Doesn't this effectively render corporate CAs useless?
I just hope they automatically disable it for non-public tlds, both from IANA and RFC 6762.
[0] https://wiki.mozilla.org/SecurityEngineering/Certificate_Tra...
All of the browsers ignore transparency for enterprise roots. To determine which is which, the list of actual public roots is stored separately in the CA database, listed in chrome://certificate-manager/crscerts for Chrome and listed as a "Builtin Object Token" in Firefox's Certificate Manager.