Add CA cert file to /usr/share/local and then run update-ca-certificates. This command will consider files with .crt extension
Text Box
root@cic-certvalidation-kh5tp:/etc/ns-cacert/cic-certs# ls
ns-cacert.cert
root@cic-certvalidation-kh5tp:/etc/ns-cacert/cic-certs# cp ns-cacert.cert /usr/local/share/ca-certificates/ns-cacert.crt
root@cic-certvalidation-kh5tp:/etc/ns-cacert/cic-certs# update-ca-certificates
Updating certificates in /etc/ssl/certs...
WARNING: Skipping duplicate certificate ns-cacert.cert
WARNING: Skipping duplicate certificate ns-cacert.cert
1 added, 0 removed; done.
Running hooks in /etc/ca-certificates/update.d...
done.
Useful link: https://askubuntu.com/questions/645818/how-to-install-certificates-for-command-line
http://manpages.ubuntu.com/manpages/disco/en/man8/update-ca-certificates.8.html
https://serverfault.com/questions/62496/ssl-certificate-location-on-unix-linux
Method to list CA certificates
root@cic-certvalidation-kh5tp:/etc/ns-cacert/cic-certs# awk -v cmd='openssl x509 -noout -subject' '/BEGIN/{close(cmd)};{print | cmd}' < /etc/ssl/certs/ca-certificates.crt
subject= /CN=ACCVRAIZ1/OU=PKIACCV/O=ACCV/C=ES
subject= /CN=ACEDICOM Root/OU=PKI/O=EDICOM/C=ES
subject= /C=ES/O=FNMT-RCM/OU=AC RAIZ FNMT-RCM
subject= /C=IT/L=Milan/O=Actalis S.p.A./03358520967/CN=Actalis Authentication Root CA
.....
Useful link: https://unix.stackexchange.com/questions/97244/list-all-available-ssl-ca-certificates