In the scheme described, users don't log into servers with the CA's certificate and private key -- the CA's private key is always protected, preferably in an HSM of some sort. Instead, the CA issues a signed certificate to the user with a set of principals; and that latter certificate is the one used to log in.
So, the process that issues certificates (the "Authority", as opposed to the "Authority Certificate") is the one I'm concerned with here.