Doesn't the Great Firewall mandate (or at least strongly suggest) that those Chinese-controlled root certs are installed for devices behind it?
If this were a root cert, OSes and browsers could ban that CA. If you want this to work with SSL, giving the Great Firewall a domain cert would be enough.