man update-ca-certificates:
update-ca-certificates is a program that updates the directory
/etc/ssl/certs to hold SSL certificates and generates certificates.crt,
a concatenated single-file list of certificates.
It reads the file /etc/ca-certificates.conf. Each line gives a pathname
of a CA certificate under /usr/share/ca-certificates that should be
trusted. Lines that begin with "#" are comment lines and thus ignored.
Lines that begin with "!" are deselected, causing the deactivation of
the CA certificate in question.
Furthermore all certificates found below /usr/local/share/ca-
certificates are also included as implicitly trusted.
Do que foi dito acima, eu diria que a maneira preferida de obter arquivos de certificado local no armazenamento confiável é colocá-los em / usr / local / share / ca-certificates e, em seguida, executar update-ca-certificates. Você não precisa tocar diretamente em / etc / ssl / certs.
Nomear os certificados com extensões .crt também parece ser necessário.