That makes sense. The downside is that now if said CA has some interests in whether to re-issue a certificate or not, we have a problem. Imagine that Cloudfare decides you are a bot and doesn't allow you to visit pages. You are going to have a problem because a lot of websites use it
I think the idea of a CA is good but it should be distributed somehow