because the root.pem doesn't include "ExtKeyUsageClientAuth". the solution is to include ExtKeyUsageClientAuth when generating root.pem.