these 97 derivations will be built: /nix/store/013b54dpzbclf291zrksw3ffh5r2201d-user-generators.drv /nix/store/1qag1wxymr8hvp8par8bmzljj0q86p5j-system-generators.drv /nix/store/lm95giifd0dhq1kdq5mb1znhn6x4p6x7-nixos-tmpfiles.d.drv /nix/store/2gvy9qsk26x5j86hyf97f090dm9r12d2-tmpfiles.d.drv /nix/store/3z64pz59i9qs2j4ibaxf5cgj128pbpbd-X-Restart-Triggers-acme-ca.foo.drv /nix/store/9ih973wng9cbgnw5yibjnv7v433fdncp-unit-script-acme-ca.foo-start.drv /nix/store/22wdlwnfq80a4gf3q30nmczyzn1br71h-unit-acme-ca.foo.service.drv /nix/store/rdxhp0awj9fb0vdx5srklv00ii428ccq-firewall-start.drv /nix/store/d97jkgjnw0qa3ficf4fi9rd83kkbqd7m-firewall-reload.drv /nix/store/36hmmd9m408dxc87qiq720gdwbzd9s0b-unit-firewall.service.drv /nix/store/4dzyy8fmxm5z2a65d2gmg0cfnz0xwcmi-acme-postrun.drv /nix/store/kndwyk76bziyv42hdjc47fy545jcjlhy-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/4fsvs6h1wgd8vrq60phvmg538s3v4sib-unit-acme-order-renew-ca.foo.service.drv /nix/store/7wymljyza967apf05c1748nk7mczl4bk-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/83l8v7ng5lz88hahqi3q041jllffgfc2-unit-systemd-tmpfiles-resetup.service.drv /nix/store/vjgbv2w3jm2ih9apj9c5wka6qjc7wrz3-system-path.drv /nix/store/nnxn7yfw4xmdr08mj85mp3lijd5wzg91-dbus-1.drv /nix/store/l2m3kxcxhlrl4g64g5x7g059cp8k9qim-X-Restart-Triggers-dbus-broker.drv /nix/store/ihzsj4k9jyp4rvxl0v6c6x6yk62mq5v9-unit-dbus-broker.service.drv /nix/store/nlqdj7wac2y36y7v7rph0hksnr8zfc9n-nginx.conf.drv /nix/store/rw7v870is11xl4657rjc3rn4yjl9w2p7-unit-script-nginx-pre-start.drv /nix/store/j0xgnc1kcj9bfpm1kr20kh5kpdsaf5c7-unit-nginx.service.drv /nix/store/ziw37k81kkkvwvzwlbgpds150xm3ig3c-ca.json.drv /nix/store/gji9fgw3k1iq8rqviilp4ra6zq505yyq-X-Restart-Triggers-step-ca.drv /nix/store/jsipvb8627mhdaf8s5qyrp9x2rdyvqb8-unit-step-ca.service.drv /nix/store/lacmwdd44dzgw2x62bsf3j9i2n527pls-unit-nginx-config-reload.service.drv /nix/store/chfxpbk41jaj1p23w27g7sl8zicxk1rc-cacert-blocklist.txt.drv /nix/store/mjv25sy4hly93mcfjy76lw8npj5wgrnn-cacert-extra-certificates-bundle.crt.drv /nix/store/v878yqsa9qmb2qrrql661rc9hlfrnxsb-nss-cacert-3.126.drv /nix/store/ln019j1z90w8hkf9v4cgjxsp9mbi8j7x-unit-nix-daemon.service.drv /nix/store/nhcgml3c92azgy1l9g42hk91dkp16pyp-acme-setup-privileged.drv /nix/store/s9km8agrqzqzbcns8xyn4ypw7jjkr7af-unit-acme-setup.service.drv /nix/store/vx4k4ah41xarp8mc8y4wjqi5whmr3g9c-unit-acme-renew-ca.foo.timer.drv /nix/store/ws9p9f1ilid28mxihffhl70mkys7m3wj-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/2qxfy1r7wbkv8ip5ihw20z8yxpzdybsi-system-units.drv /nix/store/av8fv1sm41dfnyywxlqdzfh3mhn2sn0l-system-shutdown.drv /nix/store/ji5z680ajfdb50340zz888kwws981h0l-etc-hostname.drv /nix/store/msvcmqhmajssll92gjai5phf8jw6pyac-vars-check-certificates.drv /nix/store/8600386bxqaa15pag4dvba7696g9zf2n-extra-hosts.drv /nix/store/lnad1cpwsdc1qc9azf0zgx7zjg6625vg-string-hosts.drv /nix/store/x1pznybbws35d4zvijmba9pzq23qg255-hosts.drv /nix/store/dw36hr84igwyzv8ip7cn3mzx194ccff1-unit-dbus-broker.service.drv /nix/store/xj67g54srsv4whsd8jz4zj9nhy2q9jd9-user-units.drv /nix/store/2svmdbnv87axqjd120djn6cnmw54xilr-etc.drv /nix/store/g95x9vr6y35z9c0ijprbinn29p5b6f0r-decrypt-age-secrets.drv /nix/store/n3pcql3kxl7qdz8rznx65ba10340ja0j-users-groups.json.drv /nix/store/0d6bih54gql81ng4994ah2bwciynsazn-activate.drv /nix/store/fsr83va6ggycg1gknk7f48598f9jmd1s-system-path.drv /nix/store/k2f30qnc7x8z9m1cnp12wh8ky24h6wli-dbus-1.drv /nix/store/vs4j71wqh7m28bfw4393rzr58y8qh3cf-X-Restart-Triggers-dbus-broker.drv /nix/store/16lvn0wg72nm8wqfyw1xhinnp780dw84-unit-dbus-broker.service.drv /nix/store/hmm2bx0wzw811hrag8g58hj3r5bhd709-X-Restart-Triggers-acme-test.foo.drv /nix/store/v2dkfbyzaflr3vic7zy0dpg1r7zf5sw6-unit-script-acme-test.foo-start.drv /nix/store/1v3vxm3nksax5ha6lgbhxbkyy3dryrln-unit-acme-test.foo.service.drv /nix/store/1zyfa4xzwkrj97a2h95n0cppkvimscqf-test-script.drv /nix/store/31rj4mgq1nwypvkvdpb0v0gcg51l03xz-acme-postrun.drv /nix/store/wm7bhdsgk7maxq6hxb34j1yf9infbqgb-users-groups.json.drv /nix/store/3565qvpsvl50rj114r83jqiz0x5wvvgh-dry-activate.drv /nix/store/3970p028m49mdxmznsiwlnvhcsk9qa2y-nginx.conf.drv /nix/store/yh7rn816w00yifd5ca1xf58hd9amhgii-system-path.drv /nix/store/92pjxhdbq9bisddsa6khyq7jrc3gnkgr-dbus-1.drv /nix/store/kj76ycy9nzx0jn0rw9z5q9f1bw34i7db-X-Restart-Triggers-dbus-broker.drv /nix/store/bx3crrb9v65rgr20w7nssx5xa61j8mzr-unit-dbus-broker.service.drv /nix/store/3hzf9byn95198xbqkk25rqm6l6kni4ka-user-units.drv /nix/store/957j5jriff0n30ngjx30bws3n48cnasj-unit-dbus-broker.service.drv /nix/store/55wgk4x584cy5hps2vxjd1l7xh5i69jy-system-units.drv /nix/store/kjjxn1q8w1ibsyafz9hwd3lm668h80cd-hosts.drv /nix/store/9dawl1m1711higgv7zs3gvqjxnpx0ljf-etc.drv /nix/store/p3g9b9lyy1f6cqvp3yglvdrnr6bqyf8r-activate.drv /nix/store/df5mlw4b2zncpdjwlgf9vpl2m8grq7a9-nixos-system-client-test.drv /nix/store/39fjr2797vq5lh7dmqm34qg696yhql1d-run-client-nspawn.drv /nix/store/3mfjg63hxjhyhkspdbcpqydcyaw0k97h-hosts.drv /nix/store/p125j5y841vij8f2i3nycjnfkja6sqlh-unit-40-eth1.network.drv /nix/store/4inmh5fdqgkrzz6qn5pij4h2vf3vzn6h-X-Reload-Triggers-systemd-networkd.drv /nix/store/ay571wbv71j47ly318g75adsgamj7hs5-dry-activate.drv /nix/store/ks8rl9mw8adhpl1jl9fl836m8fly008c-nixos-system-ca-test.drv /nix/store/kq8z4lglw0190hsijbmacgq9qsc7h2nh-run-ca-nspawn.drv /nix/store/8w3wfr0x961r4hy2ailivajx4dbg2fvb-unit-acme-renew-test.foo.timer.drv /nix/store/pnalsl2s49yjr48wgvnxagmx8lh49m9p-unit-script-acme-order-renew-test.foo-start.drv /nix/store/9pq23bipqykvy0c10a34z06rsm3v6gsl-unit-acme-order-renew-test.foo.service.drv /nix/store/c9wwc0yigaqqz9yq8pqmcq1r52ryj2bk-unit-dbus-broker.service.drv /nix/store/y11askc7lz9w7kxqp7mw1wc5xnhq2n5i-unit-script-nginx-pre-start.drv /nix/store/izpncllpkq760bwhv3rc9ldqk7ls13km-unit-nginx.service.drv /nix/store/lnh2ygxjgqwmhkinkgvvs4cf04s9aakk-unit-nginx-config-reload.service.drv /nix/store/lsyp04hby1xb4dmfmpfvgbxzgh4yl1z6-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/m5jrjkdvsckhlq58vrfc85h8hkf99fp4-unit-systemd-networkd.service.drv /nix/store/wajgh70k44pmyjzlf689zf4v98kpfq0s-acme-setup-privileged.drv /nix/store/zrfg1fd7pkck9wnj2c62mynfwch1hb55-unit-acme-setup.service.drv /nix/store/9lbjcmr1p60p2n9wcdd06lyw9428xs3n-system-units.drv /nix/store/hfv3flqgbxxq2v8an2nji07lmrinb0ah-user-units.drv /nix/store/xhvxpg5nlqqmgn30yvaas9vf38dd1z18-etc.drv /nix/store/sjx52nspqh7kjpy60irbs7mn923j582s-activate.drv /nix/store/fm2j8mqa57zziky02hdsd9b8f2w0sl4w-nixos-system-server-test.drv /nix/store/n31r3asb2353iy38v9afgdaqws7krlrl-run-server-nspawn.drv /nix/store/4jybdid1iqsvpb2j3zn2vc27vn2bhm09-driverConfiguration.json.drv /nix/store/lm2lyj7jx3xv7f3w04iw4xdypb00ma62-nixos-test-driver-certificates.drv /nix/store/hla48149zx7n3jy6yqax0vjl6p7q2r7w-container-test-run-certificates.drv these 3 paths will be fetched (24.4 MiB download, 77.3 MiB unpacked): /nix/store/7ax2mr4fszclbz94ky41ia2n5r6q94jn-openssl-3.6.3-man /nix/store/mabj8vrffrvzhnc1m76awgdm04p9zygr-python3.14-buildcatrust-0.5.1 /nix/store/51xw1kjjxjyfkljcqsl879nvvh97vxp0-step-ca-0.30.2 building '/nix/store/1zyfa4xzwkrj97a2h95n0cppkvimscqf-test-script.drv' building '/nix/store/ji5z680ajfdb50340zz888kwws981h0l-etc-hostname.drv' building '/nix/store/3970p028m49mdxmznsiwlnvhcsk9qa2y-nginx.conf.drv' building '/nix/store/nlqdj7wac2y36y7v7rph0hksnr8zfc9n-nginx.conf.drv' building '/nix/store/p125j5y841vij8f2i3nycjnfkja6sqlh-unit-40-eth1.network.drv' building '/nix/store/8600386bxqaa15pag4dvba7696g9zf2n-extra-hosts.drv' building '/nix/store/lm95giifd0dhq1kdq5mb1znhn6x4p6x7-nixos-tmpfiles.d.drv' building '/nix/store/lnad1cpwsdc1qc9azf0zgx7zjg6625vg-string-hosts.drv' building '/nix/store/lsyp04hby1xb4dmfmpfvgbxzgh4yl1z6-unit-acme-account-2c44cb477b4787b2cf13.target.drv' building '/nix/store/ws9p9f1ilid28mxihffhl70mkys7m3wj-unit-acme-account-d22a46d9459bf683a338.target.drv' nginx.conf> structuredAttrs is enabled nginx.conf> structuredAttrs is enabled unit-40-eth1.network> structuredAttrs is enabled unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled building '/nix/store/3z64pz59i9qs2j4ibaxf5cgj128pbpbd-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/9ih973wng9cbgnw5yibjnv7v433fdncp-unit-script-acme-ca.foo-start.drv' building '/nix/store/kndwyk76bziyv42hdjc47fy545jcjlhy-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/pnalsl2s49yjr48wgvnxagmx8lh49m9p-unit-script-acme-order-renew-test.foo-start.drv' building '/nix/store/v2dkfbyzaflr3vic7zy0dpg1r7zf5sw6-unit-script-acme-test.foo-start.drv' building '/nix/store/3mfjg63hxjhyhkspdbcpqydcyaw0k97h-hosts.drv' building '/nix/store/kjjxn1q8w1ibsyafz9hwd3lm668h80cd-hosts.drv' building '/nix/store/x1pznybbws35d4zvijmba9pzq23qg255-hosts.drv' building '/nix/store/2gvy9qsk26x5j86hyf97f090dm9r12d2-tmpfiles.d.drv' building '/nix/store/vx4k4ah41xarp8mc8y4wjqi5whmr3g9c-unit-acme-renew-ca.foo.timer.drv' building '/nix/store/8w3wfr0x961r4hy2ailivajx4dbg2fvb-unit-acme-renew-test.foo.timer.drv' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> unit-acme-renew-ca.foo.timer> structuredAttrs is enabled unit-acme-renew-test.foo.timer> structuredAttrs is enabled building '/nix/store/hmm2bx0wzw811hrag8g58hj3r5bhd709-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/nhcgml3c92azgy1l9g42hk91dkp16pyp-acme-setup-privileged.drv' building '/nix/store/22wdlwnfq80a4gf3q30nmczyzn1br71h-unit-acme-ca.foo.service.drv' building '/nix/store/lacmwdd44dzgw2x62bsf3j9i2n527pls-unit-nginx-config-reload.service.drv' building '/nix/store/lnh2ygxjgqwmhkinkgvvs4cf04s9aakk-unit-nginx-config-reload.service.drv' building '/nix/store/msvcmqhmajssll92gjai5phf8jw6pyac-vars-check-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' unit-acme-ca.foo.service> structuredAttrs is enabled unit-nginx-config-reload.service> structuredAttrs is enabled unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/4inmh5fdqgkrzz6qn5pij4h2vf3vzn6h-X-Reload-Triggers-systemd-networkd.drv' building '/nix/store/31rj4mgq1nwypvkvdpb0v0gcg51l03xz-acme-postrun.drv' building '/nix/store/4dzyy8fmxm5z2a65d2gmg0cfnz0xwcmi-acme-postrun.drv' building '/nix/store/wajgh70k44pmyjzlf689zf4v98kpfq0s-acme-setup-privileged.drv' building '/nix/store/rdxhp0awj9fb0vdx5srklv00ii428ccq-firewall-start.drv' building '/nix/store/n3pcql3kxl7qdz8rznx65ba10340ja0j-users-groups.json.drv' building '/nix/store/wm7bhdsgk7maxq6hxb34j1yf9infbqgb-users-groups.json.drv' building '/nix/store/7wymljyza967apf05c1748nk7mczl4bk-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' building '/nix/store/ziw37k81kkkvwvzwlbgpds150xm3ig3c-ca.json.drv' building '/nix/store/fsr83va6ggycg1gknk7f48598f9jmd1s-system-path.drv' building '/nix/store/vjgbv2w3jm2ih9apj9c5wka6qjc7wrz3-system-path.drv' building '/nix/store/yh7rn816w00yifd5ca1xf58hd9amhgii-system-path.drv' building '/nix/store/s9km8agrqzqzbcns8xyn4ypw7jjkr7af-unit-acme-setup.service.drv' building '/nix/store/1v3vxm3nksax5ha6lgbhxbkyy3dryrln-unit-acme-test.foo.service.drv' building '/nix/store/rw7v870is11xl4657rjc3rn4yjl9w2p7-unit-script-nginx-pre-start.drv' building '/nix/store/y11askc7lz9w7kxqp7mw1wc5xnhq2n5i-unit-script-nginx-pre-start.drv' building '/nix/store/3565qvpsvl50rj114r83jqiz0x5wvvgh-dry-activate.drv' ca.json> structuredAttrs is enabled system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment unit-acme-setup.service> structuredAttrs is enabled unit-acme-test.foo.service> structuredAttrs is enabled building '/nix/store/9pq23bipqykvy0c10a34z06rsm3v6gsl-unit-acme-order-renew-test.foo.service.drv' building '/nix/store/v878yqsa9qmb2qrrql661rc9hlfrnxsb-nss-cacert-3.126.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/g95x9vr6y35z9c0ijprbinn29p5b6f0r-decrypt-age-secrets.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' unit-acme-order-renew-test.foo.service> structuredAttrs is enabled building '/nix/store/d97jkgjnw0qa3ficf4fi9rd83kkbqd7m-firewall-reload.drv' building '/nix/store/4fsvs6h1wgd8vrq60phvmg538s3v4sib-unit-acme-order-renew-ca.foo.service.drv' building '/nix/store/zrfg1fd7pkck9wnj2c62mynfwch1hb55-unit-acme-setup.service.drv' building '/nix/store/m5jrjkdvsckhlq58vrfc85h8hkf99fp4-unit-systemd-networkd.service.drv' building '/nix/store/83l8v7ng5lz88hahqi3q041jllffgfc2-unit-systemd-tmpfiles-resetup.service.drv' building '/nix/store/gji9fgw3k1iq8rqviilp4ra6zq505yyq-X-Restart-Triggers-step-ca.drv' building '/nix/store/92pjxhdbq9bisddsa6khyq7jrc3gnkgr-dbus-1.drv' building '/nix/store/k2f30qnc7x8z9m1cnp12wh8ky24h6wli-dbus-1.drv' building '/nix/store/nnxn7yfw4xmdr08mj85mp3lijd5wzg91-dbus-1.drv' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled unit-acme-setup.service> structuredAttrs is enabled unit-systemd-networkd.service> structuredAttrs is enabled unit-systemd-tmpfiles-resetup.service> structuredAttrs is enabled building '/nix/store/izpncllpkq760bwhv3rc9ldqk7ls13km-unit-nginx.service.drv' building '/nix/store/j0xgnc1kcj9bfpm1kr20kh5kpdsaf5c7-unit-nginx.service.drv' building '/nix/store/kj76ycy9nzx0jn0rw9z5q9f1bw34i7db-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/1qag1wxymr8hvp8par8bmzljj0q86p5j-system-generators.drv' unit-nginx.service> structuredAttrs is enabled unit-nginx.service> structuredAttrs is enabled building '/nix/store/av8fv1sm41dfnyywxlqdzfh3mhn2sn0l-system-shutdown.drv' building '/nix/store/36hmmd9m408dxc87qiq720gdwbzd9s0b-unit-firewall.service.drv' building '/nix/store/jsipvb8627mhdaf8s5qyrp9x2rdyvqb8-unit-step-ca.service.drv' building '/nix/store/013b54dpzbclf291zrksw3ffh5r2201d-user-generators.drv' building '/nix/store/l2m3kxcxhlrl4g64g5x7g059cp8k9qim-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/vs4j71wqh7m28bfw4393rzr58y8qh3cf-X-Restart-Triggers-dbus-broker.drv' unit-firewall.service> structuredAttrs is enabled unit-step-ca.service> structuredAttrs is enabled building '/nix/store/957j5jriff0n30ngjx30bws3n48cnasj-unit-dbus-broker.service.drv' building '/nix/store/bx3crrb9v65rgr20w7nssx5xa61j8mzr-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/16lvn0wg72nm8wqfyw1xhinnp780dw84-unit-dbus-broker.service.drv' building '/nix/store/c9wwc0yigaqqz9yq8pqmcq1r52ryj2bk-unit-dbus-broker.service.drv' building '/nix/store/dw36hr84igwyzv8ip7cn3mzx194ccff1-unit-dbus-broker.service.drv' building '/nix/store/ihzsj4k9jyp4rvxl0v6c6x6yk62mq5v9-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/3hzf9byn95198xbqkk25rqm6l6kni4ka-user-units.drv' building '/nix/store/hfv3flqgbxxq2v8an2nji07lmrinb0ah-user-units.drv' building '/nix/store/xj67g54srsv4whsd8jz4zj9nhy2q9jd9-user-units.drv' building '/nix/store/msvcmqhmajssll92gjai5phf8jw6pyac-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/v878yqsa9qmb2qrrql661rc9hlfrnxsb-nss-cacert-3.126.drv' nss-cacert-3.126> structuredAttrs is enabled nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase building '/nix/store/g95x9vr6y35z9c0ijprbinn29p5b6f0r-decrypt-age-secrets.drv' building '/nix/store/ay571wbv71j47ly318g75adsgamj7hs5-dry-activate.drv' nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/by1vplmdkm0kw0yqf3zg2nw2jyblrshk-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/by1vplmdkm0kw0yqf3zg2nw2jyblrshk-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/by1vplmdkm0kw0yqf3zg2nw2jyblrshk-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/ppmqlpxpbi5h6chy7cnc5jwn7a3qhn37-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/ppmqlpxpbi5h6chy7cnc5jwn7a3qhn37-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/ppmqlpxpbi5h6chy7cnc5jwn7a3qhn37-nss-cacert-3.126-hashed nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/dcqggnf7rll07ymnnd571iil7b7w5vj3-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/dcqggnf7rll07ymnnd571iil7b7w5vj3-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/dcqggnf7rll07ymnnd571iil7b7w5vj3-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/nsn2fif61njpgk8404b9gzvzq8agds04-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/nsn2fif61njpgk8404b9gzvzq8agds04-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/nsn2fif61njpgk8404b9gzvzq8agds04-nss-cacert-3.126-unbundled building '/nix/store/ln019j1z90w8hkf9v4cgjxsp9mbi8j7x-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled building '/nix/store/2qxfy1r7wbkv8ip5ihw20z8yxpzdybsi-system-units.drv' building '/nix/store/55wgk4x584cy5hps2vxjd1l7xh5i69jy-system-units.drv' building '/nix/store/9lbjcmr1p60p2n9wcdd06lyw9428xs3n-system-units.drv' building '/nix/store/9dawl1m1711higgv7zs3gvqjxnpx0ljf-etc.drv' building '/nix/store/2svmdbnv87axqjd120djn6cnmw54xilr-etc.drv' building '/nix/store/xhvxpg5nlqqmgn30yvaas9vf38dd1z18-etc.drv' building '/nix/store/p3g9b9lyy1f6cqvp3yglvdrnr6bqyf8r-activate.drv' building '/nix/store/0d6bih54gql81ng4994ah2bwciynsazn-activate.drv' building '/nix/store/sjx52nspqh7kjpy60irbs7mn923j582s-activate.drv' building '/nix/store/df5mlw4b2zncpdjwlgf9vpl2m8grq7a9-nixos-system-client-test.drv' building '/nix/store/ks8rl9mw8adhpl1jl9fl836m8fly008c-nixos-system-ca-test.drv' nixos-system-client-test> structuredAttrs is enabled building '/nix/store/fm2j8mqa57zziky02hdsd9b8f2w0sl4w-nixos-system-server-test.drv' nixos-system-ca-test> structuredAttrs is enabled building '/nix/store/39fjr2797vq5lh7dmqm34qg696yhql1d-run-client-nspawn.drv' nixos-system-server-test> structuredAttrs is enabled building '/nix/store/kq8z4lglw0190hsijbmacgq9qsc7h2nh-run-ca-nspawn.drv' building '/nix/store/n31r3asb2353iy38v9afgdaqws7krlrl-run-server-nspawn.drv' building '/nix/store/4jybdid1iqsvpb2j3zn2vc27vn2bhm09-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/lm2lyj7jx3xv7f3w04iw4xdypb00ma62-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! building '/nix/store/hla48149zx7n3jy6yqax0vjl6p7q2r7w-container-test-run-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/hla48149zx7n3jy6yqax0vjl6p7q2r7w-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> ca: systemd-nspawn running (pid 53) container-test-run-certificates> server: systemd-nspawn running (pid 55) container-test-run-certificates> client: systemd-nspawn running (pid 54) container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> client # [95046.097083] client systemd-journald[69]: Journal started container-test-run-certificates> client # [95046.097111] client systemd-journald[69]: Runtime Journal (/run/log/journal/85f8280c08044e01b08b3a3d8a2b623b) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> client # [95046.099154] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [95046.103904] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [95046.104255] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [95046.104549] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [95046.109222] client systemd-journald[69]: Time spent on flushing to /var/log/journal/85f8280c08044e01b08b3a3d8a2b623b is 1.937ms for 6 entries. container-test-run-certificates> client # [95046.109222] client systemd-journald[69]: System Journal (/var/log/journal/85f8280c08044e01b08b3a3d8a2b623b) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [95046.112140] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [95046.112247] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [95046.112293] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [95046.112675] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [95046.103517] ca systemd-journald[78]: Journal started container-test-run-certificates> client # [95046.112696] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [95046.103545] ca systemd-journald[78]: Runtime Journal (/run/log/journal/e09e51c6c7cf49ad9caced8d5a4a07ac) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> client # [95046.113019] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [95046.104559] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [95046.113034] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [95046.109117] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [95046.115976] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [95046.109504] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [95046.116566] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [95046.109775] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [95046.125847] client systemd-tmpfiles[110]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [95046.114265] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/e09e51c6c7cf49ad9caced8d5a4a07ac is 1.299ms for 6 entries. container-test-run-certificates> client # [95046.125983] client systemd-tmpfiles[110]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [95046.114265] ca systemd-journald[78]: System Journal (/var/log/journal/e09e51c6c7cf49ad9caced8d5a4a07ac) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [95046.103214] server systemd-journald[69]: Journal started container-test-run-certificates> ca # [95046.117251] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [95046.103243] server systemd-journald[69]: Runtime Journal (/run/log/journal/372c65a5e59f44bf9a1225ed81515996) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> ca # [95046.117558] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [95046.104600] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [95046.117609] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [95046.109176] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [95046.118032] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [95046.109529] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [95046.118063] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [95046.109821] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [95046.118385] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [95046.114545] server systemd-journald[69]: Time spent on flushing to /var/log/journal/372c65a5e59f44bf9a1225ed81515996 is 1.298ms for 6 entries. container-test-run-certificates> ca # [95046.118399] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [95046.114545] server systemd-journald[69]: System Journal (/var/log/journal/372c65a5e59f44bf9a1225ed81515996) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [95046.141783] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [95046.118542] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [95046.134637] client systemd-tmpfiles[110]: fchmod() of /var/log/journal/85f8280c08044e01b08b3a3d8a2b623b failed: Operation not permitted container-test-run-certificates> server # [95046.118676] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [95046.134821] client systemd-tmpfiles[110]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [95046.118718] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [95046.142152] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [95046.119128] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [95046.153370] ca systemd-tmpfiles[137]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [95046.119152] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [95046.153569] ca systemd-tmpfiles[137]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [95046.119543] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [95046.153696] ca systemd-tmpfiles[137]: fchmod() of /var/log/journal/e09e51c6c7cf49ad9caced8d5a4a07ac failed: Operation not permitted container-test-run-certificates> server # [95046.119558] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [95046.153874] ca systemd-tmpfiles[137]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [95046.138102] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [95046.154981] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [95046.138901] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [95046.155489] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [95046.152169] server systemd-tmpfiles[128]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [95046.156083] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [95046.152323] server systemd-tmpfiles[128]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [95046.157749] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [95046.152427] server systemd-tmpfiles[128]: fchmod() of /var/log/journal/372c65a5e59f44bf9a1225ed81515996 failed: Operation not permitted container-test-run-certificates> ca # [95046.161860] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [95046.152576] server systemd-tmpfiles[128]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [95046.167302] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [95046.153730] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [95046.167689] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [95046.154374] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [95046.172418] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [95046.154785] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [95046.199313] ca systemd[1]: Finished Firewall. container-test-run-certificates> client # [95046.135916] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [95046.199392] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [95046.158220] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [95046.199516] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [95046.160786] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [95046.199916] ca systemd[1]: Starting Network Management... container-test-run-certificates> server # [95046.166888] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [95046.136565] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [95046.167339] server systemd[1]: Starting Update is Completed... container-test-run-certificates> client # [95046.136866] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [95046.171759] server systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [95046.148246] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [95046.191397] server systemd[1]: Finished Firewall. container-test-run-certificates> client # [95046.149064] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [95046.191476] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [95046.450672] ca systemd-networkd[196]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [95046.191601] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [95046.450731] ca systemd-networkd[196]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [95046.192019] server systemd[1]: Starting Network Management... container-test-run-certificates> ca # [95046.455639] ca systemd-networkd[196]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [95046.440790] server systemd-networkd[187]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [95046.455781] ca systemd-networkd[196]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [95046.440879] server systemd-networkd[187]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [95046.455836] ca systemd-networkd[196]: lo: Link UP container-test-run-certificates> server # [95046.446248] server systemd-networkd[187]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [95046.455840] ca systemd-networkd[196]: lo: Gained carrier container-test-run-certificates> server # [95046.446390] server systemd-networkd[187]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [95046.455965] ca systemd-networkd[196]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [95046.446456] server systemd-networkd[187]: lo: Link UP container-test-run-certificates> ca # [95046.456178] ca systemd[1]: Started Network Management. container-test-run-certificates> server # [95046.446459] server systemd-networkd[187]: lo: Gained carrier container-test-run-certificates> ca # [95046.456250] ca systemd-networkd[196]: eth1: Link UP container-test-run-certificates> server # [95046.446583] server systemd-networkd[187]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [95046.456388] ca systemd-networkd[196]: eth1: Gained carrier container-test-run-certificates> server # [95046.446840] server systemd[1]: Started Network Management. container-test-run-certificates> ca # [95046.456619] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [95046.149576] client systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [95046.456138] server systemd-networkd[187]: eth1: Link UP container-test-run-certificates> ca # [95046.474181] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [95046.456396] server systemd-networkd[187]: eth1: Gained carrier container-test-run-certificates> ca # [95046.594880] ca systemd-resolved[100]: Positive Trust Anchors: container-test-run-certificates> server # [95046.456510] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [95046.594886] ca systemd-resolved[100]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [95046.473196] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [95046.594889] ca systemd-resolved[100]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [95046.592743] server systemd-resolved[92]: Positive Trust Anchors: container-test-run-certificates> ca # [95046.594905] ca systemd-resolved[100]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [95046.592748] server systemd-resolved[92]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [95046.604604] ca systemd-resolved[100]: Using system hostname 'ca'. container-test-run-certificates> server # [95046.592751] server systemd-resolved[92]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [95046.605423] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [95046.592767] server systemd-resolved[92]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [95046.605468] ca systemd[1]: Reached target Network. container-test-run-certificates> server # [95046.603849] server systemd-resolved[92]: Using system hostname 'server'. container-test-run-certificates> ca # [95046.605501] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [95046.604655] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [95046.605525] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [95046.604694] server systemd[1]: Reached target Network. container-test-run-certificates> ca # [95046.605657] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> server # [95046.604721] server systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [95046.605675] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [95046.604744] server systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [95046.605690] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [95046.604857] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> ca # [95046.605699] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [95046.604870] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [95046.605764] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [95046.604884] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [95046.605814] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [95046.604894] server systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [95046.605882] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [95046.604957] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [95046.605892] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [95046.605013] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [95046.605911] ca systemd[1]: Reached target Basic System. container-test-run-certificates> server # [95046.605076] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [95046.610807] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [95046.605086] server systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [95046.611137] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [95046.605106] server systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [95046.611159] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> server # [95046.610716] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [95046.611589] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [95046.611027] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [95046.612172] ca systemd[1]: Starting step-ca service... container-test-run-certificates> server # [95046.611045] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> ca # [95046.612764] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [95046.611392] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [95046.621188] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [95046.612023] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [95046.154734] client systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [95046.620576] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [95046.158194] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [95046.183541] client systemd[1]: Finished Firewall. container-test-run-certificates> client # [95046.183623] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [95046.183750] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [95046.184289] client systemd[1]: Starting Network Management... container-test-run-certificates> client # [95046.435879] client systemd-networkd[183]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [95046.435947] client systemd-networkd[183]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [95046.440722] client systemd-networkd[183]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [95046.440858] client systemd-networkd[183]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [95046.440932] client systemd-networkd[183]: lo: Link UP container-test-run-certificates> client # [95046.440935] client systemd-networkd[183]: lo: Gained carrier container-test-run-certificates> client # [95046.441066] client systemd-networkd[183]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [95046.441306] client systemd[1]: Started Network Management. container-test-run-certificates> client # [95046.441358] client systemd-networkd[183]: eth1: Link UP container-test-run-certificates> client # [95046.441496] client systemd-networkd[183]: eth1: Gained carrier container-test-run-certificates> client # [95046.441944] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [95046.459760] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [95046.580190] client systemd-resolved[92]: Positive Trust Anchors: container-test-run-certificates> client # [95046.580195] client systemd-resolved[92]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [95046.580199] client systemd-resolved[92]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [95046.580215] client systemd-resolved[92]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [95046.590274] client systemd-resolved[92]: Using system hostname 'client'. container-test-run-certificates> client # [95046.591052] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [95046.591089] client systemd[1]: Reached target Network. container-test-run-certificates> client # [95046.591117] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [95046.591150] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [95046.591165] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [95046.591174] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [95046.591248] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [95046.591323] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [95046.591389] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [95046.591405] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [95046.591430] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [95046.591954] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [95046.592342] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [95046.592907] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [95046.618718] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [95046.675785] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> server # [95046.675785] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [95046.675962] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> server # [95046.676579] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> server # [95046.677389] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [95046.677389] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> server # [95046.677426] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [95046.677426] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> server # [95046.683559] server nsncd[194]: Sep 05 09:41:01.106 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [95046.683598] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [95046.683624] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [95046.683650] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [95046.676098] ca acme-setup-privileged[201]: + set -euo pipefail container-test-run-certificates> ca # [95046.676098] ca acme-setup-privileged[201]: + cd /var/lib/acme container-test-run-certificates> ca # [95046.676358] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [95046.677112] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [95046.677914] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [95046.677936] ca acme-setup-privileged[201]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [95046.677936] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [95046.677936] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [95046.691325] ca nsncd[203]: Sep 05 09:41:01.114 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [95046.691364] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [95046.691408] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [95046.691443] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [95046.698678] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [95046.699021] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [95046.686982] client nsncd[189]: Sep 05 09:41:01.110 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [95046.686996] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [95046.687027] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [95046.687054] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [95046.698660] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [95046.698980] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [95046.704359] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [95046.704915] client systemd[1]: Started Console Getty. container-test-run-certificates> client # [95046.704934] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [95046.704944] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [95046.756528] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [95046.756965] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [95046.756965] client dbus-broker-launch[190]: Invalid user-name in /nix/store/icmxydgsz8d39ksbqbi94w3l6jsf5nzr-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [95046.757179] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [95046.760565] client dbus-broker-launch[190]: Ready container-test-run-certificates> server # [95046.698670] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [95046.698998] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [95046.703700] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [95046.704124] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [95046.704144] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [95046.704154] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [95046.747079] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [95046.747542] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [95046.747542] server dbus-broker-launch[195]: Invalid user-name in /nix/store/8fwk090ldbcg1sqhkr2m0q8vsr6xq7pq-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [95046.747768] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [95046.752028] server dbus-broker-launch[195]: Ready container-test-run-certificates> ca # [95046.704295] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [95046.704642] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [95046.704661] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [95046.704670] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [95046.753085] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [95046.753949] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [95046.753949] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/4vzgpfm4kzwpgh4dnhh0424yakwryx24-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [95046.754254] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [95046.757809] ca dbus-broker-launch[205]: Ready container-test-run-certificates> server # [95046.998826] server systemd-logind[220]: New seat seat0. container-test-run-certificates> server # [95046.998951] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [95046.999581] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [95047.027148] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [95047.027219] server systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [95047.043937] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> server # [95047.044100] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> server # [95047.044100] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [95047.050329] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [95047.051023] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server # [95047.096185] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [95047.019521] ca systemd-logind[231]: New seat seat0. container-test-run-certificates> ca # [95047.019613] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [95047.023504] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [95047.029901] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [95047.029943] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [95047.043677] ca acme-setup-start[218]: + set -euo pipefail container-test-run-certificates> ca # [95047.043830] ca acme-setup-start[218]: + test -e ca/key.pem container-test-run-certificates> ca # [95047.043830] ca acme-setup-start[218]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [95047.050261] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [95047.051052] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> ca # [95047.096890] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [95047.135786] ca step-ca[204]: badger 2026/09/05 09:41:01 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [95047.137591] ca step-ca[204]: 2026/09/05 09:41:01 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [95047.139569] ca step-ca[204]: 2026/09/05 09:41:01 Starting Smallstep CA/0.30.2 (linux/amd64) container-test-run-certificates> ca # [95047.139569] ca step-ca[204]: 2026/09/05 09:41:01 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [95047.139569] ca step-ca[204]: 2026/09/05 09:41:01 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [95047.139610] ca step-ca[204]: 2026/09/05 09:41:01 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [95047.139610] ca step-ca[204]: 2026/09/05 09:41:01 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [95047.139610] ca step-ca[204]: 2026/09/05 09:41:01 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [95047.139610] ca step-ca[204]: 2026/09/05 09:41:01 X.509 Root Fingerprint: 749b14c0e4c413f17709aa80520f16f28c92e9737756cd593116286a81fec7a3 container-test-run-certificates> ca # [95047.139672] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [95047.139811] ca step-ca[204]: 2026/09/05 09:41:01 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> client # [95047.000782] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [95047.000889] client systemd[1]: Started User Login Management. container-test-run-certificates> client # [95047.023180] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [95047.028629] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [95047.028695] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [95047.028898] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [95047.028979] client systemd[1]: Startup finished in 1.143s. container-test-run-certificates> client # [95047.091588] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [95047.365904] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [95047.367848] server acme-test.foo-start[245]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [95047.367848] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [95047.372111] server acme-test.foo-start[255]: + cd test.foo container-test-run-certificates> server # [95047.372295] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [95047.373434] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [95047.373598] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [95047.374311] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [95047.374430] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [95047.375400] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [95047.376232] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [95047.377139] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [95047.377157] server acme-test.foo-start[245]: + '[' -d out ']' container-test-run-certificates> server # [95047.377157] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [95047.377949] server acme-test.foo-start[245]: + chown -R acme:nginx out container-test-run-certificates> server # [95047.379463] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [95047.379463] server acme-test.foo-start[245]: + '[' -d certificates ']' container-test-run-certificates> server # [95047.381028] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [95047.381830] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [95047.370756] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [95047.372383] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [95047.372406] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [95047.377043] ca acme-ca.foo-start[282]: + cd ca.foo container-test-run-certificates> ca # [95047.377288] ca acme-ca.foo-start[282]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [95047.377822] ca acme-ca.foo-start[283]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [95047.377956] ca acme-ca.foo-start[282]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [95047.378841] ca acme-ca.foo-start[282]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [95047.378986] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [95047.379967] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [95047.381111] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [95047.381949] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [95047.381959] ca acme-ca.foo-start[256]: + '[' -d out ']' container-test-run-certificates> ca # [95047.381959] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [95047.382747] ca acme-ca.foo-start[256]: + chown -R acme:nginx out container-test-run-certificates> ca # [95047.384137] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [95047.384137] ca acme-ca.foo-start[256]: + '[' -d certificates ']' container-test-run-certificates> ca # [95047.400102] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [95047.400826] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [95047.727865] ca nginx-pre-start[294]: nginx: the configuration file /nix/store/5k95ifqn7q5y9s48ra8xl4jc2qhvz4qh-nginx.conf syntax is ok container-test-run-certificates> ca # [95047.728088] ca nginx-pre-start[294]: nginx: configuration file /nix/store/5k95ifqn7q5y9s48ra8xl4jc2qhvz4qh-nginx.conf test is successful container-test-run-certificates> ca # [95047.736190] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [95047.736393] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [95047.736989] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca # [95047.808099] ca systemd-networkd[196]: eth1: Gained IPv6LL container-test-run-certificates> server # [95047.716464] server nginx-pre-start[267]: nginx: the configuration file /nix/store/azxra0kwyr9l6lycxi5yqm3sirghcz7b-nginx.conf syntax is ok container-test-run-certificates> server # [95047.716663] server nginx-pre-start[267]: nginx: configuration file /nix/store/azxra0kwyr9l6lycxi5yqm3sirghcz7b-nginx.conf test is successful container-test-run-certificates> server # [95047.718894] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [95047.719083] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [95047.719659] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [95048.068706] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [95048.070697] server acme-order-renew-test.foo-start[270]: + set -euo pipefail container-test-run-certificates> server # [95048.070770] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [95048.070789] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [95048.071589] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [95048.081676] server acme-order-renew-test.foo-start[282]: 2026/09/05 09:41:02 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [95048.081900] server acme-order-renew-test.foo-start[282]: 2026/09/05 09:41:02 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> server # [95048.094540] server acme-order-renew-test.foo-start[282]: 2026/09/05 09:41:02 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [95048.094743] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [95048.094780] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [95048.094780] server acme-order-renew-test.foo-start[270]: + exit 10 container-test-run-certificates> server # [95048.096167] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [95048.096247] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [95048.096416] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [95048.096583] server systemd[1]: Startup finished in 2.211s. container-test-run-certificates> server # [95048.257082] server systemd-networkd[187]: eth1: Gained IPv6LL container-test-run-certificates> ca # [95048.063711] ca acme-order-renew-ca.foo-start[297]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [95048.065438] ca acme-order-renew-ca.foo-start[297]: + set -euo pipefail container-test-run-certificates> ca # [95048.065476] ca acme-order-renew-ca.foo-start[297]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [95048.065531] ca acme-order-renew-ca.foo-start[297]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [95048.066142] ca acme-order-renew-ca.foo-start[297]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [95048.076254] ca acme-order-renew-ca.foo-start[308]: 2026/09/05 09:41:02 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [95048.076424] ca acme-order-renew-ca.foo-start[308]: 2026/09/05 09:41:02 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [95048.088822] ca step-ca[204]: time="2026-09-05T09:41:02Z" level=info duration="107.422µs" duration-ns=107422 fields.time="2026-09-05T09:41:02Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=044c5068-70e3-4c70-b83d-a5a96c4236f3 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [95048.088988] ca acme-order-renew-ca.foo-start[308]: 2026/09/05 09:41:02 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [95048.090114] ca step-ca[204]: time="2026-09-05T09:41:02Z" level=info duration=1.01928ms duration-ns=1019280 fields.time="2026-09-05T09:41:02Z" method=HEAD name=ca nonce=Q3BQeXpBOTI5RnZ4VVBnNlhvcUxCTHFXTWUyOTFYb0I path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=5a4a5668-7e39-4e51-8d43-2101d4e9242e size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [95048.091301] ca step-ca[204]: time="2026-09-05T09:41:02Z" level=info duration="923.5µs" duration-ns=923500 fields.time="2026-09-05T09:41:02Z" method=POST name=ca nonce=UnQ4Vk1UbUZYeFh0dGZ2cXlIVk1uVDNDakh4clRzamc path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=5938c503-fb93-4208-a0f0-c1afcdf7046c response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/SkgPYn3T7aO5UbFY4JdyXLbaYQ5Duq9C/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [95048.091428] ca acme-order-renew-ca.foo-start[308]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [95048.091428] ca acme-order-renew-ca.foo-start[308]: Your account credentials have been saved in your container-test-run-certificates> ca # [95048.091428] ca acme-order-renew-ca.foo-start[308]: configuration directory at "accounts". container-test-run-certificates> ca # [95048.091428] ca acme-order-renew-ca.foo-start[308]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [95048.091428] ca acme-order-renew-ca.foo-start[308]: configuration directory will also contain private keys container-test-run-certificates> ca # [95048.091428] ca acme-order-renew-ca.foo-start[308]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [95048.091428] ca acme-order-renew-ca.foo-start[308]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [95048.091507] ca acme-order-renew-ca.foo-start[308]: 2026/09/05 09:41:02 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [95048.092872] ca step-ca[204]: time="2026-09-05T09:41:02Z" level=info duration=1.272306ms duration-ns=1272306 fields.time="2026-09-05T09:41:02Z" method=POST name=ca nonce=elJvaFRHS3VDT3BWbldQcjZVdlJ2NUh3aG1tUng5S3M path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=f27ba523-d86a-4749-b784-116bdbf05ee8 response="{\"id\":\"RwGwU2sbRmynZ4IoG5V11brTAWnKRtWc\",\"status\":\"pending\",\"expires\":\"2026-09-06T09:41:02Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-09-05T09:40:02Z\",\"notAfter\":\"2026-12-04T09:41:02Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/5Y4VbpQxIImAAS22PmqYPSHAp5GJxk3T\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/RwGwU2sbRmynZ4IoG5V11brTAWnKRtWc/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [95048.149911] ca step-ca[204]: time="2026-09-05T09:41:02Z" level=info duration="706.22µs" duration-ns=706220 fields.time="2026-09-05T09:41:02Z" method=POST name=ca nonce=QW9CQlc3SnZmUUJxTjVWV1RJRk80NzI5NjNzSTRHTHA path=/acme/acme/authz/5Y4VbpQxIImAAS22PmqYPSHAp5GJxk3T protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=19643f5d-d3a0-4520-92e8-897fc91080e1 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"OsyRm32cxXyhcdHg0MX7o897YU8qh1JU\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/5Y4VbpQxIImAAS22PmqYPSHAp5GJxk3T/XFxZtxCPg25V6NWzHwqN6VXAW4pc1GmC\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"OsyRm32cxXyhcdHg0MX7o897YU8qh1JU\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/5Y4VbpQxIImAAS22PmqYPSHAp5GJxk3T/5cPfWfvblkqlJbEuxwglfxuRwJsvyoIZ\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"OsyRm32cxXyhcdHg0MX7o897YU8qh1JU\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/5Y4VbpQxIImAAS22PmqYPSHAp5GJxk3T/04UJ8GbJGPfCsXMt7yhFASjcQFUTbuSJ\"}],\"wildcard\":false,\"expires\":\"2026-09-06T09:41:02Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [95048.150191] ca acme-order-renew-ca.foo-start[308]: 2026/09/05 09:41:02 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/5Y4VbpQxIImAAS22PmqYPSHAp5GJxk3T container-test-run-certificates> ca # [95048.150191] ca acme-order-renew-ca.foo-start[308]: 2026/09/05 09:41:02 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [95048.150191] ca acme-order-renew-ca.foo-start[308]: 2026/09/05 09:41:02 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [95048.150191] ca acme-order-renew-ca.foo-start[308]: 2026/09/05 09:41:02 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [95048.151760] ca step-ca[204]: time="2026-09-05T09:41:02Z" level=info duration=1.561862ms duration-ns=1561862 fields.time="2026-09-05T09:41:02Z" method=POST name=ca nonce=T2FDTlBrVFlUYU9rMFZDcEh1bHB2WVVoVWZmbUhpY04 path=/acme/acme/challenge/5Y4VbpQxIImAAS22PmqYPSHAp5GJxk3T/5cPfWfvblkqlJbEuxwglfxuRwJsvyoIZ protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=2c895ed0-4531-495d-b4f3-ea9874966b3b response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"OsyRm32cxXyhcdHg0MX7o897YU8qh1JU\",\"validated\":\"2026-09-05T09:41:02Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/5Y4VbpQxIImAAS22PmqYPSHAp5GJxk3T/5cPfWfvblkqlJbEuxwglfxuRwJsvyoIZ\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [95048.151854] ca acme-order-renew-ca.foo-start[308]: 2026/09/05 09:41:02 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [95048.151876] ca acme-order-renew-ca.foo-start[308]: 2026/09/05 09:41:02 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [95048.154142] ca step-ca[204]: time="2026-09-05T09:41:02Z" level=info duration=2.005166ms duration-ns=2005166 fields.time="2026-09-05T09:41:02Z" method=POST name=ca nonce=c2xZZDFTZFNOZHFZZTNGeXdMbWN5TGd6WVNPUWZhdDU path=/acme/acme/order/RwGwU2sbRmynZ4IoG5V11brTAWnKRtWc/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=e1557b8f-93ba-41a4-97e6-8d70694d37ea response="{\"id\":\"RwGwU2sbRmynZ4IoG5V11brTAWnKRtWc\",\"status\":\"valid\",\"expires\":\"2026-09-06T09:41:02Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-09-05T09:40:02Z\",\"notAfter\":\"2026-12-04T09:41:02Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/5Y4VbpQxIImAAS22PmqYPSHAp5GJxk3T\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/RwGwU2sbRmynZ4IoG5V11brTAWnKRtWc/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/9idrTFzAOriNJ2rsE8fhzMsOIRoKq1xs\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [95048.154780] ca step-ca[204]: time="2026-09-05T09:41:02Z" level=info certificate="MIIB0jCCAXmgAwIBAgIQWmXUx5Tzwm73tlCV/Vm9HzAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA5MDUwOTQwMDJaFw0yNjEyMDQwOTQxMDJaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABJ9hSUe3915O4jGS39Plbej7lUQ6qApVepSb1PLVUTdLjU0Tct+KOKmFcnFvyEbznzG8hpH4c4hGq8AdbfOhXYajgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUxRhx97HnmN4Dk9SsqzbKqxzyC+wwHwYDVR0jBBgwFoAUWeywRXsJSmtGcdSQxlb4HdSZBakwEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNHADBEAiAOCsp6s1IlSo1kFoPjL5mxFGj+3vGrCRXkyE1PG6LeWQIgcFdPOlvBzOYiusLZH6DVLWEvr27uEJ8ISE8NI8v4+Hc=" duration="446.971µs" duration-ns=446971 fields.time="2026-09-05T09:41:02Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=MTZleDROMmluVElwODEzR3pRY0NiZE1UdU5UaGo1NHE path=/acme/acme/certificate/9idrTFzAOriNJ2rsE8fhzMsOIRoKq1xs protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=7023d90e-0ad2-400b-b943-0698f5595bf3 sans="map[dns:[ca.foo]]" serial=120159257286693229258371766145204731167 size=1340 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-09-05T09:40:02Z" valid-to="2026-12-04T09:41:02Z" container-test-run-certificates> ca # [95048.154872] ca acme-order-renew-ca.foo-start[308]: 2026/09/05 09:41:02 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [95048.157433] ca acme-order-renew-ca.foo-start[297]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [95048.158506] ca acme-order-renew-ca.foo-start[297]: + touch out/acme-success container-test-run-certificates> ca # [95048.159301] ca acme-order-renew-ca.foo-start[297]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [95048.160046] ca acme-order-renew-ca.foo-start[297]: + touch out/renewed container-test-run-certificates> ca # [95048.160934] ca acme-order-renew-ca.foo-start[297]: + echo Installing new certificate container-test-run-certificates> ca # [95048.160934] ca acme-order-renew-ca.foo-start[297]: Installing new certificate container-test-run-certificates> ca # [95048.160964] ca acme-order-renew-ca.foo-start[297]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [95048.162022] ca acme-order-renew-ca.foo-start[329]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [95048.162176] ca acme-order-renew-ca.foo-start[297]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [95048.162860] ca acme-order-renew-ca.foo-start[330]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [95048.162978] ca acme-order-renew-ca.foo-start[297]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [95048.163967] ca acme-order-renew-ca.foo-start[331]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [95048.164146] ca acme-order-renew-ca.foo-start[297]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [95048.164996] ca acme-order-renew-ca.foo-start[297]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [95048.165881] ca acme-order-renew-ca.foo-start[297]: + for fixpath in out certificates container-test-run-certificates> ca # [95048.165897] ca acme-order-renew-ca.foo-start[297]: + '[' -d out ']' container-test-run-certificates> ca # [95048.165897] ca acme-order-renew-ca.foo-start[297]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [95048.166722] ca acme-order-renew-ca.foo-start[297]: + chown -R acme:nginx out container-test-run-certificates> ca # [95048.168073] ca acme-order-renew-ca.foo-start[297]: + for fixpath in out certificates container-test-run-certificates> ca # [95048.168084] ca acme-order-renew-ca.foo-start[297]: + '[' -d certificates ']' container-test-run-certificates> ca # [95048.168084] ca acme-order-renew-ca.foo-start[297]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [95048.168883] ca acme-order-renew-ca.foo-start[297]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [95048.170084] ca acme-order-renew-ca.foo-start[297]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [95048.237110] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [95048.239150] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [95048.239243] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> client # [95048.257144] client systemd-networkd[183]: eth1: Gained IPv6LL container-test-run-certificates> ca # [95048.578576] ca nginx[347]: nginx: the configuration file /nix/store/5k95ifqn7q5y9s48ra8xl4jc2qhvz4qh-nginx.conf syntax is ok container-test-run-certificates> ca # [95048.578793] ca nginx[347]: nginx: configuration file /nix/store/5k95ifqn7q5y9s48ra8xl4jc2qhvz4qh-nginx.conf test is successful container-test-run-certificates> ca # [95048.916483] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [95048.916641] ca systemd[1]: Startup finished in 3.023s. container-test-run-certificates> ca # [95048.950750] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 0.76 seconds) container-test-run-certificates> ca # [95049.286711] ca acme-order-renew-ca.foo-start[362]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [95049.288609] ca acme-order-renew-ca.foo-start[362]: + set -euo pipefail container-test-run-certificates> ca # [95049.288678] ca acme-order-renew-ca.foo-start[362]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [95049.288697] ca acme-order-renew-ca.foo-start[362]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [95049.289436] ca acme-order-renew-ca.foo-start[362]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [95049.289465] ca acme-order-renew-ca.foo-start[362]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [95049.289651] ca acme-order-renew-ca.foo-start[370]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [95049.291164] ca acme-order-renew-ca.foo-start[362]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [95049.291190] ca acme-order-renew-ca.foo-start[362]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [95049.312309] ca step-ca[204]: time="2026-09-05T09:41:03Z" level=info duration="42.289µs" duration-ns=42289 fields.time="2026-09-05T09:41:03Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=f97d0b41-e7a0-4744-bb5c-e97e9d4cd9e1 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [95049.312551] ca acme-order-renew-ca.foo-start[371]: 2026/09/05 09:41:03 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [95049.312551] ca acme-order-renew-ca.foo-start[371]: 2026/09/05 09:41:03 [INFO] [ca.foo] The certificate expires at 2026-12-04T09:41:02Z, the renewal can be performed in 1439h59m38.26422598s: no renewal. container-test-run-certificates> ca # [95049.312655] ca acme-order-renew-ca.foo-start[362]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [95049.313767] ca acme-order-renew-ca.foo-start[362]: + touch out/acme-success container-test-run-certificates> ca # [95049.314585] ca acme-order-renew-ca.foo-start[362]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [95049.315259] ca acme-order-renew-ca.foo-start[362]: + for fixpath in out certificates container-test-run-certificates> ca # [95049.315271] ca acme-order-renew-ca.foo-start[362]: + '[' -d out ']' container-test-run-certificates> ca # [95049.315271] ca acme-order-renew-ca.foo-start[362]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [95049.316115] ca acme-order-renew-ca.foo-start[362]: + chown -R acme:nginx out container-test-run-certificates> ca # [95049.317583] ca acme-order-renew-ca.foo-start[362]: + for fixpath in out certificates container-test-run-certificates> ca # [95049.317594] ca acme-order-renew-ca.foo-start[362]: + '[' -d certificates ']' container-test-run-certificates> ca # [95049.317604] ca acme-order-renew-ca.foo-start[362]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [95049.318541] ca acme-order-renew-ca.foo-start[362]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [95049.319971] ca acme-order-renew-ca.foo-start[362]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [95049.384470] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [95049.384592] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [95052.391991] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [95052.392132] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [95052.392702] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [95052.393475] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.38 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 5 09:41:01 2026 GMT container-test-run-certificates> * expire date: Oct 5 09:41:01 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 77a945 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [95052.747588] server acme-test.foo-start[304]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [95052.749285] server acme-test.foo-start[304]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [95052.749285] server acme-test.foo-start[304]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [95052.753983] server acme-test.foo-start[314]: + cd test.foo container-test-run-certificates> server # [95052.754170] server acme-test.foo-start[314]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [95052.754998] server acme-test.foo-start[315]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [95052.755157] server acme-test.foo-start[314]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [95052.755855] server acme-test.foo-start[314]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [95052.756014] server acme-test.foo-start[304]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [95052.756972] server acme-test.foo-start[304]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [95052.757839] server acme-test.foo-start[304]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [95052.758702] server acme-test.foo-start[304]: + for fixpath in out certificates container-test-run-certificates> server # [95052.758713] server acme-test.foo-start[304]: + '[' -d out ']' container-test-run-certificates> server # [95052.758723] server acme-test.foo-start[304]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [95052.759577] server acme-test.foo-start[304]: + chown -R acme:nginx out container-test-run-certificates> server # [95052.761144] server acme-test.foo-start[304]: + for fixpath in out certificates container-test-run-certificates> server # [95052.761144] server acme-test.foo-start[304]: + '[' -d certificates ']' container-test-run-certificates> server # [95052.762484] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [95052.764142] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [95053.098210] server acme-order-renew-test.foo-start[322]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [95053.099850] server acme-order-renew-test.foo-start[322]: + set -euo pipefail container-test-run-certificates> server # [95053.099886] server acme-order-renew-test.foo-start[322]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [95053.099965] server acme-order-renew-test.foo-start[322]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [95053.100677] server acme-order-renew-test.foo-start[322]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [95053.123824] server acme-order-renew-test.foo-start[330]: 2026/09/05 09:41:07 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [95053.136973] server acme-order-renew-test.foo-start[330]: !!!! HEADS UP !!!! container-test-run-certificates> server # [95053.136973] server acme-order-renew-test.foo-start[330]: Your account credentials have been saved in your container-test-run-certificates> server # [95053.136973] server acme-order-renew-test.foo-start[330]: configuration directory at "accounts". container-test-run-certificates> server # [95053.136973] server acme-order-renew-test.foo-start[330]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [95053.136973] server acme-order-renew-test.foo-start[330]: configuration directory will also contain private keys container-test-run-certificates> server # [95053.136973] server acme-order-renew-test.foo-start[330]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [95053.136973] server acme-order-renew-test.foo-start[330]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [95053.137098] server acme-order-renew-test.foo-start[330]: 2026/09/05 09:41:07 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [95053.197188] server acme-order-renew-test.foo-start[330]: 2026/09/05 09:41:07 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/86cPVFjqgnpFw6ihjbJpF8ohK8IMC4yz container-test-run-certificates> server # [95053.197188] server acme-order-renew-test.foo-start[330]: 2026/09/05 09:41:07 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [95053.197188] server acme-order-renew-test.foo-start[330]: 2026/09/05 09:41:07 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [95053.197280] server acme-order-renew-test.foo-start[330]: 2026/09/05 09:41:07 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [95053.199653] server acme-order-renew-test.foo-start[330]: 2026/09/05 09:41:07 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [95053.199678] server acme-order-renew-test.foo-start[330]: 2026/09/05 09:41:07 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [95053.203245] server acme-order-renew-test.foo-start[330]: 2026/09/05 09:41:07 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [95053.205440] server acme-order-renew-test.foo-start[322]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [95053.206568] server acme-order-renew-test.foo-start[322]: + touch out/acme-success container-test-run-certificates> server # [95053.207518] server acme-order-renew-test.foo-start[322]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [95053.208156] server acme-order-renew-test.foo-start[322]: + touch out/renewed container-test-run-certificates> server # [95053.208973] server acme-order-renew-test.foo-start[322]: + echo Installing new certificate container-test-run-certificates> server # [95053.208973] server acme-order-renew-test.foo-start[322]: Installing new certificate container-test-run-certificates> server # [95053.208991] server acme-order-renew-test.foo-start[322]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [95053.210014] server acme-order-renew-test.foo-start[351]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [95053.210156] server acme-order-renew-test.foo-start[322]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [95053.210896] server acme-order-renew-test.foo-start[352]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [95053.211024] server acme-order-renew-test.foo-start[322]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [95053.211874] server acme-order-renew-test.foo-start[353]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [95053.212030] server acme-order-renew-test.foo-start[322]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [95053.212865] server acme-order-renew-test.foo-start[322]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [95053.213866] server acme-order-renew-test.foo-start[322]: + for fixpath in out certificates container-test-run-certificates> server # [95053.213890] server acme-order-renew-test.foo-start[322]: + '[' -d out ']' container-test-run-certificates> server # [95053.213890] server acme-order-renew-test.foo-start[322]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [95053.214841] server acme-order-renew-test.foo-start[322]: + chown -R acme:nginx out container-test-run-certificates> server # [95053.216287] server acme-order-renew-test.foo-start[322]: + for fixpath in out certificates container-test-run-certificates> server # [95053.216312] server acme-order-renew-test.foo-start[322]: + '[' -d certificates ']' container-test-run-certificates> server # [95053.216312] server acme-order-renew-test.foo-start[322]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [95053.217181] server acme-order-renew-test.foo-start[322]: + chown -R acme:nginx certificates container-test-run-certificates> server # [95053.218558] server acme-order-renew-test.foo-start[322]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> server # [95053.296880] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [95053.299154] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [95053.299314] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> ca # [95053.123601] ca step-ca[204]: time="2026-09-05T09:41:07Z" level=info duration="32.271µs" duration-ns=32271 fields.time="2026-09-05T09:41:07Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=bca9091c-a3a5-4b5b-8bbf-5cf2ba60d918 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [95053.135156] ca step-ca[204]: time="2026-09-05T09:41:07Z" level=info duration=10.495837ms duration-ns=10495837 fields.time="2026-09-05T09:41:07Z" method=HEAD name=ca nonce=a1lZZkZBNGFlcGRkcnhyM2pJRVhlbWJ2N3QwTmVZajQ path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=ef7e3259-857b-4cb8-b000-dff9788797c4 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [95053.136790] ca step-ca[204]: time="2026-09-05T09:41:07Z" level=info duration="780.28µs" duration-ns=780280 fields.time="2026-09-05T09:41:07Z" method=POST name=ca nonce=N0d3dndxT1pPMDdSbGF0UjBOTWh6SjRablFEYUFYb04 path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=0407d6bc-6415-470d-8263-d819708b325b response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/zSUMwXrxI4tqM4N0Xvm96pwa0VyISemL/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [95053.138984] ca step-ca[204]: time="2026-09-05T09:41:07Z" level=info duration=1.276313ms duration-ns=1276313 fields.time="2026-09-05T09:41:07Z" method=POST name=ca nonce=SUsyYWdKOWF2THBEVXRCOWRPS2tTZFo5blBHcVA5ZGk path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=800a6cce-df1f-4ffd-a4b4-0c2fcb781504 response="{\"id\":\"iCVshQUqKXjy2UsjAfdtATAitapu5Udi\",\"status\":\"pending\",\"expires\":\"2026-09-06T09:41:07Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-09-05T09:40:07Z\",\"notAfter\":\"2026-12-04T09:41:07Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/86cPVFjqgnpFw6ihjbJpF8ohK8IMC4yz\"],\"finalize\":\"https://ca.foo/acme/acme/order/iCVshQUqKXjy2UsjAfdtATAitapu5Udi/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [95053.196965] ca step-ca[204]: time="2026-09-05T09:41:07Z" level=info duration="944.87µs" duration-ns=944870 fields.time="2026-09-05T09:41:07Z" method=POST name=ca nonce=Qm53bnVpQTJRbHF5WWlLOGh0M0VRTHNlR2s5bUFLRG4 path=/acme/acme/authz/86cPVFjqgnpFw6ihjbJpF8ohK8IMC4yz protocol=HTTP/1.1 referer= remote-address="::1" request-id=9fe403b3-9476-4ce0-b09d-20f2346ebd60 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"RIWWXM4OJcLUIvMQPsQozDF6Uj2SPPUg\",\"url\":\"https://ca.foo/acme/acme/challenge/86cPVFjqgnpFw6ihjbJpF8ohK8IMC4yz/tWpCpPa3nJZYcTRLr0zwUWY0IDKiJaX3\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"RIWWXM4OJcLUIvMQPsQozDF6Uj2SPPUg\",\"url\":\"https://ca.foo/acme/acme/challenge/86cPVFjqgnpFw6ihjbJpF8ohK8IMC4yz/tiFyZLd4tVa3saT6NO130Nxcs8s3hoK9\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"RIWWXM4OJcLUIvMQPsQozDF6Uj2SPPUg\",\"url\":\"https://ca.foo/acme/acme/challenge/86cPVFjqgnpFw6ihjbJpF8ohK8IMC4yz/r4Cswis8pCyytD2gvZ4dAcPML0hFEQ2U\"}],\"wildcard\":false,\"expires\":\"2026-09-06T09:41:07Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [95053.199512] ca step-ca[204]: time="2026-09-05T09:41:07Z" level=info duration=1.445412ms duration-ns=1445412 fields.time="2026-09-05T09:41:07Z" method=POST name=ca nonce=enpIT1ZMWkxjU0R0NWo1dEFKOU1RaVV0WENPUDBDNWM path=/acme/acme/challenge/86cPVFjqgnpFw6ihjbJpF8ohK8IMC4yz/tiFyZLd4tVa3saT6NO130Nxcs8s3hoK9 protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=b4a428c9-8c7a-4539-8ab9-54c4038f38a8 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"RIWWXM4OJcLUIvMQPsQozDF6Uj2SPPUg\",\"validated\":\"2026-09-05T09:41:07Z\",\"url\":\"https://ca.foo/acme/acme/challenge/86cPVFjqgnpFw6ihjbJpF8ohK8IMC4yz/tiFyZLd4tVa3saT6NO130Nxcs8s3hoK9\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [95053.202026] ca step-ca[204]: time="2026-09-05T09:41:07Z" level=info duration=1.618658ms duration-ns=1618658 fields.time="2026-09-05T09:41:07Z" method=POST name=ca nonce=M01sS1ZENWZmQUdkY29MN25rekU0dlNmUEc1VGJkM1Q path=/acme/acme/order/iCVshQUqKXjy2UsjAfdtATAitapu5Udi/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=d1d129cc-ace0-4193-8888-f5271a2ad9b1 response="{\"id\":\"iCVshQUqKXjy2UsjAfdtATAitapu5Udi\",\"status\":\"valid\",\"expires\":\"2026-09-06T09:41:07Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-09-05T09:40:07Z\",\"notAfter\":\"2026-12-04T09:41:07Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/86cPVFjqgnpFw6ihjbJpF8ohK8IMC4yz\"],\"finalize\":\"https://ca.foo/acme/acme/order/iCVshQUqKXjy2UsjAfdtATAitapu5Udi/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/PXyxYH7w4IGz69yyhRbSL141pobTsS29\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [95053.203109] ca step-ca[204]: time="2026-09-05T09:41:07Z" level=info certificate="MIIB2DCCAX6gAwIBAgIRANAey+9MBegTby3vebB7VVMwCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwOTA1MDk0MDA3WhcNMjYxMjA0MDk0MTA3WjATMREwDwYDVQQDEwh0ZXN0LmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABGx7qDOzu5BLKU2+FL6JqKhDCet+2L7W4Yk+5I7haW9t5AwT8uacH9xzuPzf/svJDu9xn0aXVMinYkhdFo+Y1kijgaYwgaMwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUv8zpXg659PbeQgn5SaILjqfYhq8wHwYDVR0jBBgwFoAUWeywRXsJSmtGcdSQxlb4HdSZBakwEwYDVR0RBAwwCoIIdGVzdC5mb28wHQYMKwYBBAGCpGTGKEABBA0wCwIBBgQEYWNtZQQAMAoGCCqGSM49BAMCA0gAMEUCIQCTgb+i0+hp30PTTIvyr7CixpJp/8uLntyJ7SuKm9xLyAIgNKYL7h1tP6qh1vpHFATZ6m6nvX8LmFMZTPL/jDfFk6A=" duration="387.059µs" duration-ns=387059 fields.time="2026-09-05T09:41:07Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=QUY2c2drV3V3aUh5Szl3a1RpVTFla1JoZmF5RmZ6Zmk path=/acme/acme/certificate/PXyxYH7w4IGz69yyhRbSL141pobTsS29 protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=fc022f61-2716-4f6e-9547-98f324c60800 sans="map[dns:[test.foo]]" serial=276639328317226929914164313722424350035 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-09-05T09:40:07Z" valid-to="2026-12-04T09:41:07Z" container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 5 09:41:01 2026 GMT container-test-run-certificates> * expire date: Oct 5 09:41:01 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 77a945 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [95053.640662] server nginx[369]: nginx: the configuration file /nix/store/azxra0kwyr9l6lycxi5yqm3sirghcz7b-nginx.conf syntax is ok container-test-run-certificates> server # [95053.640925] server nginx[369]: nginx: configuration file /nix/store/azxra0kwyr9l6lycxi5yqm3sirghcz7b-nginx.conf test is successful container-test-run-certificates> server # [95053.982418] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [932 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [80 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 5 09:40:07 2026 GMT container-test-run-certificates> * expire date: Dec 4 09:41:07 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 33660 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 1955 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 2.06 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> d0:1e:cb:ef:4c:05:e8:13:6f:2d:ef:79:b0:7b:55:53 container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Sep 5 09:40:07 2026 GMT container-test-run-certificates> Not After : Dec 4 09:41:07 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:6c:7b:a8:33:b3:bb:90:4b:29:4d:be:14:be:89: container-test-run-certificates> a8:a8:43:09:eb:7e:d8:be:d6:e1:89:3e:e4:8e:e1: container-test-run-certificates> 69:6f:6d:e4:0c:13:f2:e6:9c:1f:dc:73:b8:fc:df: container-test-run-certificates> fe:cb:c9:0e:ef:71:9f:46:97:54:c8:a7:62:48:5d: container-test-run-certificates> 16:8f:98:d6:48 container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> BF:CC:E9:5E:0E:B9:F4:F6:DE:42:09:F9:49:A2:0B:8E:A7:D8:86:AF container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> 59:EC:B0:45:7B:09:4A:6B:46:71:D4:90:C6:56:F8:1D:D4:99:05:A9 container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:45:02:21:00:93:81:bf:a2:d3:e8:69:df:43:d3:4c:8b:f2: container-test-run-certificates> af:b0:a2:c6:92:69:ff:cb:8b:9e:dc:89:ed:2b:8a:9b:dc:4b: container-test-run-certificates> c8:02:20:34:a6:0b:ee:1d:6d:3f:aa:a1:d6:fa:47:14:04:d9: container-test-run-certificates> ea:6e:a7:bd:7f:0b:98:53:19:4c:f2:ff:8c:37:c5:93:a0 container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.02 seconds) container-test-run-certificates> (finished: run the VM test script, in 9.21 seconds) container-test-run-certificates> test script finished in 9.99s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 53) container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> kill NspawnMachine (pid 55) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.21 seconds) container-test-run-certificates> Container server terminated by signal KILL. post-build step Upload to niks3: ok time=2026-09-05T09:41:10.618Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-09-05T09:41:10.907Z level=INFO msg="Uploading 1 narinfos" time=2026-09-05T09:41:11.066Z level=INFO msg="Upload complete. (501ms)"