I have the same issue, even though my certificate includes both: openssl crl2pkcs7 -nocrl -certfile cert_combined.pem | \ openssl pkcs7 -print_certs -text -noout | grep -A1 "Extended Key Usage" X509v3 Extended Key Usage: TLS Web Client Authentication, TLS Web Server Authentication -- X509v3 Extended Key Usage: TLS Web Server Authentication However, the intermediate certificate (leaf CA) only has TLS Web Server Authentication, and as a result, the KV Store fails to start.
... View more