Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On Debian and Ubuntu, run sudo update-ca-certificates to refresh the system CA store. The command updates certificate links in /etc/ssl/certs and rebuilds the combined bundle at /etc/ssl/certs/ca-certificates.crt. These instructions apply to systems using Debian and Ubuntu’s ca-certificates implementation; other distributions may use different commands and paths.

Run the certificate update command

Open a terminal and run:

sudo update-ca-certificates

Use -v if you want verbose output, including certificate rehash details:

sudo update-ca-certificates -v

The command updates the local TLS certificate collection and generates the concatenated CA bundle. The Debian and Ubuntu command documentation describes it as updating /etc/ssl/certs and ca-certificates.crt (Debian man page; Ubuntu man page).

Add a locally supplied CA certificate

For a self-signed or corporate CA, use the CA certificate itself—not a server certificate—and make sure it is in PEM format. Save it as a .crt file beneath /usr/local/share/ca-certificates, with one certificate per file, then run the update command.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Install the certificate with a .crt extension. For example, if company-root.crt is in the current directory:

    sudo install -m 0644 company-root.crt /usr/local/share/ca-certificates/company-root.crt
  2. Refresh the system store:

    sudo update-ca-certificates

Debian’s documentation says local .crt files below this directory are included and implicitly trusted; Ubuntu’s server guidance also instructs administrators to run update-ca-certificates after adding a CA to the trusted list (Debian man page; Ubuntu server guidance). Because this adds trust at the machine level, only install a CA certificate from an organization or source you intend to trust.

Control distribution-provided certificates

The file /etc/ca-certificates.conf controls which certificates from /usr/share/ca-certificates are selected. A line beginning with # is a comment; a line beginning with ! deselects the certificate named on that line. Other listed certificate paths select certificates for trust. After changing the configuration, run sudo update-ca-certificates to rebuild the active store. The generated bundle is /etc/ssl/certs/ca-certificates.crt (Debian man page).

What the options do

Option Effect
-h, --help Show a summary of available options.
-v, --verbose Show verbose output, including rehash details.
-f, --fresh Remove existing symlinks in /etc/ssl/certs before rebuilding.
--certsconf Override the configuration file, normally /etc/ca-certificates.conf.
--certsdir Override the distribution certificate directory, normally /usr/share/ca-certificates.
--localcertsdir Override the local certificate directory, normally /usr/local/share/ca-certificates.
--etccertsdir Override the generated certificate directory, normally /etc/ssl/certs.

Use a fresh rebuild when you specifically need existing certificate symlinks removed before the store is recreated:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
sudo update-ca-certificates -f

The -f option is not the ordinary refresh command; for routine updates, use sudo update-ca-certificates. Option names and effects are documented in the Debian man page.

What happens after the store changes

Before exiting, the command runs hooks in /etc/ca-certificates/update.d. Hooks receive a list of changed certificates: additions are marked with + and removals with -. Packages can use these hooks to update related certificate stores when the main CA collection changes (Debian man page).

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Distribution scope

The command, paths, and option behavior here describe Debian and Ubuntu systems using the ca-certificates implementation. Do not assume the same command or directory layout on another Linux distribution; consult that distribution’s trust-store documentation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.