kde soudruzi z NDR udelali pri generovani serveroveho certifikatu chybu?

je mi divny, ze pri generovani se nikde nenastavuje, ze se jedna o serverovy certifikat jen "tls server", coz je mozna ono

podle me je urcite nejaka chyba v srv certifikatu, viz. require nsCertType=SERVER
Postupoval jsem podle toho, co jste mi napsal, ale mozna jsem to proste pohnojil

Sun Feb 26 20:43:58 2017 VERIFY OK: depth=1, C=CZ, ST=CZ, L=Praha, O=mojefirma, OU=mojefirma, CN=CA
Sun Feb 26 20:43:58 2017 VERIFY nsCertType ERROR: C=CZ, ST=CZ, L=Praha, O=mojefirma, OU=mojefirma, CN=SERVER, require nsCertType=SERVER
Sun Feb 26 20:43:58 2017 OpenSSL: error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed
Sun Feb 26 20:43:58 2017 TLS_ERROR: BIO read tls_read_plaintext error
Sun Feb 26 20:43:58 2017 TLS Error: TLS object -> incoming plaintext read error
Sun Feb 26 20:43:58 2017 TLS Error: TLS handshake failed
Sun Feb 26 20:43:58 2017 Fatal TLS error (check_tls_errors_co), restarting
Sun Feb 26 20:43:58 2017 SIGUSR1[soft,tls-error] received, process restarting
Sun Feb 26 20:43:59 2017 SIGHUP[hard,init_instance] received, process restarting
Sun Feb 26 20:43:59 2017 OpenVPN 2.3.14 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [PKCS11] [IPv6] built on Feb 1 2017
Sun Feb 26 20:43:59 2017 Windows version 6.2 (Windows 8 or greater) 64bit
Sun Feb 26 20:43:59 2017 library versions: OpenSSL 1.0.2k 26 Jan 2017, LZO 2.09
Sun Feb 26 20:44:00 2017 SIGTERM[hard,init_instance] received, process exiting
client
dev tun
proto tcp-client
remote mojeip 1194
nobind
persist-tun
cipher AES-256-CBC
ns-cert-type server
verb 2
ca cert_export_CA.crt
cert cert_export_CLIENT.crt
key cert_export_CLIENT.key