Do not use the brand new, recommended by the docs, way of verifying your certificate. Instead use the old way because older clients give error when they process the config.
@@ -5,13 +5,13 @@ dev tun
proto udp
remote {{ .Hostname }} {{ .Port }}
resolv-retry infinite
-remote-cert-tls server
ns-cert-type server
nobind
persist-key
persist-tun
comp-lzo
verb 3
+auth-nocache
<ca>
{{ .CA }}</ca>