Oracle’s JDK 25 documentation describes keytool as a key and certificate management utility. It stores cryptographic keys, X.509 certificate chains and trusted certificates in a keystore. The 17 examples below follow a practical workflow: identify your installed JDK, create and inspect entries, obtain and install CA-issued certificates, migrate data, maintain aliases and passwords, and review the system trust store.
Run each command separately: keytool accepts one command per invocation. Omit password options when possible so the program prompts securely; passwords shown in examples are never real credentials.
Before you start
- Install the JDK whose
keytoolyou intend to use, and ensure that executable is on yourPATH. - Use a working directory with restricted permissions for keystores, private keys and certificate requests.
- Decide whether another system requires JKS compatibility. PKCS12 is the default keystore implementation in JDK 9 and later, while JKS remains available; specify
-storetypewhenever format compatibility matters. See Oracle’s JDK 25 keytool reference. - Never treat a self-signed certificate as proof that a public CA authenticated your identity.
1. Show the installed keytool version
Check the executable before copying version-sensitive syntax:
keytool -version
The output identifies the JDK release. If multiple JDKs are installed, verify that the reported version is the one used by your application.
2. Display command help
keytool -help
Use the installed tool’s synopsis to confirm command names and options available in your exact JDK and provider configuration.
3. Create a PKCS12 keystore and key pair
keytool -genkeypair -alias app -keyalg RSA -keystore app.p12 -storetype PKCS12
If app.p12 does not exist, keytool creates it, prompts for a keystore password and entry details, and stores an RSA private/public key pair under the app alias. Without a signer, it creates a self-signed X.509 v3 certificate as a one-element chain. That is useful for development or for starting a CA workflow, but it is not a publicly trusted production identity.
4. Set the distinguished name and validity period
keytool -genkeypair -alias app -keyalg RSA -dname "CN=app.example.internal, OU=Platform, O=Example, L=London, ST=London, C=GB" -validity 365 -keystore app.p12 -storetype PKCS12
-dname supplies certificate subject fields and -validity sets the number of days. These fields describe the certificate; choosing a name or duration does not establish trust or authenticate ownership.
5. Generate an elliptic-curve key with a named group
keytool -genkeypair -alias app-ec -groupname secp256r1 -keystore app-ec.p12 -storetype PKCS12
Use a named group supported by the installed JDK and security provider. Oracle documents -groupname and -keysize as alternatives for this operation: do not specify both. If your provider does not recognize the group, choose one it reports as supported rather than guessing.
6. List every entry
keytool -list -keystore app.p12
After entering the keystore password, keytool prints aliases, entry types and certificate metadata. A key entry normally contains a private key and its associated chain; a trusted-certificate entry contains a certificate for another party.
Rank #2
7. Inspect one entry verbosely
keytool -list -v -keystore app.p12 -alias app
Verbose output includes subject and issuer, validity dates, public-key algorithm, serial number, extensions and fingerprints. Use it to confirm that a CA reply was attached to the intended key and to record fingerprints for operational checks.
8. Inspect a certificate file before importing it
keytool -printcert -file server.crt
Review the issuer, subject, validity and fingerprints without changing a keystore. Compare the fingerprint with a value obtained through a separate trusted channel (for example, your CA’s documented portal or an administrator you already trust). Do not use -noprompt to bypass that decision: it disables keytool’s interactive trust prompt.
9. Generate a PKCS #10 certificate signing request
keytool -certreq -alias app -keystore app.p12 -file app.csr
The request uses the public key associated with alias app and is written to app.csr. Send that PKCS #10 request to your certificate authority. The CA validates identity and returns a certificate or chain; generating the request alone does not make the certificate trusted.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
10. Import a CA certificate as a trusted entry
keytool -importcert -alias example-ca -file ca.crt -keystore truststore.p12 -storetype PKCS12
Use this form when the file is a CA certificate that other entries should trust. Verify its fingerprint first, choose an unused alias, and answer the trust prompt deliberately. This adds a trusted-certificate entry; it does not attach a reply to your application’s private key.
11. Import the CA reply into the original key entry
keytool -importcert -alias app -file app-reply.pem -keystore app.p12 -storetype PKCS12
Here the existing app alias identifies the key entry created earlier. Keytool validates that the returned certificate corresponds to the stored private key and, when the chain is supplied correctly, replaces the initial self-signed chain with the CA-issued chain. If the CA supplied intermediate certificates separately, import them in the order required by that CA before importing the reply, using distinct trusted aliases where appropriate.
12. Export a certificate as PEM
keytool -exportcert -rfc -alias app -keystore app.p12 -file app.pem
The -rfc option writes printable Base64 PEM delimiters instead of binary DER. The export contains the certificate, not the private key, and can be supplied to a server, load balancer or another trust store.
13. Migrate entries between keystores
keytool -importkeystore -srckeystore old.jks -srcstoretype JKS -destkeystore new.p12 -deststoretype PKCS12
Keytool prompts for source and destination passwords and lets you confirm aliases. Explicit source and destination formats prevent an accidental compatibility mismatch. Inspect old.jks first, preserve a protected backup, and list new.p12 afterward to verify every required entry and chain.
Recommended Free Tools
14. Change an entry alias
keytool -changealias -alias app -destalias web-app -keystore app.p12
This renames the entry without changing its key or certificate. Update application configuration that refers to the old alias, then verify the result:
keytool -list -keystore app.p12 -alias web-app
15. Delete one entry
keytool -delete -alias obsolete -keystore app.p12
Deletion is irreversible for that keystore copy. Check the alias, file path and a backup before confirming. List the keystore afterward to ensure that only the intended entry disappeared.
16. Change the keystore password
keytool -storepasswd -keystore app.p12
Keytool prompts for the current password and the new one. This changes the keystore password, not necessarily the password protecting a private key entry. Keep credentials out of shell history, process listings and source control; omitting password flags is safer for interactive use. Automation should obtain secrets from a protected secret manager and follow its rotation policy.
Rank #4
17. Review the system CA store
keytool -list -cacerts
This inspects the JDK’s cacerts trust store. Oracle places responsibility on administrators to verify bundled roots and retain only authorities they trust. Editing system trust changes certificate decisions for applications using that JDK, so make changes only with administrative approval, documented rollback and an understanding of which runtime actually reads the file.
Choosing the right operation
| Need | Command or approach | Trust and compatibility implication |
|---|---|---|
| Start a key-and-certificate workflow | -genkeypair |
Creates a key entry and normally a self-signed initial certificate; not public CA trust. |
| Ask a CA for issuance | -certreq |
Creates PKCS #10 material that must be submitted and validated by a CA. |
| Install a CA for trust | -importcert with a new alias |
Adds a trusted-certificate entry after fingerprint verification. |
| Install your issued certificate | -importcert using the original key alias |
Attaches the validated reply and chain to the existing private key. |
| Move between formats | -importkeystore |
Specify JKS or PKCS12 explicitly when another system depends on the format. |
| Inspect versus modify trust | -list -cacerts versus import/delete commands |
Listing is observational; edits affect system-wide trust decisions. |
Common failures and fixes
“Alias already exists”
List the target keystore and choose an unused alias, or intentionally operate on the existing key entry. Do not overwrite an entry simply to silence the error.
“Failed to establish chain from reply”
The reply may omit an intermediate, use the wrong key, or be imported under the wrong alias. Confirm the CSR’s alias, inspect the reply with -printcert, obtain the CA’s complete chain, and import required CA certificates before retrying.
Unsupported algorithm, group or option
Run keytool -version and keytool -help from the same JDK used by the application. Algorithm warnings reflect that JDK’s security properties and provider policy; do not apply a universal algorithm prescription without checking deployment requirements.
Wrong password or unreadable keystore
Confirm the file path, store type and password source. A JKS file opened as PKCS12 (or the reverse) can produce misleading errors; specify -storetype explicitly and restore from a known backup if the file was modified.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Best Value
Unexpected trust prompt
Stop and verify the certificate fingerprint through an independent channel. Interactive confirmation is a security control, not an inconvenience. Reserve -noprompt for a controlled, verified automation process.
Automation, reliability and operational safeguards
- Use one command per pipeline stage and check each exit status; keytool does not combine multiple primary commands in one invocation.
- Write keystores atomically where possible, retain encrypted backups before deletion or migration, and restrict filesystem permissions.
- Record alias names, certificate expiry dates, issuing CA and fingerprints in your operational inventory.
- Test the exact JDK, provider and keystore format in a non-production environment before rotating a live certificate.
- Keep private keys private. Export only certificates unless a documented migration specifically requires key material.
Or skip the browser setup
If your workflow also needs screenshots of certificate dashboards, documentation or deployment pages, ScreenshotNeo provides a website screenshot API and MCP server. A single request can return PNG, JPEG, WebP or PDF, while it accepts cookie banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets. Bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and response headers identify the page verdict and billing result.
cURL:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
See the ScreenshotNeo documentation for options including full-page and element capture, custom CSS and JavaScript, waiting rules, headers, cookies, geolocation, PDF output, caching, bulk jobs and signed webhooks. Its MCP server provides take_screenshot, get_page_info and capture_pdf to Claude, Cursor and other MCP clients. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.
FAQ
Does keytool create a publicly trusted certificate?
No. Its default self-signed certificate is an initial cryptographic identity. Public trust requires a certificate authority’s validation and issued chain, or explicit installation in a trust store you control.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallShould a new project use JKS or PKCS12?
Use PKCS12 unless a dependent product specifically requires JKS, and state the format explicitly in scripts and documentation.
Can one command generate a key, request a CA certificate and import the reply?
No. Each is a separate keytool invocation, with the CA validation and issuance occurring outside keytool.
Frequently Asked Questions
Can I put a real password directly in a keytool command?
Avoid it. Command-line passwords can appear in shell history or process listings; omit password flags for prompts or retrieve secrets through a protected automation mechanism.
What is the difference between a key entry and a trusted-certificate entry?
A key entry contains a private key and its certificate chain. A trusted-certificate entry contains a certificate for another party and no private key.
The Bottom Line
Use keytool’s inspection commands before changing trust, keep keystore formats explicit, and follow the create–CSR–CA reply sequence when moving from a self-signed development certificate to a CA-issued chain.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

