Hot to Use Java Keystore with Custom SSL Certificates
igorstechnoclub.com
igorstechnoclub.com
It’s not a huge deal in the grand scheme of things, but it’s frustrating to need to do something special just for Java.
I’ll say that it feels somewhat pointless on every system I’ve personally used it on. In all cases I’m still generating my private key in PEM format and using filesystem permissions to restrict access. So the PKCS12 / JKS password stuff just becomes another thing to bother with that doesn’t provide any real improvement to security.
Now maybe we should be deleting that PEM once we slurp it into the keystore, and actually setting real keystore passwords sourced from a secure location and only kept in memory, etc. I’d definitely rather not though.