On Debian and Ubuntu, run sudo update-ca-certificates to refresh the system CA store. The command updates certificate links in /etc/ssl/certs and rebuilds the combined bundle at /etc/ssl/certs/ca-certificates.crt. These instructions apply to systems using Debian and Ubuntu’s ca-certificates implementation; other distributions may use different commands and paths.
Run the certificate update command
Open a terminal and run:
sudo update-ca-certificates
Use -v if you want verbose output, including certificate rehash details:
sudo update-ca-certificates -v
The command updates the local TLS certificate collection and generates the concatenated CA bundle. The Debian and Ubuntu command documentation describes it as updating /etc/ssl/certs and ca-certificates.crt (Debian man page; Ubuntu man page).
Add a locally supplied CA certificate
For a self-signed or corporate CA, use the CA certificate itself—not a server certificate—and make sure it is in PEM format. Save it as a .crt file beneath /usr/local/share/ca-certificates, with one certificate per file, then run the update command.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors#1 Best Overall
-
Install the certificate with a
.crtextension. For example, ifcompany-root.crtis in the current directory:sudo install -m 0644 company-root.crt /usr/local/share/ca-certificates/company-root.crt -
Refresh the system store:
sudo update-ca-certificates
Debian’s documentation says local .crt files below this directory are included and implicitly trusted; Ubuntu’s server guidance also instructs administrators to run update-ca-certificates after adding a CA to the trusted list (Debian man page; Ubuntu server guidance). Because this adds trust at the machine level, only install a CA certificate from an organization or source you intend to trust.
Control distribution-provided certificates
The file /etc/ca-certificates.conf controls which certificates from /usr/share/ca-certificates are selected. A line beginning with # is a comment; a line beginning with ! deselects the certificate named on that line. Other listed certificate paths select certificates for trust. After changing the configuration, run sudo update-ca-certificates to rebuild the active store. The generated bundle is /etc/ssl/certs/ca-certificates.crt (Debian man page).
What the options do
| Option | Effect |
|---|---|
-h, --help |
Show a summary of available options. |
-v, --verbose |
Show verbose output, including rehash details. |
-f, --fresh |
Remove existing symlinks in /etc/ssl/certs before rebuilding. |
--certsconf |
Override the configuration file, normally /etc/ca-certificates.conf. |
--certsdir |
Override the distribution certificate directory, normally /usr/share/ca-certificates. |
--localcertsdir |
Override the local certificate directory, normally /usr/local/share/ca-certificates. |
--etccertsdir |
Override the generated certificate directory, normally /etc/ssl/certs. |
Use a fresh rebuild when you specifically need existing certificate symlinks removed before the store is recreated:
sudo update-ca-certificates -f
The -f option is not the ordinary refresh command; for routine updates, use sudo update-ca-certificates. Option names and effects are documented in the Debian man page.
What happens after the store changes
Before exiting, the command runs hooks in /etc/ca-certificates/update.d. Hooks receive a list of changed certificates: additions are marked with + and removals with -. Packages can use these hooks to update related certificate stores when the main CA collection changes (Debian man page).
Rank #4
Distribution scope
The command, paths, and option behavior here describe Debian and Ubuntu systems using the ca-certificates implementation. Do not assume the same command or directory layout on another Linux distribution; consult that distribution’s trust-store documentation.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →

