If you use the MITM judiciously, it's very likely that nobody will notice, or that those that notice can be compelled not to say anything.
Besides, if you have enough access to the CA, you can just get whatever cert is in the transparency log, though that's almost certainly harder for most nations and CAs.
That would require compromising the certificate requester.
But it requires a lot more steps.
Chrome, Safari, Firefox.
> And do all CAs support it?
Yes, the browsers made them.
> Besides, if you have enough access to the CA, you can just get whatever cert is in the transparency log
No, the CA doesn't have the private key of certs.
> No, the CA doesn't have the private key of certs.
Woops, yeah good point.
Sounds from other comments like my knowledge is out of date though, and browsers have real protections against the obvious ways that used to be possible, which is great news.
Of course then the question is how quickly browsers can roll out an update/config to distrust all future certs from said CA.