RSA-SIG is used for the authentication of the VPN-peers. With that, PSKs are not needed any more. But authenticating the VPN is only one step in setting it up. Both peers still need key-material for the encryption and integrity-protection. All this key-material is typically generated with Diffie-Hellmann and still needed regardless of the way you authenticate your peer.