client-config-dir /etc/openvpn/server/client-config
ccd-exclusive

ca /etc/openvpn/server/ca-cert.pem
cert /etc/openvpn/server/private/server-cert.pem
key /etc/openvpn/server/private/server-key.pem
crl-verify /etc/openvpn/server/crl dir
dh /etc/openvpn/server/private/dh4096.pem

tls-server
tls-version-min 1.3
tls-ciphersuites TLS_AES_256_GCM_SHA384
tls-groups X25519MLKEM768
tls-auth /etc/openvpn/server/private/ta.key 0
data-ciphers AES-256-GCM
auth sha512
reneg-sec 3600
replay-persist /etc/openvpn/server/replay.txt
replay-window 512 15
verify-client-cert require