update-ca-certificates - update /etc/ssl/certs and ca-certificates.crt
update-ca-certificates [--fresh]
Options you will use
--fresh- rebuild from scratch
Examples
$ sudo cp corp-root.crt /usr/local/share/ca-certificates/ && sudo update-ca-certificatestrust a company CA system-wide
Gotchas
- Only files ending in .crt under /usr/local/share/ca-certificates are picked up. A .pem there is silently ignored.
- This is the OS store (curl, openssl, python requests with certifi aside). A JDK from a tarball or a vendor image keeps its own cacerts.
Try update-ca-certificates in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.