Ao acessar a console do Mikrotik, digite:
/certificate
CA:
add name=ca-template common-name=CA-OVPN days-valid=3650 key-size=2048 key-usage=crl-sign,key-cert-sign
sign ca-template name=CA-OVPN
SERVER (Precisa alterar na configuração do servidor OVPN):
add name=server-template common-name=SERVER-OVPN days-valid=3650 key-size=2048 key-usage=digital-signature,key-encipherment,tls-server
sign server-template name=SERVER-OVPN ca=CA-OVPN
Clientes:
add name=client-template common-name=cliente01 days-valid=3650 key-size=2048 key-usage=tls-client
sign client-template name=cliente01 ca=CA-OVPN
add name=client-template common-name=cliente02 days-valid=3650 key-size=2048 key-usage=tls-client
sign client-template name=cliente02 ca=CA-OVPN