Thank you, Charles and Tom, for bringing this to the forefront.  We have
contacted the cross-signed partner and asked for an explanation. We've also
demanded revocation within 24 hours and a full scan to determine whether any
other certificates exist.  


Some additional problematic certs:

chains to Swisscom:  wxadm.swissucc.local

chains to CATCert, notBefore in 2017:   maritim4.mmaritim.local

chains to PROCERT, notBefore in 2017:  fospuca.local

chains to Baltimore Cybertrust Root (DigiCert):   lorweb.local

chains to Baltimore Cybertrust Root (DigiCert), notBefore in 2017:  skbfep01.justica.local  energy.ctd  and  pt

chains to QuoVadis, notBefore in 2017:  (swapped -/.)

chains to DocuSign, notBefore in 2017:   " " (trailing space)
