Yeah, something weird is going on here. On a freshly installed macOS 10.12 machine here in my office the DoD Root CA 2 root certificate is in the System Roots keychain, where is where you’d expect to find built-in root certificates, and it’s marked as trusted. However, my day-to-day work machine is showing exactly the same state as you’re seeing: DoD Root CA 2 is in the login keychain and is thus untrusted. I suspect that there’s something broken in how the system roots are handled during an OS upgrade.
You should file a bug about this; please post your bug number, just for the record.
You should be able to work around this by dragging the DoD Root CA 2 to your System (not System Roots) keychain and then marking it as trusted, just like you’d trust any other root certificate.
Share and Enjoy
—
Quinn “The Eskimo!”
Apple Developer Relations, Developer Technical Support, Core OS/Hardware
let myEmail = "eskimo" + "1" + "@apple.com"