keytool - manage a Java keystore of cryptographic keys, certificate chains and trusted certificates
keytool -command [options]
Options you will use
-list -cacerts- the JDK's own truststore
-list -keystore F -storepass P- a specific keystore
-importcert -alias A -file F -cacerts- trust a CA (default store password: changeit)
-noprompt- do not ask "Trust this certificate?"
-printcert -file F- decode a certificate file
-list- List the entries in a keystore.
-importcert- Import a certificate (or chain) as a trusted entry.
-exportcert- Export a certificate.
-printcert- Print a certificate file.
-delete- Delete an entry.
-genkeypair- Generate a key pair and a self-signed certificate.
-alias ALIAS- The name of the entry in the keystore.
-file FILE- The certificate file to import, export or print.
-cacerts- Use the JDK's own truststore ($JAVA_HOME/lib/security/cacerts) instead of -keystore.
-keystore FILE- The keystore file (default ~/.keystore).
-storepass PASSWORD- The keystore password. The JDK cacerts default is
changeit. On the command line it shows up in ps and shell history. -storetype TYPE- PKCS12 (the default since JDK 9) or JKS.
-noprompt- Do not ask "Trust this certificate? [no]:" - needed in scripts and Dockerfiles.
-v- Verbose: print every certificate in full.
-rfc- Print certificates in PEM form.
Examples
$ keytool -list -cacerts -storepass changeit | grep -i labcorpis our CA there
$ sudo keytool -importcert -noprompt -alias labcorp-root -file labcorp-root.crt -cacerts -storepass changeitadd it
Gotchas
- The JVM reads the truststore at startup: restart the service after importing.
- The JDK's cacerts is replaced on every JDK upgrade. Imports made by hand vanish with it.
Taught in
Try keytool in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.