In the server configuration file, you can select the algorithm that will be used for traffic encryption.
Based on previous recommendation established in that document, select AES with a 256 bits key in CBC mode.
-\todo{cm: make configA/B sections/tables}
+Note that TLS is used only for negotiation bla bla bla...
+
+\todo{cm: explain how openvpn crypto works; make configA/B sections/tables}
% openvpn --show-ciphers
% --show-tls