CA certificate-signing keys, certificate status signing keys and keys that sign updates to authorised host lists in encryption devices serve nothing beyond subordinate certificate requests, status checking and self-signed roots, whether combined or as separate dedicated keys.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.