Certificates soft-link in system-wide location at /etc/ssl/certs
Key files goes into /etc/ssl/private
System-provided actual files are located at /usr/share/ca-certificates
custom certificates goes into /usr/local/share/ca-certificates
Whenever you put certificate in above mentioned path, run update-ca-certificate to
update /etc/ssl/certs lists