And significant part of security is concentrated around the way Certifying Authorities validate the domain ownership. (So called challenges).
Next, maybe clients can run those challenges directly, instead of relying onto certificates? For example, when connecting a server, client client sends two unique values, and the server must create DNS record <unique-val-1>.server.com with record value of the <unique-val-2>. Client check that such record is created and thus the server has proven it controls the domain name.
Auth through DNS, that's what it is. We will just need to speed up the DNS system.