Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

keytool is Java’s command-line utility for managing keys, certificates, and keystore entries. The examples below use the syntax documented for JDK 25; options and defaults can vary by installed JDK and security configuration. Before changing a production keystore, confirm the local command reference and verify certificates through a trusted channel. Oracle’s Java SE 25 keytool reference documents the commands and behaviors described here.

Before running keytool commands

A keystore stores entries identified by aliases. An alias is the name you use to refer to an entry, so keep it consistent across commands and update applications or scripts if you rename it. Commands that omit options may rely on defaults: in JDK 25, the documented default alias is mykey, the default validity period is 90 days, and the default keystore name is .keystore in the user’s home directory. The documented default key sizes are 3072 bits for RSA, 384 bits for EC, and 2048 bits for DSA; the default store type comes from Java security configuration. Set required values explicitly where policy demands them, and check the documentation for the JDK you actually run.

These examples omit passwords so keytool can prompt interactively. Avoid putting real secrets in reusable command lines or shell history. Replace filenames, aliases, algorithms, and store types with values appropriate to your environment.

Generate and inspect keys and certificates

1. Generate a key pair

keytool -genkeypair -alias app-server -keyalg RSA -keystore app-server.p12

This creates a public/private key pair and stores it with a certificate under the app-server alias. Keytool can prompt for certificate identity details; explicit distinguished-name and validity options are also available. A new key pair’s self-signed certificate is not automatically trusted by other systems.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

2. List keystore entries

keytool -list -keystore app-server.p12

Add -alias app-server to limit the listing to one entry, or -v for verbose certificate and entry details.

3. Inspect a certificate file

keytool -printcert -file server.cer

Use this to inspect a received certificate, including its fingerprint, before deciding whether to trust it. Compare the fingerprint with one obtained independently through a trusted channel; otherwise, a substituted certificate could be accepted as trusted.

4. Display certificate details for one keystore entry

keytool -list -v -alias app-server -keystore app-server.p12

The verbose listing shows certificate information for the selected entry, which is useful when checking what certificate is stored under an alias.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

5. Generate a secret key

keytool -genseckey -alias app-secret -keyalg AES -keystore app-secrets.p12

This stores a secret-key entry rather than a public/private key pair. Select an algorithm and key size that meet the application’s requirements and your security policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Request and install certificates

6. Create a certificate signing request

keytool -certreq -alias app-server -file app-server.csr -keystore app-server.p12

The CSR is associated with the key entry. Submit it to the certificate authority using that authority’s process; keytool creates the request but does not obtain a CA signature.

7. Review a CSR

keytool -printcertreq -file app-server.csr

This displays the request’s contents. It does not establish that a certificate has been issued or validate a CA’s response.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

8. Import a CA certificate reply for a key entry

keytool -importcert -alias app-server -file app-server-chain.pem -keystore app-server.p12

When the alias identifies a key entry, keytool treats the input as a certificate reply and associates the returned certificate or chain with that entry. Ensure the necessary issuer certificates are trusted and that the reply matches the key entry’s request.

9. Add a trusted CA certificate

keytool -importcert -alias example-root -file root-ca.cer -keystore truststore.p12

When the alias does not identify a key entry, keytool treats the import as a trusted-certificate entry. Inspect the certificate and verify its fingerprint independently before accepting it. Avoid -noprompt when you need keytool’s interactive trust confirmation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

10. Export a certificate

keytool -exportcert -rfc -alias app-server -file app-server.pem -keystore app-server.p12

-rfc requests printable certificate encoding; without it, the output is binary. For a key entry, the exported certificate is the first certificate in its chain.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

11. Build and import a certificate chain

A chain workflow can involve creating root, intermediate, and server key entries; exporting the root certificate; creating CSRs for subordinate certificates; having the appropriate signer issue certificates; and importing the resulting chain into the server key entry. Adapt aliases, extensions, file handling, and keystores to the actual certificate hierarchy. The required CA signing steps take place outside keytool.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Move and manage keystore entries

12. Import entries from another keystore

keytool -importkeystore -srckeystore old-store.jks -destkeystore new-store.p12

This can import one selected entry or all entries. Specify source and destination store types or aliases when required by your setup. Review overwrite behavior before running the command: with -noprompt, colliding entries can be overwritten, while entries that cannot be imported are skipped with a warning.

13. Rename an entry alias

keytool -changealias -alias old-name -destalias new-name -keystore app-server.p12

Aliases identify entries and must be unique within the keystore. Update configuration and scripts that refer to the old alias.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.

14. Delete an entry

keytool -delete -alias retired-cert -keystore truststore.p12

Check both the alias and keystore filename before confirming the deletion.

Change passwords and handle command input or output

15. Change the keystore password

keytool -storepasswd -keystore app-server.p12

This changes the keystore’s store password. Use the interactive prompt or an approved secret-handling method rather than embedding a production password in a reusable command.

16. Change an entry’s key password

keytool -keypasswd -alias app-server -keystore app-server.p12

This changes the password for the selected key entry; it is separate from changing the keystore’s store password.

17. Read from standard input or write to standard output

keytool -exportcert -rfc -alias app-server -keystore app-server.p12

Oracle documents standard input as the default for file-reading operations and standard output as the default for file-writing operations when -file is omitted. This export example therefore writes the certificate to standard output. Check the specific command’s behavior before composing a pipeline.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.