Could someone tell me if this is correct? In an IKE negotiation using RSA-signatures: When sending a CR the payload contains the Subject name of the CA in used and it's sent in its binary format (ASN.1 representation) When receiving it, it must match the Issuer name of the certificate to be sent. Is there any error in this? Tonino