# Certificates config
dh pub/dh.pem
ca pub/cacert.pem
cert pub/cert.pem
key priv/key.pem
tls-server

{

if (-e "/etc/openvpn/routed/priv/takey.pem" &&
    !-z "/etc/openvpn/routed/priv/takey.pem"){
  $OUT .= "tls-auth priv/takey.pem 0\n";
}

if (-e '/etc/openvpn/routed/pub/cacrl.pem' &&
   !-z '/etc/openvpn/routed/pub/cacrl.pem'){
  $OUT .= "crl-verify pub/cacrl.pem\n";
}

}
