That's dumb.
If you're going to install a new root certificate on all your client machines, you could just as well generate your own CA inside your organization and do the same thing without trusting some third party.
(Edit: I think I've been trolled.)