"Again its not clear to me where/how to extract the root certificate from the ARRL LOTW program".
AFAIK, tQSL program itself doesn't contain this. All necessary certificates (root, ca) and keys are imported from <call-sign>.tq6 file sent to the callsign owner.
BTW, I have OpenVPN server running too, capable of assigning 44.165.15.xx addresses. Thanks to GURU Rob/PE1CHL for nifty tips on how to issue all-in-one end user config file.
Best regards --- Tom - SP2L
Sent from Xperia Z1 with AquaMail http://www.aqua-mail.com