Only somewhat joking: maybe there should be a rule that CAs are only allowed to issue to entities in foreign countries, outside traditional alliances, to ensure independence. I'm pretty confident Iranian intelligence couldn't pressure a major US CA to issue a cert for Iranian intelligence gathering; I'm pretty confident Turkish intelligence couldn't pressure a Japanese CA to issue for intelligence purposes. The problem is then US sites would need to get their certs from (at best) Russian or maybe Chinese CAs, and possibly only North Korean CAs.
This still doesn't prevent the "evil CA issues something covertly to do evil", but it at least leaves an audit trail in that legit, widely-used certs aren't likely to be issued to illegitimate parties.
The problems are mostly in business administration. A Japanese CA would need staff who can communicate in every foreign language that could be encountered in a 'hostile' nation. And they'd presumably have to get those employees from the Japanese population, because otherwise if you hire all Turkisk nationals at a Japanese CA, what's the point? Then they'd have to be willing to accept payment in the currency of all the hostile nations, etc.
Not to mention the difficulties of defining hostile nations. That would just further encourage countries like China and the US, which both want to intercept traffic, to negotiate with each other to get mutual access.
This still doesn't prevent the "evil CA issues something covertly to do evil", but it at least leaves an audit trail in that legit, widely-used certs aren't likely to be issued to illegitimate parties.