Without a Certificate Authority (CA), each server has their own certificate; which users has to trust, each time it communicates with it.
I.e users has to store multiple self signed certificates from unknown source in their Database.
With a CA, only one certificate has to be trusted for all servers in IITK.