Thanks Mathias!  I was finally able to use --tls-verify successfully.  I had
my server chrooted and that made troubleshooting more difficult.


Both --tls-verify and --crl-verify can be used for this.

--tls-verify executes a script which you can have check the certificate's 
CN agaist a list of users you wish to reject or accept.

--crl-verify should refer to a standard CRL file which is a file 
containing a list of revoked certificates. There is no need to restart 
OpenVPN when adding certs to this file as OpenVPN will check it each time 
a new client connects. See the openssl manpage for more info on how to 
create a CRL file or look at the easy-rsa scripts that come with OpenVPN.

