mTLS adds a second certificate in the other direction, and the failure messages are notoriously unhelpful. Nearly all of it comes down to three things: the right extended key usage, a chain the server trusts, and the client actually sending it.
$ openssl s_client -connect <host>:443 -cert client.crt -key client.key -CAfile ca.crt </dev/null
$ openssl x509 -in client.crt -noout -ext extendedKeyUsage
$ openssl verify -CAfile ca.crt client.crt
$ openssl s_client -connect <host>:443 </dev/null 2>&1 | grep -i "acceptable client certificate"
Look for: Whether the EKU includes clientAuth, whether verify passes against the CA the server trusts, and which CA names the server says it will accept.