The Tor service model is equivalent to if every site used a self-signed certificate, which doesn't scale.
The more feasible CA-free architecture is to have the browser operator perform domain validation and counter-sign every sites key, but that has other downsides and is arguably even less distributed.