My solution was actually to install the ISSUER certificate for our organizations root CA (which hijacks GitHub, and others) into /usr/local/share/ca-certificates, then run 'sudo update-ca-certificates'.

If the certificate is available in DER format (might be the case if you got it from somewhere Microsofty), you can convert using 'openssl'.
<code class="language-bash">
openssl x509 -in YourOrgRootCA.der -inform der -outform pem -out YourOrgRootCA.crt

The '.crt' extension seems to be required, otherwise 'update-ca-certificates' won't pick up the new certificates.
