> This update uses https by default, but one of the servers answering to > bugs.debian.org (bembo.debian.org) uses a TLS certificate that is not > signed by a well-known authority, leading to the certificate > verification failure.
You can probably forget about that, further investigation seems to show that I messed up during my tests and something else is amiss. Sorry for the noise.