http://stormwdumgah7rpl6fdj4yhrl2i2a7j3bkzyjcv5qxk3a6253n22thyd.onion/blog/port-striping-v2
That means even for customers using ancient versions of OpenVPN, we could use an ECC CA certificate, even if the server certificate had to be RSA. After some testing, we implemented these new cryptographic features. The new configs were rewritten to be OS independent, and the default RSA configs were to use 8192-bit RSA server certificates, along with secp521r1 (521-bit EC) CA certificates, and 8192-bit DH parameters.