Uploaded image for project: 'Documentation'
  1. Documentation
  2. DOCS-4103

x509 client and server certificates

      It is possible to use a single x509 certificate for both member authentication and x.509 client authentication. To do so, obtain a certificate with both clientAuth and serverAuth (i.e. “TLS Web Client Authentication” and “TLS Web Server Authentication”) specified as Extended Key Usage (EKU) values, or simply do not specify any EKU values. Provide this file as the the --sslPEMKeyFile and omit the --sslClusterFile option described below.

      It is very confusing, as it might sound that we encourage to use the same x509 certificate for both client and server authentication.

            Assignee:
            sam.kleinman Sam Kleinman (Inactive)
            Reporter:
            alex.komyagin@mongodb.com Alexander Komyagin (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved:
              9 years, 28 weeks, 6 days ago