Locating the cacerts file


What's inside this article ⌄
  • Cacerts file location
  • Linux cacerts
  • MacOS cacerts
  • Windows cacerts

The cacerts file is a collection of trusted Certificate Authority (CA) certificates. It is used to establish trust by Java-based applications and tools.


Linux & macOS

The cacerts file is located in the Java Runtime Environment (JRE) distribution under the following path:

<jre_path>/lib/security/cacerts

The file does not specify an extension in its name but is of JKS (Java Keystore) type. In some cases (e.g., ZooKeeper), you may need to explicitly specify the file type using a property like ssl.trustStore.type.

If you have Java installed and can execute java in a terminal, the following commands can help you locate the cacerts file:

Step 1: Find the Java executable path:

readlink -f $(which java)

This command uses:

  • which: Locates the java executable being used.
  • readlink: Resolves the symbolic link to the actual location of the file.

Example output:

/usr/java/jdk1.8.0_111/jre/bin/java

Step 2: Replace /bin/java with the path to the cacerts file:

/usr/java/jdk1.8.0_111/jre/lib/security/cacerts

Windows

Step 1: Locate the Java executable:

where java

This command provides the location of the Java executable file being used.

Step 2: Resolve the directory of the link: Run the findstr and dir commands to determine the target file of the link:

findstr java | dir /a "<path to the folder with the link from the previous command>"

Example output:

C:\Program Files\Java\jre1.8.0_111\bin\java.exe

Step 3: Replace bin\java.exe with the path to the cacerts file:

C:\Program Files\Java\jre1.8.0_111\lib\security\cacerts

Notes

  • Ensure you have appropriate permissions to access the cacerts file.
  • When specifying the cacerts file in Java-based configurations, also configure the password for it (default is usually changeit, unless modified).