How would clients receive the trusted CA data from the registrar? DNS?
This would very easily be susceptible to MITM attacks. Any DNS security to prevent MITM attacks is going to have the same CA issue we currently have.