The package update-ca-certificates used here is specific to debian, while most linux distributions use the trust package, which is also included in debian. The relevant flag being trust --extract-compat. We should switch, but a simple replacement of the commands didn't work, so not sure when I'll have time to learn about what's going on, meantime posting here.