Why stop there? Why not sign and verify off the mother of all root CA’s, your TPM 2.0 Module EEPROM?
(fun to walk down through the trees and the silicon desert of despair, to the land of the ROM, where things can never change)