I'd be very surprised if Symantec doesn't have some backroom deal with intelligence agencies, and not just in the U.S. either, especially since they've acquired BlueCoat - a "security company" known for selling surveillance tools to authoritarian regimes - and after they made the BlueCoat CEO the CEO of Symantec.
Prior to the Symantec aquisition, VeriSign used to pitch just this thing as a product. AFAIK the usage was limited to DoD and a few mundane things. The IC wasn't interested because it was easier for them to just steal certificates or work around TLS completely.
The CA system is such an untrustworthy mess.
http://www.theverge.com/2017/1/25/14381174/microsoft-thailan...