Strongswan roadwarrior scenario with pubkey authentication issues
The value of the CN
RDN can't be matched individually in strongSwan (unless you actually configure it as partial DN and enable relaxed RDN matching in strongswan.conf).
The configured identity either has to be the full subject DN or a subjectAltName (SAN) contained in the certificate.