It then compares the decrypted message CA_Randl with the original message that is encapsulated in the proxy credential. The expiration time of the proxy credential as well as the expiration time of the public key MN_Pub are also checked. If one of these checks results false, the master node is not authenticated as well. In this case, a refusal message with reasons is sent back to the master node. The authentication phase is then terminated.