CA authorities can set the date when the certificate was issued to any date they like, bypassing the "trusted until" mechanism. Such a CA can still issue any certificate they like, pass browser checks and do MitM. In this way you still trust them to sign the correct issue date while you want to distrust them. Isn't Mozilla's mechanism kind of weird by being not "too simple"?
I don't think using curl and openssl directly check CT, though....