Where Are Trusted CA Certificates Stored on Linux?
Where Linux keeps trusted CA certificates on Debian and Red Hat families, and the commands that rebuild the store.
Last updated
Linux keeps trusted certificate authorities in different trees per distro family. Debian builds a bundle at /etc/ssl/certs from sources under /usr/share and /usr/local/share via update-ca-certificates. Red Hat consolidates under /etc/pki with update-ca-trust reading anchors and blocklists.
Your own certificates always go in the local or admin tier, never in the generated bundle. The update commands merge everything into the files applications actually read. Java keeps a separate cacerts keystore that trails the same sources through its own extraction.
Where Linux stores this, by platform
/etc/ssl/certs/ca-certificates.crt
Generated bundle plus per-certificate directory for OpenSSL apps. Drop custom PEM .crt files in /usr/local/share/ca-certificates, then run update-ca-certificates. The ca-certificates.conf file selects which distro certs stay active.
/etc/pki/ca-trust/extracted/openssl/ca-bundle.trust.crt
Red Hat family consolidated store: anchors for additions, extracted bundles for readers. Drop custom PEM files in /etc/pki/ca-trust/source/anchors/, then run update-ca-trust extract. Java cacerts and OpenSSL bundles regenerate from the same sources.
Frequently asked questions
how do I trust a company root CA
Copy the PEM .crt file into /usr/local/share/ca-certificates on Debian or the anchors folder on Red Hat, then run the update command for your family. Verify with a listing of the generated bundle. Applications using the system OpenSSL store pick it up immediately.
how do I remove a CA
Delete the source file and rerun the update command to regenerate the bundle without it. Never hand-edit the generated bundle files since the next update overwrites them. Revoked commercial CAs disappear through package updates instead.
do browsers use the system store
No. Firefox keeps its own certificate store separate from the system bundle and needs its own import. Chromium mostly follows the system store. Server tools like curl read the system bundle, which is why this page centers on it.
Notice an outdated path? Let us know.