] ca acme-order-renew-ca.foo-start[320]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [94526.184152] ca acme-order-renew-ca.foo-start[320]: configuration directory will also contain private keys container-test-run-certificates> ca # [94526.184152] ca acme-order-renew-ca.foo-start[320]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [94526.184152] ca acme-order-renew-ca.foo-start[320]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [94526.184152] ca acme-order-renew-ca.foo-start[320]: 2026/09/05 09:42:26 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [94526.186890] ca step-ca[204]: time="2026-09-05T09:42:26Z" level=info duration=2.350872ms duration-ns=2350872 fields.time="2026-09-05T09:42:26Z" method=POST name=ca nonce=WElYYWs5bEs4RnJXYWl0MXVhVVRIdkd3MVVwTmhmMDQ path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=77e8a1d6-98bc-49e0-95e4-858a783513c7 response="{\"id\":\"E3SXGC3hwDPOBU8Ti80YNMhX2DsAyKaY\",\"status\":\"pending\",\"expires\":\"2026-09-06T09:42:26Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-09-05T09:41:26Z\",\"notAfter\":\"2026-12-04T09:42:26Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/v3cLutL5QDPaQu0vR9TjfNkkZcwAlHF5\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/E3SXGC3hwDPOBU8Ti80YNMhX2DsAyKaY/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [94526.246393] ca step-ca[204]: time="2026-09-05T09:42:26Z" level=info duration=2.120789ms duration-ns=2120789 fields.time="2026-09-05T09:42:26Z" method=POST name=ca nonce=U1l0Y2laVUtKektid25oa1llRURFNHNBaTN3bEVqb1Q path=/acme/acme/authz/v3cLutL5QDPaQu0vR9TjfNkkZcwAlHF5 protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=951211b0-052b-4919-955f-132807051fc6 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"KuPR9WtqAksvorq4226lPXi6rF4RSaX0\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/v3cLutL5QDPaQu0vR9TjfNkkZcwAlHF5/GRgCggIxxCuQ9rPhRL1wnttMpAmwSyFA\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"KuPR9WtqAksvorq4226lPXi6rF4RSaX0\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/v3cLutL5QDPaQu0vR9TjfNkkZcwAlHF5/5FAeyZ71SXDdm0FTtWnR8c65J8AdzaEm\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"KuPR9WtqAksvorq4226lPXi6rF4RSaX0\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/v3cLutL5QDPaQu0vR9TjfNkkZcwAlHF5/hbKpvGqr5yEqNEJGxZaGulvPft98AWmt\"}],\"wildcard\":false,\"expires\":\"2026-09-06T09:42:26Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [94526.246728] ca acme-order-renew-ca.foo-start[320]: 2026/09/05 09:42:26 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/v3cLutL5QDPaQu0vR9TjfNkkZcwAlHF5 container-test-run-certificates> ca # [94526.246728] ca acme-order-renew-ca.foo-start[320]: 2026/09/05 09:42:26 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [94526.246728] ca acme-order-renew-ca.foo-start[320]: 2026/09/05 09:42:26 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [94526.246810] ca acme-order-renew-ca.foo-start[320]: 2026/09/05 09:42:26 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [94526.252013] ca step-ca[204]: time="2026-09-05T09:42:26Z" level=info duration=4.556622ms duration-ns=4556622 fields.time="2026-09-05T09:42:26Z" method=POST name=ca nonce=T0NnOWdQVGJWSlFLVENUTzhNQ3gwTlQzcGJPc0U1c1Q path=/acme/acme/challenge/v3cLutL5QDPaQu0vR9TjfNkkZcwAlHF5/5FAeyZ71SXDdm0FTtWnR8c65J8AdzaEm protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=a45fce2b-062d-4932-9ef7-b3923c815253 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"KuPR9WtqAksvorq4226lPXi6rF4RSaX0\",\"validated\":\"2026-09-05T09:42:26Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/v3cLutL5QDPaQu0vR9TjfNkkZcwAlHF5/5FAeyZ71SXDdm0FTtWnR8c65J8AdzaEm\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [94526.252668] ca acme-order-renew-ca.foo-start[320]: 2026/09/05 09:42:26 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [94526.252776] ca acme-order-renew-ca.foo-start[320]: 2026/09/05 09:42:26 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [94526.263172] ca step-ca[204]: time="2026-09-05T09:42:26Z" level=info duration=8.630479ms duration-ns=8630479 fields.time="2026-09-05T09:42:26Z" method=POST name=ca nonce=ck82cFRZZE5CeUNwYkRGdTBObXdEUTY1SEhWT1VoU1Q path=/acme/acme/order/E3SXGC3hwDPOBU8Ti80YNMhX2DsAyKaY/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=1b25382c-5908-42b8-9db4-bc6f9e4779e4 response="{\"id\":\"E3SXGC3hwDPOBU8Ti80YNMhX2DsAyKaY\",\"status\":\"valid\",\"expires\":\"2026-09-06T09:42:26Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-09-05T09:41:26Z\",\"notAfter\":\"2026-12-04T09:42:26Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/v3cLutL5QDPaQu0vR9TjfNkkZcwAlHF5\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/E3SXGC3hwDPOBU8Ti80YNMhX2DsAyKaY/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/6n3EIXa99bkjbvb2LYen5eIuVsAoA0lL\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [94526.265916] ca step-ca[204]: time="2026-09-05T09:42:26Z" level=info certificate="MIIB1DCCAXmgAwIBAgIQH2R1Q7l9U3ZzUxv/JKUVxzAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA5MDUwOTQxMjZaFw0yNjEyMDQwOTQyMjZaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABFhacbRAd14+mr4y8ALFtpCcLSKndYqjWrr3ED25cSm7AjlhImp+3wtzlxu9+eDfJtUl+7U1mOpp3MptFAJ2yVGjgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUsi0ouFjezv0WvmTDQm0EJwWTcK4wHwYDVR0jBBgwFoAUx24OQgxCLFtIAVMVSCEosPJxiiEwEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNJADBGAiEAgTNOVCQi74EqlVBWI2mRzdOppP9fN2UodOZV04a0uH4CIQCVAVG+FVAEvou7WRZQTn7IoMqLQR3B11OJ8QIX6YtvsQ==" duration=1.790905ms duration-ns=1790905 fields.time="2026-09-05T09:42:26Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=Y0RNdThjMDBuMDByODNDU25RR2lzVnM2c3d4Zm1GTzc path=/acme/acme/certificate/6n3EIXa99bkjbvb2LYen5eIuVsAoA0lL protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=42090429-b678-4ee7-9a6c-8bd0d4525a7d sans="map[dns:[ca.foo]]" serial=41727675962802627209865850856734528967 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-09-05T09:41:26Z" valid-to="2026-12-04T09:42:26Z" container-test-run-certificates> ca # [94526.266271] ca acme-order-renew-ca.foo-start[320]: 2026/09/05 09:42:26 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [94526.271795] ca acme-order-renew-ca.foo-start[309]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [94526.273902] ca acme-order-renew-ca.foo-start[309]: + touch out/acme-success container-test-run-certificates> ca # [94526.275659] ca acme-order-renew-ca.foo-start[309]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [94526.277054] ca acme-order-renew-ca.foo-start[309]: + touch out/renewed container-test-run-certificates> ca # [94526.278789] ca acme-order-renew-ca.foo-start[309]: + echo Installing new certificate container-test-run-certificates> ca # [94526.278789] ca acme-order-renew-ca.foo-start[309]: Installing new certificate container-test-run-certificates> ca # [94526.278827] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [94526.280472] ca acme-order-renew-ca.foo-start[353]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [94526.280724] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [94526.282429] ca acme-order-renew-ca.foo-start[354]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [94526.282689] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [94526.284173] ca acme-order-renew-ca.foo-start[355]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [94526.284384] ca acme-order-renew-ca.foo-start[309]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [94526.286158] ca acme-order-renew-ca.foo-start[309]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [94526.287983] ca acme-order-renew-ca.foo-start[309]: + for fixpath in out certificates container-test-run-certificates> ca # [94526.288013] ca acme-order-renew-ca.foo-start[309]: + '[' -d out ']' container-test-run-certificates> ca # [94526.288033] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [94526.289741] ca acme-order-renew-ca.foo-start[309]: + chown -R acme:nginx out container-test-run-certificates> ca # [94526.292923] ca acme-order-renew-ca.foo-start[309]: + for fixpath in out certificates container-test-run-certificates> ca # [94526.292943] ca acme-order-renew-ca.foo-start[309]: + '[' -d certificates ']' container-test-run-certificates> ca # [94526.292970] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [94526.294738] ca acme-order-renew-ca.foo-start[309]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [94526.298901] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [94526.434662] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [94526.126381] server acme-order-renew-test.foo-start[269]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [94526.129195] server acme-order-renew-test.foo-start[269]: + set -euo pipefail container-test-run-certificates> server # [94526.129297] server acme-order-renew-test.foo-start[269]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [94526.129388] server acme-order-renew-test.foo-start[269]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [94526.130859] server acme-order-renew-test.foo-start[269]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [94526.156354] server acme-order-renew-test.foo-start[280]: 2026/09/05 09:42:26 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [94526.156769] server acme-order-renew-test.foo-start[280]: 2026/09/05 09:42:26 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> server # [94526.186361] server acme-order-renew-test.foo-start[280]: 2026/09/05 09:42:26 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [94526.187071] server acme-order-renew-test.foo-start[269]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [94526.187071] server acme-order-renew-test.foo-start[269]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [94526.187071] server acme-order-renew-test.foo-start[269]: + exit 10 container-test-run-certificates> server # [94526.190050] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [94526.190172] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [94526.190451] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [94526.190831] server systemd[1]: Startup finished in 4.100s. container-test-run-certificates> ca # [94526.438950] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [94526.439197] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca # [94526.971185] ca nginx[371]: nginx: the configuration file /nix/store/k9srfa7ii17ghl9acb5c7df33yr41ysz-nginx.conf syntax is ok container-test-run-certificates> ca # [94526.971687] ca nginx[371]: nginx: configuration file /nix/store/k9srfa7ii17ghl9acb5c7df33yr41ysz-nginx.conf test is successful container-test-run-certificates> ca # [94527.470626] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [94527.471198] ca systemd[1]: Startup finished in 5.365s. container-test-run-certificates> ca # [94527.771600] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 3.94 seconds) container-test-run-certificates> ca # [94528.324553] ca acme-order-renew-ca.foo-start[386]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [94528.327135] ca acme-order-renew-ca.foo-start[386]: + set -euo pipefail container-test-run-certificates> ca # [94528.327208] ca acme-order-renew-ca.foo-start[386]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [94528.327322] ca acme-order-renew-ca.foo-start[386]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [94528.328723] ca acme-order-renew-ca.foo-start[386]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [94528.328723] ca acme-order-renew-ca.foo-start[386]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [94528.329349] ca acme-order-renew-ca.foo-start[394]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [94528.333592] ca acme-order-renew-ca.foo-start[386]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [94528.333674] ca acme-order-renew-ca.foo-start[386]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [94528.377154] ca step-ca[204]: time="2026-09-05T09:42:28Z" level=info duration="69.241µs" duration-ns=69241 fields.time="2026-09-05T09:42:28Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=de91c669-0c01-46a8-bbf9-6f159b1b8029 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [94528.377842] ca acme-order-renew-ca.foo-start[395]: 2026/09/05 09:42:28 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [94528.377842] ca acme-order-renew-ca.foo-start[395]: 2026/09/05 09:42:28 [INFO] [ca.foo] The certificate expires at 2026-12-04T09:42:26Z, the renewal can be performed in 1439h59m37.636660263s: no renewal. container-test-run-certificates> ca # [94528.378209] ca acme-order-renew-ca.foo-start[386]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [94528.380325] ca acme-order-renew-ca.foo-start[386]: + touch out/acme-success container-test-run-certificates> ca # [94528.382124] ca acme-order-renew-ca.foo-start[386]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [94528.383440] ca acme-order-renew-ca.foo-start[386]: + for fixpath in out certificates container-test-run-certificates> ca # [94528.383440] ca acme-order-renew-ca.foo-start[386]: + '[' -d out ']' container-test-run-certificates> ca # [94528.383537] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [94528.385403] ca acme-order-renew-ca.foo-start[386]: + chown -R acme:nginx out container-test-run-certificates> ca # [94528.388387] ca acme-order-renew-ca.foo-start[386]: + for fixpath in out certificates container-test-run-certificates> ca # [94528.388387] ca acme-order-renew-ca.foo-start[386]: + '[' -d certificates ']' container-test-run-certificates> ca # [94528.388502] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [94528.390571] ca acme-order-renew-ca.foo-start[386]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [94528.393861] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [94528.538622] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [94528.538977] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [94531.569611] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [94531.569827] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [94531.570713] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [94531.572323] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.57 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1010 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 5 09:42:24 2026 GMT container-test-run-certificates> * expire date: Oct 5 09:42:24 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 3fbab6 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [94532.086333] server acme-test.foo-start[315]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [94532.089495] server acme-test.foo-start[315]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [94532.089544] server acme-test.foo-start[315]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [94532.105258] server acme-test.foo-start[324]: + cd test.foo container-test-run-certificates> server # [94532.105540] server acme-test.foo-start[324]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [94532.107083] server acme-test.foo-start[325]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [94532.107364] server acme-test.foo-start[324]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [94532.108806] server acme-test.foo-start[324]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [94532.109057] server acme-test.foo-start[315]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [94532.111253] server acme-test.foo-start[315]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [94532.113096] server acme-test.foo-start[315]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [94532.114888] server acme-test.foo-start[315]: + for fixpath in out certificates container-test-run-certificates> server # [94532.114888] server acme-test.foo-start[315]: + '[' -d out ']' container-test-run-certificates> server # [94532.114948] server acme-test.foo-start[315]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [94532.117075] server acme-test.foo-start[315]: + chown -R acme:nginx out container-test-run-certificates> server # [94532.120378] server acme-test.foo-start[315]: + for fixpath in out certificates container-test-run-certificates> server # [94532.120378] server acme-test.foo-start[315]: + '[' -d certificates ']' container-test-run-certificates> server # [94532.124053] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [94532.128695] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [94532.641109] server acme-order-renew-test.foo-start[332]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [94532.644966] server acme-order-renew-test.foo-start[332]: + set -euo pipefail container-test-run-certificates> server # [94532.645045] server acme-order-renew-test.foo-start[332]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [94532.645171] server acme-order-renew-test.foo-start[332]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [94532.646610] server acme-order-renew-test.foo-start[332]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [94532.700548] server acme-order-renew-test.foo-start[340]: 2026/09/05 09:42:32 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [94532.739372] server acme-order-renew-test.foo-start[340]: !!!! HEADS UP !!!! container-test-run-certificates> server # [94532.739372] server acme-order-renew-test.foo-start[340]: Your account credentials have been saved in your container-test-run-certificates> server # [94532.739372] server acme-order-renew-test.foo-start[340]: configuration directory at "accounts". container-test-run-certificates> server # [94532.739372] server acme-order-renew-test.foo-start[340]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [94532.739372] server acme-order-renew-test.foo-start[340]: configuration directory will also contain private keys container-test-run-certificates> server # [94532.739372] server acme-order-renew-test.foo-start[340]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [94532.739372] server acme-order-renew-test.foo-start[340]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [94532.739372] server acme-order-renew-test.foo-start[340]: 2026/09/05 09:42:32 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [94532.810178] server acme-order-renew-test.foo-start[340]: 2026/09/05 09:42:32 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/6o7M584YXDEw06S3WXce0cjMHAq7QOFq container-test-run-certificates> server # [94532.810178] server acme-order-renew-test.foo-start[340]: 2026/09/05 09:42:32 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [94532.810178] server acme-order-renew-test.foo-start[340]: 2026/09/05 09:42:32 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [94532.810178] server acme-order-renew-test.foo-start[340]: 2026/09/05 09:42:32 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [94532.819360] server acme-order-renew-test.foo-start[340]: 2026/09/05 09:42:32 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [94532.819509] server acme-order-renew-test.foo-start[340]: 2026/09/05 09:42:32 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [94532.839384] server acme-order-renew-test.foo-start[340]: 2026/09/05 09:42:32 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [94532.845102] server acme-order-renew-test.foo-start[332]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [94532.847404] server acme-order-renew-test.foo-start[332]: + touch out/acme-success container-test-run-certificates> server # [94532.849199] server acme-order-renew-test.foo-start[332]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [94532.850371] server acme-order-renew-test.foo-start[332]: + touch out/renewed container-test-run-certificates> server # [94532.852221] server acme-order-renew-test.foo-start[332]: + echo Installing new certificate container-test-run-certificates> server # [94532.852221] server acme-order-renew-test.foo-start[332]: Installing new certificate container-test-run-certificates> server # [94532.852221] server acme-order-renew-test.foo-start[332]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [94532.853902] server acme-order-renew-test.foo-start[372]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [94532.854370] server acme-order-renew-test.foo-start[332]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [94532.856246] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [94532.856504] server acme-order-renew-test.foo-start[332]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [94532.857882] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [94532.858090] server acme-order-renew-test.foo-start[332]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [94532.859998] server acme-order-renew-test.foo-start[332]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [94532.861792] server acme-order-renew-test.foo-start[332]: + for fixpath in out certificates container-test-run-certificates> server # [94532.861826] server acme-order-renew-test.foo-start[332]: + '[' -d out ']' container-test-run-certificates> server # [94532.861826] server acme-order-renew-test.foo-start[332]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [94532.863591] server acme-order-renew-test.foo-start[332]: + chown -R acme:nginx out container-test-run-certificates> server # [94532.866780] server acme-order-renew-test.foo-start[332]: + for fixpath in out certificates container-test-run-certificates> server # [94532.866780] server acme-order-renew-test.foo-start[332]: + '[' -d certificates ']' container-test-run-certificates> server # [94532.866855] server acme-order-renew-test.foo-start[332]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [94532.868809] server acme-order-renew-test.foo-start[332]: + chown -R acme:nginx certificates container-test-run-certificates> server # [94532.871101] server acme-order-renew-test.foo-start[332]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [94532.699825] ca step-ca[204]: time="2026-09-05T09:42:32Z" level=info duration="46.16µs" duration-ns=46160 fields.time="2026-09-05T09:42:32Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=33a7fe3e-5246-4566-b60c-314e7bddf609 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [94532.732904] ca step-ca[204]: time="2026-09-05T09:42:32Z" level=info duration=28.163867ms duration-ns=28163867 fields.time="2026-09-05T09:42:32Z" method=HEAD name=ca nonce=aGxBbzJUOEpLZWNHQUVrVW8yQTVIR2dDb29VSkxNSjk path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=88e37a4a-2231-461d-9bc5-1982aa615e85 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [94532.738614] ca step-ca[204]: time="2026-09-05T09:42:32Z" level=info duration=2.028988ms duration-ns=2028988 fields.time="2026-09-05T09:42:32Z" method=POST name=ca nonce=Z095WDRsUTYySml3RHplc3JSeG1VRmRhSTNDRkxzV1Q path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=05907dcc-3fb8-4940-867e-33b1f59e6a81 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/hAModOlaJDdVMTuYG1M7dYXzPQrjX2DK/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [94532.746966] ca step-ca[204]: time="2026-09-05T09:42:32Z" level=info duration=4.37918ms duration-ns=4379180 fields.time="2026-09-05T09:42:32Z" method=POST name=ca nonce=ZE9IcFBCOWpWNnoxZEludk5QRjFreEF2akFaZWg1d0o path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=52bd9351-1f15-45d9-887f-c00704213779 response="{\"id\":\"ZkjUQQhRFRAORLrP4t2eLdmkcjlxB1tl\",\"status\":\"pending\",\"expires\":\"2026-09-06T09:42:32Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-09-05T09:41:32Z\",\"notAfter\":\"2026-12-04T09:42:32Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/6o7M584YXDEw06S3WXce0cjMHAq7QOFq\"],\"finalize\":\"https://ca.foo/acme/acme/order/ZkjUQQhRFRAORLrP4t2eLdmkcjlxB1tl/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [94532.809486] ca step-ca[204]: time="2026-09-05T09:42:32Z" level=info duration=2.298232ms duration-ns=2298232 fields.time="2026-09-05T09:42:32Z" method=POST name=ca nonce=dnpXTHk0SG1QOFpSNTJZVHp6dk9MRk5ma2Nhc0pNV2g path=/acme/acme/authz/6o7M584YXDEw06S3WXce0cjMHAq7QOFq protocol=HTTP/1.1 referer= remote-address="::1" request-id=10925bef-ab40-4127-9b54-9ecfb3616447 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"lyDqVVNygaJIwzltSkaYWY9sIbm3HIG3\",\"url\":\"https://ca.foo/acme/acme/challenge/6o7M584YXDEw06S3WXce0cjMHAq7QOFq/Tc1kOqxu5Woocfnliu7TqMHND9qsWUob\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"lyDqVVNygaJIwzltSkaYWY9sIbm3HIG3\",\"url\":\"https://ca.foo/acme/acme/challenge/6o7M584YXDEw06S3WXce0cjMHAq7QOFq/P8sxvpwV01lZJ0EeNzobJ6H9lj600ztz\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"lyDqVVNygaJIwzltSkaYWY9sIbm3HIG3\",\"url\":\"https://ca.foo/acme/acme/challenge/6o7M584YXDEw06S3WXce0cjMHAq7QOFq/3pmKFlT21xW5VSPCXDdsD2MY1wJRE22J\"}],\"wildcard\":false,\"expires\":\"2026-09-06T09:42:32Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [94532.818796] ca step-ca[204]: time="2026-09-05T09:42:32Z" level=info duration=5.134551ms duration-ns=5134551 fields.time="2026-09-05T09:42:32Z" method=POST name=ca nonce=WW1pRkp0aFMyNWVkajBnWU94Y3VjMEhnWUJwNGV0NUY path=/acme/acme/challenge/6o7M584YXDEw06S3WXce0cjMHAq7QOFq/P8sxvpwV01lZJ0EeNzobJ6H9lj600ztz protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=2b5e2088-f655-4fd5-a4b5-32322d4c9310 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"lyDqVVNygaJIwzltSkaYWY9sIbm3HIG3\",\"validated\":\"2026-09-05T09:42:32Z\",\"url\":\"https://ca.foo/acme/acme/challenge/6o7M584YXDEw06S3WXce0cjMHAq7QOFq/P8sxvpwV01lZJ0EeNzobJ6H9lj600ztz\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [94532.832069] ca step-ca[204]: time="2026-09-05T09:42:32Z" level=info duration=8.272434ms duration-ns=8272434 fields.time="2026-09-05T09:42:32Z" method=POST name=ca nonce=NU1Bc1JuRkdMNWRISXlaTnI1NFFTVlhPUHlLT3M1Tkg path=/acme/acme/order/ZkjUQQhRFRAORLrP4t2eLdmkcjlxB1tl/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=669ae59b-23e9-46a8-b546-538e3e855eca response="{\"id\":\"ZkjUQQhRFRAORLrP4t2eLdmkcjlxB1tl\",\"status\":\"valid\",\"expires\":\"2026-09-06T09:42:32Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-09-05T09:41:32Z\",\"notAfter\":\"2026-12-04T09:42:32Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/6o7M584YXDEw06S3WXce0cjMHAq7QOFq\"],\"finalize\":\"https://ca.foo/acme/acme/order/ZkjUQQhRFRAORLrP4t2eLdmkcjlxB1tl/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/b9PqXHGZ2BR59X6R7accbR9JBJq8FzVm\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [94532.838621] ca step-ca[204]: time="2026-09-05T09:42:32Z" level=info certificate="MIIB1zCCAX6gAwIBAgIRAI0EeDLBkCd2gt/2LM6LCggwCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwOTA1MDk0MTMyWhcNMjYxMjA0MDk0MjMyWjATMREwDwYDVQQDEwh0ZXN0LmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABLPXGVFjYZkrmAraA7C6rcMAhhe9IugT+ryWEaxnBUff0f5Oni1xVhV3OCFgrGZKWGCxllLm/UV4TQ3Yzlb9YFSjgaYwgaMwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUOuzksp69FkUKYwkXa8Qs89PUCYYwHwYDVR0jBBgwFoAUx24OQgxCLFtIAVMVSCEosPJxiiEwEwYDVR0RBAwwCoIIdGVzdC5mb28wHQYMKwYBBAGCpGTGKEABBA0wCwIBBgQEYWNtZQQAMAoGCCqGSM49BAMCA0cAMEQCIHXwYPvWhDFlCt77aDdiqYoaEm/J6b8dnRi/vFnFise/AiBSyhuBY6ZrdB5TeRtvXTfer5ZskgGzvEz6UmBRqzWLZA==" duration=2.842919ms duration-ns=2842919 fields.time="2026-09-05T09:42:32Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=UGVHTEZrekVieWhLYVB4Y1IwS2Nmb0VqM2FsZU5kcjM path=/acme/acme/certificate/b9PqXHGZ2BR59X6R7accbR9JBJq8FzVm protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=abd05820-98c6-4838-9716-e72239484fab sans="map[dns:[test.foo]]" serial=187444354503572719875601935128169482760 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-09-05T09:41:32Z" valid-to="2026-12-04T09:42:32Z" container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1010 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 5 09:42:24 2026 GMT container-test-run-certificates> * expire date: Oct 5 09:42:24 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 3fbab6 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [94532.995008] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [94532.999946] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [94533.000276] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [94533.507281] server nginx[390]: nginx: the configuration file /nix/store/1hcqj3qwgk1l5wg86fhwxyq6ddsn1ggy-nginx.conf syntax is ok container-test-run-certificates> server # [94533.507787] server nginx[390]: nginx: configuration file /nix/store/1hcqj3qwgk1l5wg86fhwxyq6ddsn1ggy-nginx.conf test is successful container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [931 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [78 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 5 09:41:32 2026 GMT container-test-run-certificates> * expire date: Dec 4 09:42:32 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 52840 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 630 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 2.16 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> 8d:04:78:32:c1:90:27:76:82:df:f6:2c:ce:8b:0a:08 container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Sep 5 09:41:32 2026 GMT container-test-run-certificates> Not After : Dec 4 09:42:32 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:b3:d7:19:51:63:61:99:2b:98:0a:da:03:b0:ba: container-test-run-certificates> ad:c3:00:86:17:bd:22:e8:13:fa:bc:96:11:ac:67: container-test-run-certificates> 05:47:df:d1:fe:4e:9e:2d:71:56:15:77:38:21:60: container-test-run-certificates> ac:66:4a:58:60:b1:96:52:e6:fd:45:78:4d:0d:d8: container-test-run-certificates> ce:56:fd:60:54 container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> 3A:EC:E4:B2:9E:BD:16:45:0A:63:09:17:6B:C4:2C:F3:D3:D4:09:86 container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> C7:6E:0E:42:0C:42:2C:5B:48:01:53:15:48:21:28:B0:F2:71:8A:21 container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:44:02:20:75:f0:60:fb:d6:84:31:65:0a:de:fb:68:37:62: container-test-run-certificates> a9:8a:1a:12:6f:c9:e9:bf:1d:9d:18:bf:bc:59:c5:8a:c7:bf: container-test-run-certificates> 02:20:52:ca:1b:81:63:a6:6b:74:1e:53:79:1b:6f:5d:37:de: container-test-run-certificates> af:96:6c:92:01:b3:bc:4c:fa:52:60:51:ab:35:8b:64 container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.05 seconds) container-test-run-certificates> (finished: run the VM test script, in 12.72 seconds) container-test-run-certificates> server # [94534.065042] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> test script finished in 13.57s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> kill NspawnMachine (pid 53) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> kill NspawnMachine (pid 55) container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> Container server terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.49 seconds) warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy post-build step Upload to niks3: ok time=2026-09-05T09:42:42.995Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-09-05T09:42:43.391Z level=INFO msg="Uploading 1 narinfos" time=2026-09-05T09:42:43.653Z level=INFO msg="Upload complete. (714ms)"