Add SSL certificate from URL to JKS


What's inside this article ⌄
  • How to import URL certificate JKS
  • Add SSL cert from url to keystore
  • Download certificate to JKS
  • Java keystore add URL certificate

Let’s imagine that you need to download a certificate from a website / service / endpoint and put it in the trusted certificates store (JKS or cacerts).

To do this, you need to fill in the parameters SERVER_URL, ALIAS_NAME, CERT_NAME and run the script:

1# parameters
2SERVER_URL=serverhost:serverport
3ALIAS_NAME=your_alias
4CERT_NAME=trust
5
6# action
7openssl s_client -showcerts -connect ${SERVER_URL} </dev/null 2>/dev/null|openssl x509 -outform PEM >${CERT_NAME}.pem
8openssl x509 -outform der -in ${CERT_NAME}.pem -out ${CERT_NAME}.der
9keytool -import -alias ${ALIAS_NAME} -keystore ${CERT_NAME}.jks -file ${CERT_NAME}.der

As a result, a trusted jks storage will be created with the name CERT_NAME, which will contain the certificate of the specified URL

If you need to add a certificate to java standard cacerts, then you need to replace ${CERT_NAME}.jks in the last command to cacerts.