Last time I checked we don't have any CA's from North Korea or Afghanistan...
Happy to be proven wrong.
Although you can argue that US' FPKI is "rogue" for the purposes of WebPKI (there's no control, no transparency, no audit etc.) and cross signature over FPKI Bridge was one of the reasons contributing to Symantec forcible retirement.
Last time I checked we don't have any CA's from North Korea or Afghanistan...
Happy to be proven wrong.