Self-signed certificates, trust on first use (or verify out of band) like SSH, works around most of this
So it's not technically infeasible to have networking gear drop any connection which doesn't chain back to a government-approved root?
Yse, and that is a very scary thought. China is doing something similar already.
Only on old TLS versions. TLS 1.3 changed it so the server certificate is also encrypted.