    I am using Tomato with OpenVPN with TLS authentication. How can I temporarily reject connection from user with particular key (common name)??

    If the list of acceptable CommonNames is small enough, you could use the client-specific options table to whitelist certain clients and select "Allow only these clients".

    If you would rather blacklist that particular client, you'll need to manage the client-config-dir manually (see the OpenVPN man-page) and add "disable" to that CommonName.

    This is another interesting idea for a future feature, though (being able to disable a CommonName from the client-specific options table). Right now, not selecting "enable" just leaves out that CommonName entirely, but perhaps it should actively disable it...
