The roadwarriors carol and dave set up a connection each to gateway moon. The authentication is based on X.509 certificates. Gateway moon has already loaded a revoked certificate for carol and a self-signed certificate for dave locally but gets actual certificates as CERT payloads from both peers. The RSA signature verification process tries all candidate peer certificates until it finds a valid one with a matching public key.