DNSSEC+DANE will fix it. Soon we will have self-signed certificates once again!
I can't wait. Now I can screw up DNSSEC and take out my entire domain in the process.