The VPN gateway moon grants access to the subnet behind it to anyone presenting a certificate belonging to a trust chain anchored in the strongSwan Root CA. The hosts carol and dave have certificates from the intermediate Research CA and Sales CA, respectively. Responder moon does not possess copies of the Research and Sales CA certificates and must therefore request them from the initiators carol and dave, respectively.