By setting strictcrlpolicy=yes, a strict CRL policy is enforced on all peers. The VPN gateway moon grants access to the hosts alice and venus to anyone presenting a certificate belonging to a trust chain anchored in strongSwan Root CA. Therefore both road warriors carol and dave, holding certificates from the Research CA and Sales CA, respectively, can reach both alice and venus.