(I am just looking into certificate pinning, but CA can generate another certificate or wildcarded certificate that client trusts, which enables mitm, I am doing it all the time on https proxy (http://www.squid-cache.org/Doc/config/ssl_bump/). This way you can decrypt traffic - redirect traffic to your server and impersonate the right one while proxying data from original server)