Incident Mis-Issued Certificates for IP Address 1.1.1.1
unmitigatedrisk.com
unmitigatedrisk.com
The intractable and difficult root (pun unintended) problem is OS/browsers/CA root cert list providers must delegate trust carefully to legit CAs while continually auditing they're not issuing garbage certs to entities that can't prove they own the subject(s) they're covering.
CA = Certifying Authority is the issuer of certs that make https:// work, but isn't limited to uses of just the web. S/MIME email, some software signatures, and more.