http://cs.i2p/blog/port-striping-v2?i2paddresshelper=XeeEcrjZBSZvLCLt32HWWojBguqcQNIfCcYnLhCSpV3LHMHvq-3nkdVw3DGoJYEQnLEpbhLEH~KwUXs42auWcbRedx895ciACwHpMBnchqCYvYeqKNOnMnlZkpSGJNNSRXAcUM48WLh7v6PscDCDKQFN8KVo9n6OBm0KKQjmaQjIN3unappXVvN90d0Q6tWjftn1mTtm2Is4sYYM3glXr47IXPjTha~XW6Ex5wNqtD7pR5rNN5g5Xcpww2teT~mo52Z1xFE5g7ZgK3rHRVnShmolLNwU2VT1ZGqI5X74Tq6DPu6itln3SYyF6db-X
OpenVPN didn't support it back then, but that only applied to the server certificate. Whenever OpenVPN verifies a CA certificate, pretty much all of that processing is handled directly by OpenSSL. That means even for customers using ancient versions of OpenVPN, we could use an ECC CA certificate, even if the server certificate had to be RSA.