I never understood how trustworthy is cert that you could buy for 100$. What that certificate proves? That whoever signed the stuff had a 100$ at some point?
Besides ... why can't java just pull the certs out of the system (like you did manually) or ship with them like every browser does (I presume).