Import both key and certificate under system certificates
You will need to include the CA certificate that you generate or download from startssl.com with the openvpn configuration file.
I cannot help you with the actual openvpn server configuration and the openvpn configuration files … there are many examples of them on this forum.
However I must say that OpenVPN server support in ROS 4.x-5.x is beta at best:
1, I have not found a way to propagate the default route to clients (so you have to add 60-80 route commands to the configuration files to route everything through the openvpn interface except the openvpn server IP) … the methods that work elsewhere refuse to work with ROS.
2, OpenVPN breaks a lof of your configuration ability in winbox (missing and spurions network interfaces)
3, OpenVPN will lock up from time to time, so you need to restart the router every few days, depending on load.