Openvpn not started

My config is like this:

client
dev tun
proto tcp-client
remote DYNDNS_ADDRESS 443
float
ncp-ciphers AES-128-GCM:AES-256-GCM:AES-128-CBC:AES-256-CBC
comp-lzo adaptive
keepalive 15 60
auth-user-pass /etc/openvpn/auth/2018893555.txt
remote-cert-tls server
<ca>
-----BEGIN CERTIFICATE-----
Y9u88kYQUdPyNimnkMBO92nMtqZNAI58WFlQ2QBtblc4a3aaRVh9cQPrdnyHcbtJ
wg9w2nSc8t3FfRcwtXGtR699WMt3WH4ZmtKROhUdOtyCGokIMBMihjJOnSvSTWaF
sepkZbufWBxSAuqLtbK7hp5rGK1PnvUyJ3oVEUbBlHRyjitdKm9uybiqGGQryDx7
AIVpvrWFPYRTW9682VI3awgJ13gzx1KmBcjClyM8vRNWPYGxTD2N79qVoQhQd2N1
ty9tiGvsMFoIxXkjfdRgOSaVN1ESoZOY94Am8TaPHhKl5goYQsopi84UnBBm7p9e
C0U9aSWSVFMstdzYr1NmREwgOn1oi0QQ648P97lu8BX9wtte62Jj9v4lFUAidsrf
P2nNm4c8OPAAErWSNl01yYBMGBblTT2u5Wxn5AjGDL3Db3hQFT2nPzefLaFIpPa8
B4TVhYXsDHbm0FTHECtGbBLEYnwJW7smgO6pIc1wwW90UNx8PZiSDamwGI2RfIP0
5Bz0M7EPNEEzpslLeTelYWdFuTpAY2hVk4mOlZjajWwo1AgLyAXwP0sIEN4JHkNb
4eppp0wYHsMopRzJbPHVOOVF9A3wSnqxPjHtYVNHFQd0Aj6RoIpMNUQarNRUEPQd
dQRuKyEKIwUaD0SJG7AJO03kHNDWOodlJNggnkE5t6Ut8R66L7IJOsq8vqeg6JeL
uCUrehnEcLOJ9f0muWtG1drBLSngfOyvK0PYMTlXQ0sohloKdQT4mNM9qWYDsoXo
zwLPDbAO9zqH0q2gVuonfUfuLG2FDgeVwrCOkUTtdfVhoIsMokub8fIXU7BshSy2
zJWeHOLgHa9P3qJ7ZQdTcOzIQ1jYCpUkOdjaHVCksmT61QBVBYRWxuqEgnh76YOH
jS0PaU4FMl2N0Um6wyW9UqxPI09JDNY6CBmOkJn5llxLJ1Zd7GY4oWR3z58fXiyL
2mdkFOYoBl4L1B9k84t2ZfH6EdroLA2CJnI5H38NfWl4I1K1ETwJdRvLiOZXrhpe
oxuEMBhGwm7DTTmUxEjgAsJHIgxNQF9jyLhlOUZshK3520g0BfcaWkFwXP9NaMLM
D9OYZEK=
-----END CERTIFICATE-----
</ca>
<tls-crypt>
-----BEGIN OpenVPN Static key V1-----
8cd1471744b160539a5a38ee1d5bf5fa
f4e0293d682ac7d11e9a12e111863d63
36604319de544021e5a29d3a8dc66bfa
a4762f8295de68c3157d924ebd022b57
b1be3ad6e2f2421309614d29811ee683
ea915096577dd0e91e169fbc7a72dd66
4b16b09a91aec0f5c4f80ad9a97d6de7
0c1251a9161bfb0768a2e5ba167c6cdc
41a633fe88bf815573c03bb57b49fcba
d98c1aa68d8356a5ece6cff274f66bde
db5b99f26dfee74276d65a50892a8f8b
3d46c2141440249ec62b26442a418fc0
0d21f74f48fc576dbdd9492726e200a7
77d6f34746224d6120db3a55fd0635e6
c325a48f265f2b8bf5881c5e3c83764c
992b85fae95f1a19c2ad273ae08e110c
-----END OpenVPN Static key V1-----
</tls-crypt>
resolv-retry infinite
nobind
daemon

I think whats wrong is you need to only copy the base64 blob sections from your cert like i have above ONLY. The plaintext is causing the parser to remove those lines and then failing to load the config.

You can convert any cert files to base64 with the openvpn tools.

If you SSH into the router and check the ovpn in /etc/openvpn/YOUROPVNNAME , i think you will see that those plain text sections have been removed. You can compare the uploaded to the original and see what was “incorrect” in the original.