FOIA the PRISM tech stack 13 years ago
If I remember correctly, Verisign has indicated they would be willing to create a trusted root level certificate for the government to spoof the ssl of any domain... so I don't know if SSL is enough, unless you only allow CAs you've created or you trust.