> every web browser in the world will be forced to trust the root certificates from all European Trust Service Providers
What I could never understand is why limiting the scope of root certificates is not a standard feature? Why cannot I set a whitelist of domains for the specific root certificate and expect the connection to fail when this root is used for anything else?