ca-certificates in stretch and ascii is quite old and includes the
expired DST Root CA X3 certificate, which might be used to validate some
(all?) certificates from Let's Encrypt, including deb-multimedia.org.
Try disabling that certificate: see update-ca-certificates(8) and/or
<https://serverfault.com/a/1079226>.