There are cases when the certificates issued by the Certifier Service need to have a DNS record in order to be accepted by certain applications. We already put the IP address of the remote peer but this is not enough. Ideally, there should be a mechanism similar to Certificate Signing Request where you can put all of the requested props and then have it signed by the CS.