# Issue in connecting via tls , sharded cluster exposed loadbalancer. via mongocompass

**URL:** <https://forums.percona.com/t/issue-in-connecting-via-tls-sharded-cluster-exposed-loadbalancer-via-mongocompass/39527>\
**Category:** MongoDB® General Discussion\
**Created:** [October 9, 2025, 7:04pm UTC](https://forums.percona.com/t/issue-in-connecting-via-tls-sharded-cluster-exposed-loadbalancer-via-mongocompass/39527 "2025-10-09T19:04:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rohit\_Singh](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/rohit_singh/32/20587_2.png) [@Rohit\_Singh](https://forums.percona.com/u/Rohit_Singh)\
**Post date:** [October 9, 2025, 7:04pm UTC](https://forums.percona.com/t/issue-in-connecting-via-tls-sharded-cluster-exposed-loadbalancer-via-mongocompass/39527/1 "2025-10-09T19:04:45Z")

</div>

tls:

```auto
mode: preferTLS

```

# 90 days in hours

certValidityDuration: 2160h

allowInvalidCertificates: true

issuerConf:

name: percona-cluster-issuer

kind: ClusterIssuer

group: [cert-manager.io](http://cert-manager.io).

connection string : mongodb://user:password@k8s-mongopre-stagemon-73a0897a4c-ba595be8c7c7e792.elb.ap-south-1.ws.com:27017/admin?tls=true&tlsCAFile=%2FUsers%2Frohitsingh%2Fca.crt&tlsAllowInvalidHostnames=true

k get certificates  
NAME READY SECRET AGE  
stage-mongo-preprod-ca-cert True stage-mongo-preprod-ca-cert 8h  
stage-mongo-preprod-ssl True stage-mongo-preprod-ssl 8h  
stage-mongo-preprod-ssl-internal True stage-mongo-preprod-ssl-internal 8h  
➜ secret. , kubectl get secret stage-mongo-preprod-ca-cert -o jsonpath=“{.data[‘ca.crt’]}” | base64 --decode \> ca.crt

{“t”:{“$date”:“2025-10-09T18:35:25.586Z”},“s”:“E”, “c”:“NETWORK”, “id”:23212, “ctx”:“js”,“msg”:“SSL peer certificate validation failed; connection rejected”,“attr”:{“error”:“Certificate trust failure: CSSMERR\_TP\_NOT\_TRUSTED”}}  
Error: couldn’t connect to server [k8s-mongopre-stagemon-73a0897a4c-ba595be8c7c7e792.elb.ap-south-1.amazonaws.com:27017](http://k8s-mongopre-stagemon-73a0897a4c-ba595be8c7c7e792.elb.ap-south-1.amazonaws.com:27017), connection attempt failed: SSLHandshakeFailed: Certificate trust failure: CSSMERR\_TP\_NOT\_TRUSTED :

via mongo compass : **k8s-mon95be8c7c7e792.elb.ap-south-1.amazonaws.:27017** unable to get local issuer certificate

---

<div class="post-metadata">

**Author:** ![radoslaw.szulgo](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/radoslaw.szulgo/32/17315_2.png) [@radoslaw.szulgo](https://forums.percona.com/u/radoslaw.szulgo)\
**Post date:** [October 13, 2025, 12:15pm UTC](https://forums.percona.com/t/issue-in-connecting-via-tls-sharded-cluster-exposed-loadbalancer-via-mongocompass/39527/2 "2025-10-13T12:15:31Z")

</div>

The error `Certificate trust failure: CSSMERR_TP_NOT_TRUSTED` and `unable to get local issuer certificate` means that your client (Mongo Compass) does not trust the TLS certificate being presented by the MongoDB server.

The most likely scenario is that **the external certificate (`stage-mongo-preprod-ssl`) was NOT signed by the internal CA (`stage-mongo-preprod-ca-cert`).**

The operator might be configured to use one self-signed CA for internal traffic but a different issuer (such as Let’s Encrypt or another corporate CA) for the external-facing certificate. When you extract the `stage-mongo-preprod-ca-cert` and give it to Compass, you are giving it the wrong key to validate the server’s certificate.

Try to check it first:

```bash
openssl s_client -connect k8s-mongopre-stagemon-73a0897a4c-ba595be8c7c7e792.elb.ap-south-1.ws.com:27017 -starttls mongodb < /dev/null

```

^^ Check the Issuer.

Then:

```auto
openssl x509 -in ca.crt -noout -subject -issuer

```

Subject and Issuer should be the same. If they are not - you need to fix it. If they are, maybe you miss an Intermidiate certificate to make sure whole validation chain is provided.

---

<div class="post-metadata">

**Author:** ![radoslaw.szulgo](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/radoslaw.szulgo/32/17315_2.png) [@radoslaw.szulgo](https://forums.percona.com/u/radoslaw.szulgo)\
**Post date:** [October 21, 2025, 8:47am UTC](https://forums.percona.com/t/issue-in-connecting-via-tls-sharded-cluster-exposed-loadbalancer-via-mongocompass/39527/3 "2025-10-21T08:47:44Z")

</div>

@Rohit_Singh were you able to check this?

---

<div class="post-metadata">

**Author:** ![Rohit\_Singh](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/rohit_singh/32/20587_2.png) [@Rohit\_Singh](https://forums.percona.com/u/Rohit_Singh)\
**Post date:** [November 6, 2025, 6:00pm UTC](https://forums.percona.com/t/issue-in-connecting-via-tls-sharded-cluster-exposed-loadbalancer-via-mongocompass/39527/4 "2025-11-06T18:00:31Z")

</div>

this issue is solved.  
i was not passing the whole certificate chain to mongo-compass

---

<div class="post-metadata">

**Author:** ![Ivan\_Groenewold](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/ivan_groenewold/32/6299_2.png) [@Ivan\_Groenewold](https://forums.percona.com/u/Ivan_Groenewold)\
**Post date:** [November 7, 2025, 11:17am UTC](https://forums.percona.com/t/issue-in-connecting-via-tls-sharded-cluster-exposed-loadbalancer-via-mongocompass/39527/5 "2025-11-07T11:17:43Z")

</div>


