更新时遇到的ssl证书的问题

我尝试过「已解决」GPGME密钥和PGP签名问题 / 新手园地 / Arch Linux 中文论坛 -U 的方式覆盖原来的gpg,现在安装一个包或者更新似乎都是正常使用的,只是更新后依然报错

sudo pacman -Syu
:: Synchronizing package databases...
 core is up to date
 extra is up to date
 multilib is up to date
error: failed retrieving file 'core.db' from sg.mirrors.cicku.me : SSL certificate problem: unable to get local issuer certificate
error: failed retrieving file 'extra.db' from sg.mirrors.cicku.me : SSL certificate problem: unable to get local issuer certificate
error: failed retrieving file 'multilib.db' from sg.mirrors.cicku.me : SSL certificate problem: unable to get local issuer certificate
warning: too many errors from sg.mirrors.cicku.me, skipping for the remainder of this transaction
:: Starting full system upgrade...
 there is nothing to do

cicku.me 的证书似乎是有点问题,我的 curl 和 wget 也会报错。它发送了三个证书,最后一个是由「AAA Certificate Services」签名的——这个根证书我本地并没有。但该证书同时也被「SSL.com TLS ECC Root CA 2022」签名,这个有,并且会被浏览器认可。

https://www.ssllabs.com/ssltest/analyze.html?d=sg.mirrors.cicku.me&s=2606%3A4700%3A78%3A0%3A0%3A90%3A0%3A1c4&latest

Mozilla NSS 更新把 Sectigo 的一个 root 删了

https://gitlab.archlinux.org/archlinux/packaging/packages/nss/-/issues/1