CA.key 			private key for CA certificate
CA.crt			self-signed certificate
CA.pem			CA pem key file

certificate.key		private key for cluster members
certificate.csr		self-signed certificate request
certificate.crt		self-signed certificate for cluster members
certificate.pem		pem key file for cluster members

client.key		client private key for namaste app (gaOwner)
client.csr		self-signed certificate request for namaste client app
client.pem		cluster client PEM key

admin-client.key	client private key for DB Owner (gaAdmin)
admin-client.csr	self-signed certificate request for database admin user
admin-client.pem	admin-client PEM key

DEPLOYMENT
----------
Keys should be copied to /opt/mongodb -- make sure you set the permissions to 400!


Connecting to client:

mongo --port 27027 --ssl --host database.givingassistant.org -sslPEMKeyFile /opt/mongodb/certificate.pem --sslCAFile /opt/mongodb/CA.pem
