Correct me if I'm wrong, but the signed server-identifying cert is swapped in TLS before the connection is encrypted, no?
So it's not technically infeasible to have networking gear drop any connection which doesn't chain back to a government-approved root?