During mutual TLS authentication, the phone validates the provisioning server certificate and presents an identity certificate to the provisioning server. To validate the certificate, the provisioning server must trust the root certificate authority (CA) certificate issuing the phone identity certificate.