So all good for RDO Juno!
Please note later -1 review from Nathan, I jumped to the conclusion!
"We still need to perform the PKI certificate setup, even if UUID
tokens are being used. The reason is that the token revocation list is
signed regardless of the token format. If the keys/cert are not
created, then an attempt to fetch the revocation list will result in
signing errors due to an underlying ENOENT."