System checking it just verifies the signature is valid and thus all data presented is valid? Your browser doesn't need to query any Root CAs to trust SSL certificate, https works without internet.
History of entry and visas/etc could be stored on device as well
If you want to argue for a theoretical system that is self-contained, only relies on the data that is present on either the physical (or the theoretical cryptographically signed digital) passport, you're free to do that.
But in the real world, the systems that deal with processing people's entries already cross-reference multiple other existing databases, require internet connectivity to do so, and I think you'll have hard time convincing anyone to stop doing that.