> I personaly cannot think of a good reason they do this. Maybe they argue that they don't trust any CA Authorities other than themselves
They do it precisely because they cannot trust any other CAs. You cannot trust any CAs — and yet you do. Go into your browser: odds are you have CAs controlled by the Russian, Chinese & Turkish governments. You're not just trusting those CAs to issue certificates for .cn, .ru or .tr: you're trusting them for every TLD in the world, to include .com, .gov & .mil. Yes, if you're using XPKI (the standard PKI basically everything on the Internet uses), you're trusting that the Chinese government will never man-in-the-middle your sessions with the IRS. The DoD (rather wisely) chooses to trust only itself to certify itself.
My own opinion is that what we should have done was adopt a system which leveraged DNS to delegate trust (note that this is what Let's Encrypt does), and that we should have rooted DNS in a multinational board: if the U.S., China, Russia, Iran, the United Kingdom, the Ukraine, France & Mexico all agree on something, it's really very likely to be true.
We should also have leveraged IP assignments. Imagine if when you talked to a system it produced proof that it really is allowed to have its IP address and that it really is allowed to speak for a particular domain. That's really what people want, not some sort of nebulous tie to a real-world identity. What we care about is that facebook.com is facebook.com, not that it's Facebook, Inc., headquartered in Menlo Park.