This is needed to be able to access resources on external (to Bluemix) servers in SoftLayer that the client manages. Resources on these servers need to be accessed over https during CF operations (such as application staging) and by runtime operations. Without the self-signed certificates, the connections over https are not trusted and are failing, most likely due to security prompts. (The same connections over http: are working fine.)
One example of what the client is doing is specifying a custom buildpack on the CF push (ie, -b https://buildpack.mycustomdomain.com). CF is not able to download the buildpack due to the un-trusted connection.
Without having the certificate in CF, the https requests to the client-managed external servers will not be trusted and the connections will fail.
NOTICE TO EU RESIDENTS: per EU Data Protection Policy, if you wish to remove your personal information from the IBM ideas portal, please login to the ideas portal using your previously registered information then change your email to "email@example.com" and first name to "anonymous" and last name to "anonymous". This will ensure that IBM will not send any emails to you about all idea submissions