You can use the revocation list.
No need for recreating all the key's :)
Take a look at the how-to of the easy-RSA on how to creat a CRL.
also there is a sticky in the openVPN-forum about your question:
http://forum.pfsense.org/index.php/topic,4105.0.html