Автор: Захар Тихонов 
Т.е. для Са вы выпускаете свой TLS сертификат и указываете его дважды отпечаток
Я так и сделал, ошибка следующая:
root@kv-gpca-sub01:/var/opt/cprocsp/keys/stan# /opt/cpca/nats-streaming/nats-streaming-server -sc /opt/cpca/nats-streaming/nats.conf
[61152] 2025/02/04 12:26:00.093480 [INF] STREAM: Starting nats-streaming-server[pkica-cluster] version 0.24.6
[61152] 2025/02/04 12:26:00.093581 [INF] STREAM: ServerID: 6axA8QEelzKe6qYvDqD4lU
[61152] 2025/02/04 12:26:00.093586 [INF] STREAM: Go version: go1.18.5
[61152] 2025/02/04 12:26:00.093588 [INF] STREAM: Git commit: [not set]
[61152] 2025/02/04 12:26:00.095713 [INF] Starting nats-server
[61152] 2025/02/04 12:26:00.095727 [INF] Version: 2.8.2
[61152] 2025/02/04 12:26:00.095732 [INF] Git: [not set]
[61152] 2025/02/04 12:26:00.095736 [INF] Name: NDEHEYY2VQPP6BSP6ZIVU7UZHVFDT45H7ZCT5FPL2EKQNZNOGGGGQ54F
[61152] 2025/02/04 12:26:00.095741 [INF] ID: NDEHEYY2VQPP6BSP6ZIVU7UZHVFDT45H7ZCT5FPL2EKQNZNOGGGGQ54F
[61152] 2025/02/04 12:26:00.095753 [INF] Using configuration file: /opt/cpca/nats-streaming/nats.conf
[61152] 2025/02/04 12:26:00.095759 [WRN] Maximum payloads over 8.00 MB are generally discouraged and could lead to poor performance
[61152] 2025/02/04 12:26:00.096690 [INF] Listening for client connections on localhost:4222
[61152] 2025/02/04 12:26:00.096830 [INF] TLS required for client connections
[61152] 2025/02/04 12:26:00.096925 [INF] Server is ready
[61152] 2025/02/04 12:26:00.154051 [FTL] STREAM: Failed to start: use of closed network connection
Конфиг:# NATS
listen: kv-gpca-sub01.ipa.ucb.local:4222
max_payload: 10Mb
# NATS Streaming
cluster_id: "pkica-cluster"
store: "file"
dir: "/opt/cpca/pkica-store"
store_limits: {
max_channels: 50
max_bytes: 50GB
}
tls: {
# серверный сертификат NATS
cert_file: "/opt/cpca/nats-streaming/ssl/nats-server.cer"
key_file: "/opt/cpca/nats-streaming/ssl/nats-server.cer"
verify_and_map: true
ip a и hostname:root@kv-gpca-sub01:~# ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
link/ether 00:50:56:93:40:4a brd ff:ff:ff:ff:ff:ff
altname enp11s0
altname ens192
inet 10.8.95.17/24 brd 10.8.95.255 scope global eth0
valid_lft forever preferred_lft forever
root@kv-gpca-sub01:~# hostname
kv-gpca-sub01.ipa.ucb.local