Hello Julien! > I'm surprised by this one: you already set ca to something different. Can you share the generated openvpn.conf? OOPS! There was a mistake in config.scm. This error is gone now. Now the openvpn.conf is https://paste.debian.net/1173026/ and error is https://paste.debian.net/1173027/ > Ok, looking at the service definition, this is not so surprising: it expects a file in the cert and key fields, and uses the defaults here. I'm surprised it doesn't complain about client.crt. I pushed a small update to the service. After you run guix pull, you should be able to specify (cert 'disabled) and (key 'disabled). Thanks a lot! I will try it. > This is only a warning, but you don't want your password to be world readable: chown it to openvpn's user, and chmod it to 600. Cool! Regards, RG.