tambien hay una linea de windows que saca los privelegios
no creo que te haga falta ya que usas todo debian
# Downgrade privileges after initialization (non-Windows only)
#;user nobody
#;group nogroup
lo tenes configurado para uno o todos los clientes?
# SSL/TLS parms.
# See the server config file for more
# description. It's best to use
# a separate .crt/.key file pair
# for each client. A single ca
# file can be used for all clients.
ca /etc/openvpn/ssl/ca.crt
cert /etc/openvpn/ssl/client.crt
key /etc/openvpn/ssl/client.key
# If a tls-auth key is used on the server
# then every client must also have the key.
tls-auth /etc/openvpn/ssl/ta.key 1