It could be interesting to note that extracting all the cacerts from your local Firefox installation isn’t that tricky, if you just use some of the magic that are at hand with the NSS certutil tool.
Users of OpenSSL or GnuTLS based tools or libraries (such as libcurl) might be pleased to learn this.
curl users in general of course should be aware that we no longer ship any ca-cert bundle with curl (as of curl 7.18.1), as it seems some ports haven’t yet updated or discovered this.
Update: this script is now present as lib/firefox-db2pem.sh in the curl CVS repository.