|
In my
opinion, CRP provides a way to establish a trusted CA domain so that both the
initiator and responder can understand they have the ability to validate the
certificate send over through the certificate payload. As the initiator, if it
has multiple certificates issued by different CA's, it SHOULD send multiple CRPs
which contain the different CA DN. As a responder, when it receives the CRPs, it
SHOULD check if it holds any certificate issued by those CA's, then it has the
option to send the certificates which may be validated by initiator. Otherwise,
a certificate received in the certificate payload may not be validated because
the other party doesn't have the right CA certificate.
Regards!
Kaijun
|