The first question would be is the role of the application that needs to communicate with many vendors as a server or as a client. If it is a server and treating all the vendors the same (according to the defined policies), then one keyring with one server chain is sufficient.
If different vendors are treated differently, different server cert chains are needed. A single keyring can still be used if different cert labels are used for different vendors, otherwise you need to have individual keyring for each vendor.
If it plays the role of a client, a keyring ring with all the vendor's CA certificate or a CERTAUTH virtual keyring can work.
------------------------------
Wai Choi
------------------------------