It is for generation and sharing of SSL certificates (keys need to be 600 permission and root in CT as well as 600 and root in another container, host, server where the storage is used).
Doing it with user would require a lot of work in many containers, servers to change.. maybe that container...