...
Ensure certificate files are in PEM format by opening in a text editor. If the file appears to have special characters or does not start with “-----BEGIN CERTIFICATE-----” it is in the DER format and needs converted. See Convert DER to PEM Format before proceeding.
Run the following command including a -certfile mycertfile.cer pair for every certificate file. There should be at least 2-3 certificate files but the number can be more than that.
openssl crl2pkcs7 -nocrl -certfile certificate.cer -certfile intermediate.cer -out certificate.p7b
Convert .p7b and Private Key to .pfx (
...
PKCS12)
This process must be performed on a machine with OpenSSL installed
Convert the .p7b file to a single chained certificate
openssl pkcs7 -print_certs -in certificate.p7b -out temp.cer
Create combined .pfx from the certificate chain and the private key
openssl pkcs12 -export -in certificate.cer -inkey cert.key -out final.pfx
. It will ask for a password for the pfx. If this .pfx file is intended to be imported into a java keystore, such as omis.jks, you want to use the same password for the .pfx file as the target java keystore.
Import .pfx (PKCS12) into Java Keystore
This process must be performed on a machine with the full Java SDK installed. The Java Runtime does NOT have the required utilities. It is highly recommended to create a backup of the keystore prior starting this process
If the certificate being imported is intended to replace an existing certificate, for example in the case the original certificate has expired, the existing certificate must be removed. You can see if the certificate is already present using
keytool -list -keystore keystore.jks
. The existing certificate can be removed usingkeytool -delete -alias alias_name -keystore keystore.jks
.Import the .pfx file into the Java keystore using
keytool -importkeystore -srckeystore final.pfx -destkeystore keystore.jks
. This will import the key chain under the alias ‘1'. Although this will technically work, it makes it difficult to identify which certificate is which.Change the alias to match the CN of the certificate using
keytool -changealias -alias 1 -destalias cn_name_of_cetificate -keystore keystore.jks
Ensure everything is correct using
keytool -v -list -keystore keystore.jks