-
Type: Bug
-
Resolution: Fixed
-
Priority: Major - P3
-
Affects Version/s: 3.6.0, 3.6.1
-
Component/s: Networking, Security
-
None
-
Fully Compatible
-
ALL
-
v3.6
-
-
Platforms 2018-01-15
-
(copied to CRM)
In a 3.6.0 and 3.6.1 replica set cluster with x.509 membership authentication with distinct pem files for clusterFile (with "TLS Web Client Authentication" X509v3 Extended Key Usage) and PEMKeyFile (with "TLS Web Server Authentication" X509v3 Extended Key Usage) mongod options the client ssl connection requests are served by client certificate (with obvious [CONNECT_ERROR] for SSL peer certificate validation failed: unsupported certificate purpose).
It affects 3.4 --> 3.6 upgrade cluster and also a fresh 3.6 installation.