What is your rationale behind this (if I understood it correctly) being a Service rather than a way of doing things ?
It's becoming increasingly difficult for me to run my own code, that I am perfectly happy to sign myself, on my own devices. That might seem like a fringe case. But it shows a deeper problem:
I do not trust you. I don't even know you in the first place.
Yet you (well, as part of a goup) are asking me to give you more power over my devices.
What is this push towards centralizing trust ?
Example: Firefox extensions need to be signed now. I can't send my friends the extensions I wrote myself. There is just no way. I can't go over to their house, sit next to them, and install my self signed-root certificate, and have their version of firefox trust it.
It must be signed by Mozilla: An organization that most people will never ever in their lives's interact with. That makes no sense.
And not even to speak of trying to install private Root CAs into iPhones or Android devices.
How does your solution empower users to own their own devices, and not have them owned by someone they are separated from by several degrees and whom they have never met ?