OnCallReady

Commands

keytool - manage a Java keystore of cryptographic keys, certificate chains and trusted certificates

keytool -command [options]

Options you will use

-list -cacerts
the JDK's own truststore
-list -keystore F -storepass P
a specific keystore
-importcert -alias A -file F -cacerts
trust a CA (default store password: changeit)
-noprompt
do not ask "Trust this certificate?"
-printcert -file F
decode a certificate file
-list
List the entries in a keystore.
-importcert
Import a certificate (or chain) as a trusted entry.
-exportcert
Export a certificate.
-printcert
Print a certificate file.
-delete
Delete an entry.
-genkeypair
Generate a key pair and a self-signed certificate.
-alias ALIAS
The name of the entry in the keystore.
-file FILE
The certificate file to import, export or print.
-cacerts
Use the JDK's own truststore ($JAVA_HOME/lib/security/cacerts) instead of -keystore.
-keystore FILE
The keystore file (default ~/.keystore).
-storepass PASSWORD
The keystore password. The JDK cacerts default is changeit. On the command line it shows up in ps and shell history.
-storetype TYPE
PKCS12 (the default since JDK 9) or JKS.
-noprompt
Do not ask "Trust this certificate? [no]:" - needed in scripts and Dockerfiles.
-v
Verbose: print every certificate in full.
-rfc
Print certificates in PEM form.

Examples

$ keytool -list -cacerts -storepass changeit | grep -i labcorp

is our CA there

$ sudo keytool -importcert -noprompt -alias labcorp-root -file labcorp-root.crt -cacerts -storepass changeit

add it

Gotchas

Taught in

Try keytool in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.