How about the TLD NICs sign your certificates when you register the domain?
Ideally they have already verified your name, company and address, and you have to trust them to some extend anyway, because they are responsible for the name servers
Ideally they have already verified your name, company and address, and you have to trust them to some extend anyway, because they are responsible for the name servers
So this is not solving the problem, this is moving it elsewhere.