Glad to see this happening - I removed CNNIC from my machines back in Feb - https://github.com/sammcj/delete-unknown-root-ca
How does this work, e.g., on systems which install root CAs from standard packages? I think you'll find you'll need to 1) re-run the script and 2) that you're not getting the benefit of retaining the root but flagging it as untrusted.
I just posted on flagging the CNNIC root as untrusted in Debian. That's better than deleting the CA, as it should now show as negative trust if I'm grokkign things properly.
It's not intended as patch or fix for the CA system which is broken by design - merely something that I was interested in trying.