Indeed, the main problem of trust is the third party and agreement.
The DID and VC standards have an interesting approach. Use self-signed public keys, and third-party-signed credentials. To prevent MITM use credentials, to encrypt channel use the keys.
The agreement part, however, remains difficult because the protocols are always evolving.
Maybe in a few years we'll get it solved, just like Bitcoin solved double-spending without centralization?