Not a security expert here but it seem like akamai should also be required to use a root CA that does not use md5 for it's encryption. It am under the impression that md5 based encryption has been broken since 2008:
http://www.win.tue.nl/hashclash/rogue-ca/#sec71