They're using a CACert (a kind of community-based CA) certificate, that isn't trusted by default on most systems.
If the root certificate you're getting is from "CA Cert Signing Authority" and matches the details given on http://www.cacert.org/index.php?id=3 then you're probably not being MITM'd.