...or it may never get updated after single installation of
ca-certificates-update. Let's assume anyone with custom certificates has
ca-certificates-update which will update ca-certificates.crt after
upgrade
%dir /etc/ssl/certs
/etc/ssl/certs/ca-certificates.crt
%config(noreplace) %verify(not md5 mtime size) /etc/pki/tls/certs/ca-bundle.crt
-%config(noreplace) %verify(not md5 mtime size) %{certsdir}/ca-certificates.crt
+%verify(not md5 mtime size) %{certsdir}/ca-certificates.crt
%files update
%defattr(644,root,root,755)