I have, I've set up "truly offline" root certificate authorities and the like in the past.
Yes, it's a pain to operate, but if the alternative is "the bad guys get all of our money", then it can be worth it.