I wrote:
Ohta-san is using the term MiTM in an unusual way.
Wrong. See, for example,
More facts have recently come to light about the compromise
of the DigiNotar Certificate Authority, which appears to have
enabled Iranian hackers to launch successful man-in-the-middle
attacks against hundreds of thousands of Internet users inside
and outside of Iran.
Sorry, this is not a good reference because it mentions MitM attack
on ISP chain is enabled by diginotar.
A proper reference is:
Intermediate Certificate – Intermediate certificates branch
off of root certificates like branches off of trees. They
act as middle-men between the protected root certificates
and the server certificates issued out to the public.
Masataka Ohta
DNSOP mailing list