· 6 years ago · Nov 10, 2019, 04:50 AM
1letsencrypt@langermann-server:~$ acme.sh --issue -d tojolula.de --keylength 4096 -w /var/www/letsencrypt --key-file /etc/letsencrypt/tojolula.de/key.pem --ca-file /etc/letsencrypt/tojolula.de/ca.pem --cert-file /etc/letsencrypt/tojolula.de/cert.pem --fullchain-file /etc/letsencrypt/tojolula.de/fullchain.pem --debug --reloadcmd "sudo /bin/systemctl reload nginx.service"
2[So 10. Nov 05:42:50 CET 2019] Lets find script dir.
3[So 10. Nov 05:42:50 CET 2019] _SCRIPT_='/home/letsencrypt/.acme.sh/acme.sh'
4[So 10. Nov 05:42:50 CET 2019] _script='/home/letsencrypt/.acme.sh/acme.sh'
5[So 10. Nov 05:42:50 CET 2019] _script_home='/home/letsencrypt/.acme.sh'
6[So 10. Nov 05:42:50 CET 2019] Using config home:/home/letsencrypt/.acme.sh
7https://github.com/Neilpang/acme.sh
8v2.8.4
9[So 10. Nov 05:42:50 CET 2019] Running cmd: issue
10[So 10. Nov 05:42:50 CET 2019] _main_domain='tojolula.de'
11[So 10. Nov 05:42:50 CET 2019] _alt_domains='no'
12[So 10. Nov 05:42:50 CET 2019] Using config home:/home/letsencrypt/.acme.sh
13[So 10. Nov 05:42:50 CET 2019] ACME_DIRECTORY='https://acme-v02.api.letsencrypt.org/directory'
14[So 10. Nov 05:42:50 CET 2019] DOMAIN_PATH='/home/letsencrypt/.acme.sh/tojolula.de'
15[So 10. Nov 05:42:50 CET 2019] Using ACME_DIRECTORY: https://acme-v02.api.letsencrypt.org/directory
16[So 10. Nov 05:42:50 CET 2019] _init api for server: https://acme-v02.api.letsencrypt.org/directory
17[So 10. Nov 05:42:50 CET 2019] GET
18[So 10. Nov 05:42:50 CET 2019] url='https://acme-v02.api.letsencrypt.org/directory'
19[So 10. Nov 05:42:50 CET 2019] timeout=
20[So 10. Nov 05:42:50 CET 2019] _CURL='curl -L --silent --dump-header /home/letsencrypt/.acme.sh/http.header -g '
21[So 10. Nov 05:42:51 CET 2019] ret='0'
22[So 10. Nov 05:42:51 CET 2019] ACME_KEY_CHANGE='https://acme-v02.api.letsencrypt.org/acme/key-change'
23[So 10. Nov 05:42:51 CET 2019] ACME_NEW_AUTHZ
24[So 10. Nov 05:42:51 CET 2019] ACME_NEW_ORDER='https://acme-v02.api.letsencrypt.org/acme/new-order'
25[So 10. Nov 05:42:51 CET 2019] ACME_NEW_ACCOUNT='https://acme-v02.api.letsencrypt.org/acme/new-acct'
26[So 10. Nov 05:42:51 CET 2019] ACME_REVOKE_CERT='https://acme-v02.api.letsencrypt.org/acme/revoke-cert'
27[So 10. Nov 05:42:51 CET 2019] ACME_AGREEMENT='https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf'
28[So 10. Nov 05:42:51 CET 2019] ACME_NEW_NONCE='https://acme-v02.api.letsencrypt.org/acme/new-nonce'
29[So 10. Nov 05:42:51 CET 2019] ACME_VERSION='2'
30[So 10. Nov 05:42:51 CET 2019] Le_NextRenewTime
31[So 10. Nov 05:42:51 CET 2019] _on_before_issue
32[So 10. Nov 05:42:51 CET 2019] _chk_main_domain='tojolula.de'
33[So 10. Nov 05:42:51 CET 2019] _chk_alt_domains
34[So 10. Nov 05:42:51 CET 2019] Le_LocalAddress
35[So 10. Nov 05:42:51 CET 2019] d='tojolula.de'
36[So 10. Nov 05:42:51 CET 2019] Check for domain='tojolula.de'
37[So 10. Nov 05:42:51 CET 2019] _currentRoot='/var/www/letsencrypt'
38[So 10. Nov 05:42:51 CET 2019] d
39[So 10. Nov 05:42:51 CET 2019] _saved_account_key_hash is not changed, skip register account.
40[So 10. Nov 05:42:51 CET 2019] Read key length:4096
41[So 10. Nov 05:42:51 CET 2019] _createcsr
42[So 10. Nov 05:42:51 CET 2019] Single domain='tojolula.de'
43[So 10. Nov 05:42:51 CET 2019] Getting domain auth token for each domain
44[So 10. Nov 05:42:51 CET 2019] d
45[So 10. Nov 05:42:51 CET 2019] url='https://acme-v02.api.letsencrypt.org/acme/new-order'
46[So 10. Nov 05:42:51 CET 2019] payload='{"identifiers": [{"type":"dns","value":"tojolula.de"}]}'
47[So 10. Nov 05:42:51 CET 2019] RSA key
48[So 10. Nov 05:42:51 CET 2019] HEAD
49[So 10. Nov 05:42:51 CET 2019] _post_url='https://acme-v02.api.letsencrypt.org/acme/new-nonce'
50[So 10. Nov 05:42:51 CET 2019] _CURL='curl -L --silent --dump-header /home/letsencrypt/.acme.sh/http.header -g -I '
51[So 10. Nov 05:42:52 CET 2019] _ret='0'
52[So 10. Nov 05:42:52 CET 2019] POST
53[So 10. Nov 05:42:52 CET 2019] _post_url='https://acme-v02.api.letsencrypt.org/acme/new-order'
54[So 10. Nov 05:42:52 CET 2019] _CURL='curl -L --silent --dump-header /home/letsencrypt/.acme.sh/http.header -g '
55[So 10. Nov 05:42:52 CET 2019] _ret='0'
56[So 10. Nov 05:42:52 CET 2019] code='201'
57[So 10. Nov 05:42:52 CET 2019] Le_LinkOrder='https://acme-v02.api.letsencrypt.org/acme/order/71446178/1477808258'
58[So 10. Nov 05:42:52 CET 2019] Le_OrderFinalize='https://acme-v02.api.letsencrypt.org/acme/finalize/71446178/1477808258'
59[So 10. Nov 05:42:52 CET 2019] url='https://acme-v02.api.letsencrypt.org/acme/authz-v3/1168561771'
60[So 10. Nov 05:42:52 CET 2019] payload
61[So 10. Nov 05:42:53 CET 2019] POST
62[So 10. Nov 05:42:53 CET 2019] _post_url='https://acme-v02.api.letsencrypt.org/acme/authz-v3/1168561771'
63[So 10. Nov 05:42:53 CET 2019] _CURL='curl -L --silent --dump-header /home/letsencrypt/.acme.sh/http.header -g '
64[So 10. Nov 05:42:53 CET 2019] _ret='0'
65[So 10. Nov 05:42:53 CET 2019] code='200'
66[So 10. Nov 05:42:53 CET 2019] d='tojolula.de'
67[So 10. Nov 05:42:53 CET 2019] Getting webroot for domain='tojolula.de'
68[So 10. Nov 05:42:53 CET 2019] _w='/var/www/letsencrypt'
69[So 10. Nov 05:42:53 CET 2019] _currentRoot='/var/www/letsencrypt'
70[So 10. Nov 05:42:53 CET 2019] entry='"type":"http-01","status":"pending","url":"https://acme-v02.api.letsencrypt.org/acme/chall-v3/1168561771/ZVR1aw","token":"qd3ImvHJuearPsBUpNtiD9XhzMlk5qpg_j3Wk0_DnJw"'
71[So 10. Nov 05:42:53 CET 2019] token='qd3ImvHJuearPsBUpNtiD9XhzMlk5qpg_j3Wk0_DnJw'
72[So 10. Nov 05:42:53 CET 2019] uri='https://acme-v02.api.letsencrypt.org/acme/chall-v3/1168561771/ZVR1aw'
73[So 10. Nov 05:42:53 CET 2019] keyauthorization='qd3ImvHJuearPsBUpNtiD9XhzMlk5qpg_j3Wk0_DnJw.0Et1OVC42UD51nOBO5KbBgFwxmwlyrLQ4vdUn-xgIrs'
74[So 10. Nov 05:42:53 CET 2019] dvlist='tojolula.de#qd3ImvHJuearPsBUpNtiD9XhzMlk5qpg_j3Wk0_DnJw.0Et1OVC42UD51nOBO5KbBgFwxmwlyrLQ4vdUn-xgIrs#https://acme-v02.api.letsencrypt.org/acme/chall-v3/1168561771/ZVR1aw#http-01#/var/www/letsencrypt'
75[So 10. Nov 05:42:53 CET 2019] d
76[So 10. Nov 05:42:53 CET 2019] vlist='tojolula.de#qd3ImvHJuearPsBUpNtiD9XhzMlk5qpg_j3Wk0_DnJw.0Et1OVC42UD51nOBO5KbBgFwxmwlyrLQ4vdUn-xgIrs#https://acme-v02.api.letsencrypt.org/acme/chall-v3/1168561771/ZVR1aw#http-01#/var/www/letsencrypt,'
77[So 10. Nov 05:42:53 CET 2019] d='tojolula.de'
78[So 10. Nov 05:42:53 CET 2019] ok, let's start to verify
79[So 10. Nov 05:42:53 CET 2019] Verifying: tojolula.de
80[So 10. Nov 05:42:53 CET 2019] d='tojolula.de'
81[So 10. Nov 05:42:53 CET 2019] keyauthorization='qd3ImvHJuearPsBUpNtiD9XhzMlk5qpg_j3Wk0_DnJw.0Et1OVC42UD51nOBO5KbBgFwxmwlyrLQ4vdUn-xgIrs'
82[So 10. Nov 05:42:53 CET 2019] uri='https://acme-v02.api.letsencrypt.org/acme/chall-v3/1168561771/ZVR1aw'
83[So 10. Nov 05:42:53 CET 2019] _currentRoot='/var/www/letsencrypt'
84[So 10. Nov 05:42:53 CET 2019] wellknown_path='/var/www/letsencrypt/.well-known/acme-challenge'
85[So 10. Nov 05:42:53 CET 2019] writing token:qd3ImvHJuearPsBUpNtiD9XhzMlk5qpg_j3Wk0_DnJw to /var/www/letsencrypt/.well-known/acme-challenge/qd3ImvHJuearPsBUpNtiD9XhzMlk5qpg_j3Wk0_DnJw
86[So 10. Nov 05:42:53 CET 2019] Changing owner/group of .well-known to www-data:www-data
87[So 10. Nov 05:42:53 CET 2019] chown: der Eigentümer von '/var/www/letsencrypt/.well-known/acme-challenge/u3o8A5p5h9K1DZGW18E9hcHQg-ce20CBK6zuuS-x5JQ' wird geändert: Vorgang nicht zulässig
88chown: der Eigentümer von '/var/www/letsencrypt/.well-known/acme-challenge/qd3ImvHJuearPsBUpNtiD9XhzMlk5qpg_j3Wk0_DnJw' wird geändert: Vorgang nicht zulässig
89chown: der Eigentümer von '/var/www/letsencrypt/.well-known/acme-challenge' wird geändert: Vorgang nicht zulässig
90chown: der Eigentümer von '/var/www/letsencrypt/.well-known' wird geändert: Vorgang nicht zulässig
91[So 10. Nov 05:42:53 CET 2019] url='https://acme-v02.api.letsencrypt.org/acme/chall-v3/1168561771/ZVR1aw'
92[So 10. Nov 05:42:53 CET 2019] payload='{}'
93[So 10. Nov 05:42:53 CET 2019] POST
94[So 10. Nov 05:42:53 CET 2019] _post_url='https://acme-v02.api.letsencrypt.org/acme/chall-v3/1168561771/ZVR1aw'
95[So 10. Nov 05:42:53 CET 2019] _CURL='curl -L --silent --dump-header /home/letsencrypt/.acme.sh/http.header -g '
96[So 10. Nov 05:42:54 CET 2019] _ret='0'
97[So 10. Nov 05:42:54 CET 2019] code='200'
98[So 10. Nov 05:42:54 CET 2019] trigger validation code: 200
99[So 10. Nov 05:42:54 CET 2019] sleep 2 secs to verify
100[So 10. Nov 05:42:56 CET 2019] checking
101[So 10. Nov 05:42:56 CET 2019] url='https://acme-v02.api.letsencrypt.org/acme/chall-v3/1168561771/ZVR1aw'
102[So 10. Nov 05:42:56 CET 2019] payload
103[So 10. Nov 05:42:56 CET 2019] POST
104[So 10. Nov 05:42:56 CET 2019] _post_url='https://acme-v02.api.letsencrypt.org/acme/chall-v3/1168561771/ZVR1aw'
105[So 10. Nov 05:42:56 CET 2019] _CURL='curl -L --silent --dump-header /home/letsencrypt/.acme.sh/http.header -g '
106[So 10. Nov 05:42:57 CET 2019] _ret='0'
107[So 10. Nov 05:42:57 CET 2019] code='200'
108[So 10. Nov 05:42:57 CET 2019] tojolula.de:Verify error:Invalid response from http://tojolula.de/.well-known/acme-challenge/qd3ImvHJuearPsBUpNtiD9XhzMlk5qpg_j3Wk0_DnJw [87.176.226.54]:
109[So 10. Nov 05:42:57 CET 2019] Debug: get token url.
110[So 10. Nov 05:42:57 CET 2019] GET
111[So 10. Nov 05:42:57 CET 2019] url='http://tojolula.de/.well-known/acme-challenge/qd3ImvHJuearPsBUpNtiD9XhzMlk5qpg_j3Wk0_DnJw'
112[So 10. Nov 05:42:57 CET 2019] timeout=1
113[So 10. Nov 05:42:57 CET 2019] _CURL='curl -L --silent --dump-header /home/letsencrypt/.acme.sh/http.header -g --connect-timeout 1'
114<html>
115<head><title>403 Forbidden</title></head>
116<body>
117<center><h1>403 Forbidden</h1></center>
118<hr><center>nginx</center>
119</body>
120</html>
121[So 10. Nov 05:42:57 CET 2019] ret='0'
122[So 10. Nov 05:42:57 CET 2019] Debugging, skip removing: /var/www/letsencrypt/.well-known/acme-challenge/qd3ImvHJuearPsBUpNtiD9XhzMlk5qpg_j3Wk0_DnJw
123[So 10. Nov 05:42:57 CET 2019] pid
124[So 10. Nov 05:42:57 CET 2019] No need to restore nginx, skip.
125[So 10. Nov 05:42:57 CET 2019] _clearupdns
126[So 10. Nov 05:42:57 CET 2019] dns_entries
127[So 10. Nov 05:42:57 CET 2019] skip dns.
128[So 10. Nov 05:42:57 CET 2019] _on_issue_err
129[So 10. Nov 05:42:57 CET 2019] Please check log file for more details: /home/letsencrypt/.acme.sh/acme.sh.log
130[So 10. Nov 05:42:57 CET 2019] url='https://acme-v02.api.letsencrypt.org/acme/chall-v3/1168561771/ZVR1aw'
131[So 10. Nov 05:42:57 CET 2019] payload='{}'
132[So 10. Nov 05:42:57 CET 2019] POST
133[So 10. Nov 05:42:57 CET 2019] _post_url='https://acme-v02.api.letsencrypt.org/acme/chall-v3/1168561771/ZVR1aw'
134[So 10. Nov 05:42:57 CET 2019] _CURL='curl -L --silent --dump-header /home/letsencrypt/.acme.sh/http.header -g '
135[So 10. Nov 05:42:57 CET 2019] _ret='0'
136[So 10. Nov 05:42:57 CET 2019] code='400'
137[So 10. Nov 05:42:57 CET 2019] Diagnosis versions:
138openssl:openssl
139OpenSSL 1.1.1 11 Sep 2018
140apache:
141apache doesn't exists.
142nginx:
143nginx version: nginx/1.16.1
144built with OpenSSL 1.1.1 11 Sep 2018
145TLS SNI support enabled
146configure arguments: --with-cc-opt='-g -O2 -fdebug-prefix-map=/build/nginx-hIpOlr/nginx-1.16.1=. -fstack-protector-strong -Wformat -Werror=format-security -fPIC -Wdate-time -D_FORTIFY_SOURCE=2' --with-ld-opt='-Wl,-Bsymbolic-functions -Wl,-z,relro -Wl,-z,now -fPIC' --prefix=/usr/share/nginx --conf-path=/etc/nginx/nginx.conf --http-log-path=/var/log/nginx/access.log --error-log-path=/var/log/nginx/error.log --lock-path=/var/lock/nginx.lock --pid-path=/run/nginx.pid --modules-path=/usr/lib/nginx/modules --http-client-body-temp-path=/var/lib/nginx/body --http-fastcgi-temp-path=/var/lib/nginx/fastcgi --http-proxy-temp-path=/var/lib/nginx/proxy --http-scgi-temp-path=/var/lib/nginx/scgi --http-uwsgi-temp-path=/var/lib/nginx/uwsgi --with-compat --with-debug --with-pcre-jit --with-http_ssl_module --with-http_stub_status_module --with-http_realip_module --with-http_auth_request_module --with-http_v2_module --with-http_dav_module --with-http_slice_module --with-threads --with-http_addition_module --with-http_geoip_module=dynamic --with-http_gunzip_module --with-http_gzip_static_module --with-http_image_filter_module=dynamic --with-http_sub_module --with-http_xslt_module=dynamic --with-stream=dynamic --with-stream_ssl_module --with-stream_ssl_preread_module --with-mail=dynamic --with-mail_ssl_module --add-dynamic-module=/build/nginx-hIpOlr/nginx-1.16.1/debian/modules/http-auth-pam --add-dynamic-module=/build/nginx-hIpOlr/nginx-1.16.1/debian/modules/http-dav-ext --add-dynamic-module=/build/nginx-hIpOlr/nginx-1.16.1/debian/modules/http-echo --add-dynamic-module=/build/nginx-hIpOlr/nginx-1.16.1/debian/modules/http-upstream-fair --add-dynamic-module=/build/nginx-hIpOlr/nginx-1.16.1/debian/modules/http-subs-filter
147socat:
148socat by Gerhard Rieger and contributors - see www.dest-unreach.org
149Usage:
150socat [options] <bi-address> <bi-address>
151 options:
152 -V print version and feature information to stdout, and exit
153 -h|-? print a help text describing command line options and addresses
154 -hh like -h, plus a list of all common address option names
155 -hhh like -hh, plus a list of all available address option names
156 -d increase verbosity (use up to 4 times; 2 are recommended)
157 -D analyze file descriptors before loop
158 -ly[facility] log to syslog, using facility (default is daemon)
159 -lf<logfile> log to file
160 -ls log to stderr (default if no other log)
161 -lm[facility] mixed log mode (stderr during initialization, then syslog)
162 -lp<progname> set the program name used for logging
163 -lu use microseconds for logging timestamps
164 -lh add hostname to log messages
165 -v verbose data traffic, text
166 -x verbose data traffic, hexadecimal
167 -b<size_t> set data buffer size (8192)
168 -s sloppy (continue on error)
169 -t<timeout> wait seconds before closing second channel
170 -T<timeout> total inactivity timeout in seconds
171 -u unidirectional mode (left to right)
172 -U unidirectional mode (right to left)
173 -g do not check option groups
174 -L <lockfile> try to obtain lock, or fail
175 -W <lockfile> try to obtain lock, or wait
176 -4 prefer IPv4 if version is not explicitly specified
177 -6 prefer IPv6 if version is not explicitly specified
178 bi-address:
179 pipe[,<opts>] groups=FD,FIFO
180 <single-address>!!<single-address>
181 <single-address>
182 single-address:
183 <address-head>[,<opts>]
184 address-head:
185 abstract-client:<filename> groups=FD,SOCKET,RETRY,UNIX
186 abstract-connect:<filename> groups=FD,SOCKET,RETRY,UNIX
187 abstract-listen:<filename> groups=FD,SOCKET,LISTEN,CHILD,RETRY,UNIX
188 abstract-recv:<filename> groups=FD,SOCKET,RETRY,UNIX
189 abstract-recvfrom:<filename> groups=FD,SOCKET,CHILD,RETRY,UNIX
190 abstract-sendto:<filename> groups=FD,SOCKET,RETRY,UNIX
191 create:<filename> groups=FD,REG,NAMED
192 exec:<command-line> groups=FD,FIFO,SOCKET,EXEC,FORK,TERMIOS,PTY,PARENT,UNIX
193 fd:<num> groups=FD,FIFO,CHR,BLK,REG,SOCKET,TERMIOS,UNIX,IP4,IP6,UDP,TCP,SCTP
194 gopen:<filename> groups=FD,FIFO,CHR,BLK,REG,SOCKET,NAMED,OPEN,TERMIOS,UNIX
195 interface:<interface> groups=FD,SOCKET
196 ip-datagram:<host>:<protocol> groups=FD,SOCKET,RANGE,IP4,IP6
197 ip-recv:<protocol> groups=FD,SOCKET,RANGE,IP4,IP6
198 ip-recvfrom:<protocol> groups=FD,SOCKET,CHILD,RANGE,IP4,IP6
199 ip-sendto:<host>:<protocol> groups=FD,SOCKET,IP4,IP6
200 ip4-datagram:<host>:<protocol> groups=FD,SOCKET,RANGE,IP4
201 ip4-recv:<protocol> groups=FD,SOCKET,RANGE,IP4
202 ip4-recvfrom:<protocol> groups=FD,SOCKET,CHILD,RANGE,IP4
203 ip4-sendto:<host>:<protocol> groups=FD,SOCKET,IP4
204 ip6-datagram:<host>:<protocol> groups=FD,SOCKET,RANGE,IP6
205 ip6-recv:<protocol> groups=FD,SOCKET,RANGE,IP6
206 ip6-recvfrom:<protocol> groups=FD,SOCKET,CHILD,RANGE,IP6
207 ip6-sendto:<host>:<protocol> groups=FD,SOCKET,IP6
208 open:<filename> groups=FD,FIFO,CHR,BLK,REG,NAMED,OPEN,TERMIOS
209 openssl:<host>:<port> groups=FD,SOCKET,CHILD,RETRY,IP4,IP6,TCP,OPENSSL
210 openssl-listen:<port> groups=FD,SOCKET,LISTEN,CHILD,RETRY,RANGE,IP4,IP6,TCP,OPENSSL
211 pipe:<filename> groups=FD,FIFO,NAMED,OPEN
212 proxy:<proxy-server>:<host>:<port> groups=FD,SOCKET,CHILD,RETRY,IP4,IP6,TCP,HTTP
213 pty groups=FD,NAMED,TERMIOS,PTY
214 sctp-connect:<host>:<port> groups=FD,SOCKET,CHILD,RETRY,IP4,IP6,SCTP
215 sctp-listen:<port> groups=FD,SOCKET,LISTEN,CHILD,RETRY,RANGE,IP4,IP6,SCTP
216 sctp4-connect:<host>:<port> groups=FD,SOCKET,CHILD,RETRY,IP4,SCTP
217 sctp4-listen:<port> groups=FD,SOCKET,LISTEN,CHILD,RETRY,RANGE,IP4,SCTP
218 sctp6-connect:<host>:<port> groups=FD,SOCKET,CHILD,RETRY,IP6,SCTP
219 sctp6-listen:<port> groups=FD,SOCKET,LISTEN,CHILD,RETRY,RANGE,IP6,SCTP
220 socket-connect:<domain>:<protocol>:<remote-address> groups=FD,SOCKET,CHILD,RETRY
221 socket-datagram:<domain>:<type>:<protocol>:<remote-address> groups=FD,SOCKET,RANGE
222 socket-listen:<domain>:<protocol>:<local-address> groups=FD,SOCKET,LISTEN,CHILD,RETRY,RANGE
223 socket-recv:<domain>:<type>:<protocol>:<local-address> groups=FD,SOCKET,RANGE
224 socket-recvfrom:<domain>:<type>:<protocol>:<local-address> groups=FD,SOCKET,CHILD,RANGE
225 socket-sendto:<domain>:<type>:<protocol>:<remote-address> groups=FD,SOCKET
226 socks4:<socks-server>:<host>:<port> groups=FD,SOCKET,CHILD,RETRY,IP4,IP6,TCP,SOCKS4
227 socks4a:<socks-server>:<host>:<port> groups=FD,SOCKET,CHILD,RETRY,IP4,IP6,TCP,SOCKS4
228 stderr groups=FD,FIFO,CHR,BLK,REG,SOCKET,TERMIOS,UNIX,IP4,IP6,UDP,TCP,SCTP
229 stdin groups=FD,FIFO,CHR,BLK,REG,SOCKET,TERMIOS,UNIX,IP4,IP6,UDP,TCP,SCTP
230 stdio groups=FD,FIFO,CHR,BLK,REG,SOCKET,TERMIOS,UNIX,IP4,IP6,UDP,TCP,SCTP
231 stdout groups=FD,FIFO,CHR,BLK,REG,SOCKET,TERMIOS,UNIX,IP4,IP6,UDP,TCP,SCTP
232 system:<shell-command> groups=FD,FIFO,SOCKET,EXEC,FORK,TERMIOS,PTY,PARENT,UNIX
233 tcp-connect:<host>:<port> groups=FD,SOCKET,CHILD,RETRY,IP4,IP6,TCP
234 tcp-listen:<port> groups=FD,SOCKET,LISTEN,CHILD,RETRY,RANGE,IP4,IP6,TCP
235 tcp4-connect:<host>:<port> groups=FD,SOCKET,CHILD,RETRY,IP4,TCP
236 tcp4-listen:<port> groups=FD,SOCKET,LISTEN,CHILD,RETRY,RANGE,IP4,TCP
237 tcp6-connect:<host>:<port> groups=FD,SOCKET,CHILD,RETRY,IP6,TCP
238 tcp6-listen:<port> groups=FD,SOCKET,LISTEN,CHILD,RETRY,RANGE,IP6,TCP
239 tun[:<ip-addr>/<bits>] groups=FD,CHR,NAMED,OPEN,INTERFACE
240 udp-connect:<host>:<port> groups=FD,SOCKET,IP4,IP6,UDP
241 udp-datagram:<host>:<port> groups=FD,SOCKET,RANGE,IP4,IP6,UDP
242 udp-listen:<port> groups=FD,SOCKET,LISTEN,CHILD,RANGE,IP4,IP6,UDP
243 udp-recv:<port> groups=FD,SOCKET,RANGE,IP4,IP6,UDP
244 udp-recvfrom:<port> groups=FD,SOCKET,CHILD,RANGE,IP4,IP6,UDP
245 udp-sendto:<host>:<port> groups=FD,SOCKET,IP4,IP6,UDP
246 udp4-connect:<host>:<port> groups=FD,SOCKET,IP4,UDP
247 udp4-datagram:<remote-address>:<port> groups=FD,SOCKET,RANGE,IP4,UDP
248 udp4-listen:<port> groups=FD,SOCKET,LISTEN,CHILD,RANGE,IP4,UDP
249 udp4-recv:<port> groups=FD,SOCKET,RANGE,IP4,UDP
250 udp4-recvfrom:<host>:<port> groups=FD,SOCKET,CHILD,RANGE,IP4,UDP
251 udp4-sendto:<host>:<port> groups=FD,SOCKET,IP4,UDP
252 udp6-connect:<host>:<port> groups=FD,SOCKET,IP6,UDP
253 udp6-datagram:<host>:<port> groups=FD,SOCKET,RANGE,IP6,UDP
254 udp6-listen:<port> groups=FD,SOCKET,LISTEN,CHILD,RANGE,IP6,UDP
255 udp6-recv:<port> groups=FD,SOCKET,RANGE,IP6,UDP
256 udp6-recvfrom:<port> groups=FD,SOCKET,CHILD,RANGE,IP6,UDP
257 udp6-sendto:<host>:<port> groups=FD,SOCKET,IP6,UDP
258 unix-client:<filename> groups=FD,SOCKET,NAMED,RETRY,UNIX
259 unix-connect:<filename> groups=FD,SOCKET,NAMED,RETRY,UNIX
260 unix-listen:<filename> groups=FD,SOCKET,NAMED,LISTEN,CHILD,RETRY,UNIX
261 unix-recv:<filename> groups=FD,SOCKET,NAMED,RETRY,UNIX
262 unix-recvfrom:<filename> groups=FD,SOCKET,NAMED,CHILD,RETRY,UNIX
263 unix-sendto:<filename> groups=FD,SOCKET,NAMED,RETRY,UNIX