Missing TLS Client Authentication breaks galera distributed database

Recklessly? That's harsh. Let's Encrypt announced this change last May ...

Here: Ending TLS Client Authentication Certificate Support in 2026 - Let's Encrypt
And: Ending TLS Client Authentication Certificate Support in 2026

The reason for the change (from those notices) is:

This change is prompted by changes to Google Chrome’s root program requirements, which impose a June 2026 deadline to split TLS Client and Server Authentication into separate PKIs. Many uses of client authentication are better served by a private certificate authority, and so Let’s Encrypt is discontinuing support for TLS Client Authentication ahead of this deadline.