This can be marked as solved. I was of course following the docs for the new Instance Based "Road Warrior" setup, which can be found here: https://docs.opnsense.org/manual/how-tos/sslvpn_instance_roadwarrior.html
In there, the tiniest comment "Leaf Certificate - Type Server: Set the Common Name to the FQDN of this machine." bears all the weight here. You must set a CN value, no matter what it is, for things to work. I don't use a FQDN on my router yet, so I had omitted it. I put one that is a subdomain of my actual domain, but is not an actual DNS entry anywhere on my network. The other "Self-Signed Certificate Chains" doc also points to this, saying to put "leaf-certificate.example.com". See: https://docs.opnsense.org/manual/how-tos/self-signed-chain.html
Once I had reissued the certificate the OpenVPN instance was using, I restarted the instance from the Dashboard. I exported the ovpn client file again and imported.
RANT: Can we please get better warnings in OpnSense??!! I've been using it for 7+ years now and every single problem I have pulled my hair on can be chalked down to "UI does not clearly tell you what is a required field or warn you of obvious issues."
If modern OpenVPN/openssl implementations demand a CN, then it should either:
1) Be a required field when creating a new leaf certificate.
2) Flagged as a health status issue up top that says "Your OpenVPN instance certificate chain is missing a Common Name."
I'm tired boss. This took 5+ hours out of a good weekend. A tiny sentence, not in bold, not italicized, with no warnings from the router itself. That took 5 hours.
In there, the tiniest comment "Leaf Certificate - Type Server: Set the Common Name to the FQDN of this machine." bears all the weight here. You must set a CN value, no matter what it is, for things to work. I don't use a FQDN on my router yet, so I had omitted it. I put one that is a subdomain of my actual domain, but is not an actual DNS entry anywhere on my network. The other "Self-Signed Certificate Chains" doc also points to this, saying to put "leaf-certificate.example.com". See: https://docs.opnsense.org/manual/how-tos/self-signed-chain.html
Once I had reissued the certificate the OpenVPN instance was using, I restarted the instance from the Dashboard. I exported the ovpn client file again and imported.
RANT: Can we please get better warnings in OpnSense??!! I've been using it for 7+ years now and every single problem I have pulled my hair on can be chalked down to "UI does not clearly tell you what is a required field or warn you of obvious issues."
If modern OpenVPN/openssl implementations demand a CN, then it should either:
1) Be a required field when creating a new leaf certificate.
2) Flagged as a health status issue up top that says "Your OpenVPN instance certificate chain is missing a Common Name."
I'm tired boss. This took 5+ hours out of a good weekend. A tiny sentence, not in bold, not italicized, with no warnings from the router itself. That took 5 hours.
"