This article goes over a possible solution for Authentication Issues when using certificates as the authentication method in a VPN.
Trusted CA profile profile-name not matched
Trusted CA Contraints Failed
Delete the following statement if configured:
set security ike policy ike-policy trusted-ca ca-profile profile-name;
After that, if the config was ok and you got the error mentioned above, the VPN should come up, this does not bypass Certificate Validation, cert validation is still done and you can see it using PKI traceoptions.