Where is the vpn key generated?
The vpn key is generated by the client. According to the relevant information of the query, the whole spirit of PKI is that the public key (or certificate) contains all the contents needed by the third party (here refers to your VPN server) to verify its authenticity, and only the client needs the private key to sign these verification challenges. Although this will make the process of registering new users slightly longer, by letting each client generate its own private key and certificate signing request, the distribution of private keys will be restricted and the security will be greatly improved.