From what I understand, the certificate authorities (CAs) have to get their root certificate included in the browser.
What if the root certificate of a particular CA is not included in the web browser yet. Is there another way to get it in? Maybe my question is not clear enough. The question shoud be : in a PKI hierarchical model, if subCAs have not root certificate include in web browser then how subCAs can get in?