Option 3: Use the tls-remote directive on the client to accept/reject the server connection based on the common name of the server certificate.
+
# Sample OpenVPN 2.0 configuration files
+
+
Latest sample configuration files [https://github.com/OpenVPN/openvpn/tree/master/sample/sample-config-files are available on GitHub].
+
+
Option 4: Use a tls-verify script or plugin to accept/reject the server connection based on a custom test of the server certificate's embedded X509 subject details.
Option 5: Sign server certificates with one CA and client certificates with a different CA. The client configuration ca directive should reference the server-signing CA file, while the server configuration ca directive should reference the client-signing CA file.