Installing SSL certificates "a la debian"
If you put new CA certificates in the right directory with the right name, they are treated as the official ones by the debian hooks:
sudo mv NEW-CA_Bundle.pem /usr/local/share/ca-certificates/NEW-CA_Bundle.crt
Launch this command to manually force the regeneration of the /etc/ssl/certs folder:
sudo update-ca-certificates