DEV Community

Artem
Artem

Posted on

3 2

SSL certificate for java application

A third-party service is available via https, so how can java app connect to that service?

Truststore and Keystore

Java has two places for save certificate: truststore and keystore

Truststore - for client and public key
Keystore - for private key

In our task we need a truststore

Tools

For SSL certificate use such tools like openssl and keytool from jdk

Example

First of all download certificate from third-party-service.

sudo rm -f thirdPartyCert.pem && sudo echo -n | openssl s_client -showcerts -connect third-party-service:443 | sed -ne '/-BEGIN CERTIFICATE-/,/-END CERTIFICATE-/p' > thirdPartyCert.pem
Enter fullscreen mode Exit fullscreen mode

Copy current truststore

cp $JAVA_HOME/lib/security/cacerts currentCacerts
Enter fullscreen mode Exit fullscreen mode

Import the new certificate to truststore

keytool -import -trustcacerts -keystore "currentCacerts" -alias third-party-service -file "thirdPartyCert.pem" -storepass changeit
Enter fullscreen mode Exit fullscreen mode

Check certificate

keytool -list -v -keystore currentCacerts -alias third-party-service -storepass changeit
Enter fullscreen mode Exit fullscreen mode

Use the option to add a certificate while launching your app

-Djavax.net.ssl.trustStore=mySuperCacerts
Enter fullscreen mode Exit fullscreen mode

Perfect!
Alt Text

Image of Datadog

Create and maintain end-to-end frontend tests

Learn best practices on creating frontend tests, testing on-premise apps, integrating tests into your CI/CD pipeline, and using Datadog’s testing tunnel.

Download The Guide

Top comments (0)

The Most Contextual AI Development Assistant

Pieces.app image

Our centralized storage agent works on-device, unifying various developer tools to proactively capture and enrich useful materials, streamline collaboration, and solve complex problems through a contextual understanding of your unique workflow.

👥 Ideal for solo developers, teams, and cross-company projects

Learn more