This is relevant for VSD-3.3 IMO since from a security standpoint it makes sense to regularly change the encryption subkeys and expire old ones while keeping the sign/certify key.
It should also allow you to create an Authentication / Sign subkey though since there are usecases for that, too.