> Don’t we already just use the certificates to just negotiate the final encryption keys?
No, since forward secret key agreement the certificate private key isn't involved at all in the secrecy of the session keys; the private key only proves the authenticity of the connection / the session keys.