It doesn't matter much for TLS certificates (the slowness might though) except if they choose to issue another certificate under your name with their private key to MITM your connections, it'd look more legitimate if your real certificate is issued by the same CA, but admittedly, the real issue here is on the client side: browsers trusting way too many CAs that directly include many governments.