There can still be a root password for emergencies, but it wouldn't be available for remote access -- ILOM or some other BMC (or even a serial port concentrator) would be configured for HSPD-12-compliant auth for remote console access, then you would use the root password for system access (though you could also just reboot into a separate operating system, since disk encryption isn't required except for mobile devices).
I'm not sure what the above poster's command or organization was doing to comply with HSPD-12, but they were most likely doing something. The compliant reports are generally public, also.
CAC login is for web only in most cases.
In my experience, at every place we had a different approach but all satisfied HSPD-12 and did not use passwords shortly after the various directives were promulgated through the various channels, except on classified systems since there wasn't a procedure at the time to declassify the CAC/PIV after periods processing -- though there were plans for changing that, and it may be resolved by now.