Profiler: validate server/PKI settings before they reach OpenVPN config
- Schema validators on the update models (ports, subnet/mask, routes,
DNS, public host, loopback-only management address, MTU/MSS, script
paths, PKI DN fields, key size and lifetimes).
- Script paths must be root-owned, non-writable files directly inside
/etc/openvpn/scripts (services/validation.py).
- Generators refuse values with newlines, quotes, backslashes or control
characters; router maps validation errors to HTTP 400.
- Add change record and links.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>