I have an OpenVPN gateway setup. A CA was created on the same server with Easy-RSA.
Each OpenVPN client has its own certificate-key pair issued with the aforementioned CA. Server has its own certificate and a private key.
While client's certificate and private key are indeed located on the client side and are used in the connection handshake, I see how OpenVPN server can identify a client connecting to it.
But the documentation to OpenVPN states that there is mutual authentication going on, meaning that no only client is authenticated on the server, but the server is authenticated (it's identity is being verified) with the client. How could the client check if the server is indeed the server its has intended to connect to?
My assumption is that since the client also has their common CA's cert, when the server will present its certificate, a client will try to verify it with the CA's cert. Is this how it will know that the server is the correct one?