OK, that's a little awkward. A browser extension could automate this. But in practice, nobody wants to do this, because hardly anyone has opinions on particular CAs. It's a sort of meta-opinion - some people feel strongly they should be able to feel strongly about CAs, but hardly anyone actually does. So nobody uses such browser extensions.
On Firefox it's preferences -> advanced -> certificates -> view certificates.
Users have a clear stake in whatever informational exchange occurs between them and the websites we access. We should have the authority to participate in determining the terms on which that exchange is secured.
https://bugzilla.mozilla.org/show_bug.cgi?id=583935
But syncing which certificates to delete is probably a much harder sell.
At least there's a way to do programmatically:
apt-get install libnss3-tools
certutil -d /home/$USER/.mozilla/firefox/$FIREFOX_PROFILE -D -n $TARGET_CA_NAMEUnfortunately, it couldn't on Chrome, because you can't even access a page's certificate from an extension in Chrome:
http://stackoverflow.com/questions/18689724/get-fingerprint-...
And Firefox's certificate API is not much better, only passive access without ability to block connections if you detect an unwanted cert.
Nope. Firefox's Addon API lets you do pretty much whatever you want. It might be kind of hard and annoying, but you can certainly block connections that are signed by an untrusted CA. How do you think Convergence [0] worked?
https://developer.mozilla.org/en-US/Add-ons/Overlay_Extensio...
So with Firefox, you could build the kind of add-on described by Mike.
But I have confirmed for myself Chrome extension API's lack of ability to even read the certificate of a current page[1]. Chrome may be able to read block page loads (don't know, haven't checked) but without being able to even view a cert, it doesn't do much good.
1. https://code.google.com/p/chromium/issues/detail?id=93636
Incidentally, I can also add my own CA.