By setting strictcrlpolicy=yes, a strict CRL policy is enforced on all peers. The VPN gateway moon grants access to the hosts alice and venus to anyone presenting a certificate belonging to a trust chain anchored in the strongSwan Root CA. Therefore both road warriors carol and dave, holding certificates from the Research CA and Sales CA, respectively, can reach both alice and venus.