http://ciisqbg45nggykdl6rjdrq3wc64csga4vkphu66qsi65mypeitqedoad.onion/blog/tlscryptv2
But even if we did, there's no way to tell if a client plans to use that key maliciously or not (I.e., to create a fingerprint so the traffic can be blocked by DPI firewalls, or to bypass the TLS stack protection, or to bypass the DoS protection, etc.) That problem is solved by --tls-crypt-v2, which was introduced in OpenVPN 2.5.0 The techie specs for it are here .