Because, as far as I understand, the answer is no: signing certs have no sense of signing "for an origin". If a CA issued me a CA cert, I could use it to create a signed cert for microsoft.com. Which seems nonsensical.
All I want is to get issued a CA cert that lets me sign arbitrary things within my domain's scope. Basically, the X.509 equivalent of a DNS NS record, delegating responsibility for making assertions about that domain (and only that domain) to "my" CA. Why is that so hard?