Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To change Java security settings for just one JVM, start that process with -Djava.security.properties=/path/to/override.security. One equals sign adds your file to the JDK’s master security file; two equals signs replace the master file entirely. Put the option on the target Java command, not in a machine-wide setting.

Choose an additive override or a complete replacement

The JDK’s normal master security-properties file is typically $JAVA_HOME/conf/security/java.security. With one equals sign, Java loads the alternate file in addition to the master file. When both files define a key, the value in the alternate file takes precedence because it is loaded later. Oracle documents the syntax and location in The Security Properties File.

Launch option Effect When to use it Operational consideration
-Djava.security.properties=/opt/app/override.security Adds the specified file to the master security properties; duplicate keys take the alternate file’s value. A targeted change while retaining the JDK’s other security settings. Usually the lower-risk choice. Remove the launch option to roll back the per-process override.
-Djava.security.properties==/opt/app/only.security Replaces the master security-properties file with the specified file. When you intentionally manage the complete security-properties profile. Your file must include every setting the application needs. Restore the prior file or remove the replacement option to roll back.

Launch one JVM with an override file

  1. Create a readable properties file, for example /opt/app/override.security, and include only the security-property assignments you intend to change:

    jdk.tls.disabledAlgorithms=SSLv3, TLSv1, TLSv1.1, RC4
    ssl.KeyManagerFactory.algorithm=SunX509
  2. Add the appropriate option to the command that starts the target application. For an additive override:

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
    java -Djava.security.properties=/opt/app/override.security -jar app.jar

    For a complete replacement, use two equals signs:

    java -Djava.security.properties==/opt/app/only.security -jar app.jar
  3. Keep the flag on this process’s Java command. Other JVMs on the host are unaffected unless their launch commands or environment configuration also pass the option.

The example property names and values are illustrative; exact names, defaults, and supported algorithms depend on the JDK version and vendor. Check the target JDK’s master file and documentation before changing security settings. With the additive form, leave unrelated master-file settings in place; with replacement, supply the complete set your application requires.

Pass the option correctly on Windows

Use a path or file URL that the Java launcher can read, formatted and quoted as required by the shell and any service wrapper that starts the JVM. Keep the option before the application’s -jar or main-class argument. Confirm the actual command line used by the service or launcher; editing a shell command that is not used to start the target process will not change its configuration.

Change a security property from Java code

For a property that supports dynamic changes, use java.security.Security.setProperty:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
import java.security.Security;

Security.setProperty("ssl.KeyManagerFactory.algorithm", "SunX509");

Oracle warns that some properties cannot be changed dynamically after they have been read from a security-properties file and cached during initialization of java.security.Security. An attempted update may throw no exception and still have no effect. Set the value before initializing the security or TLS component that consumes it. System.setProperty changes a system property; it is not a substitute for Security.setProperty when the target is a Java security property. See Oracle’s security-properties documentation and the Security API reference.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Check whether the override took effect

Run a diagnostic invocation with the same override and inspect the resulting security configuration:

java -Djava.security.properties=/opt/app/override.security 
     -Djava.security.debug=properties -jar app.jar

Or print the effective security settings while checking the JVM version:

java -Djava.security.properties=/opt/app/override.security 
     -XshowSettings:security -version

Oracle documents -Djava.security.debug=properties for logging property processing and final values, and -XshowSettings:security for an overview of effective settings. For a running application, verify the exact launch arguments and runtime configuration rather than assuming a separate diagnostic command has identical inputs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If the override does not work

  • The launch option is missing or in the wrong place: Confirm the target JVM’s command line contains -Djava.security.properties=... before -jar or the main class.
  • The alternate file is unavailable: Check that the path is correct and the account running Java can read it. Use shell-appropriate quoting or a correctly formatted file URL where needed.
  • The setting is blocked: OpenJDK’s master file documents security.overridePropertiesFile=true by default. If the JDK image sets it to false, command-line alternate security-properties files are disabled. An organization that controls the JDK image can use this setting to prevent such overrides. See the OpenJDK master security-properties file.
  • The property was changed too late: A security property may already have been read and cached when Security.setProperty runs. Move the call earlier or configure it at JVM startup.
  • A profile selector was assigned after initialization: Security properties are assembled as the security framework initializes; setting a profile selector or related system property afterward may not change the loaded configuration. Set initialization-dependent options on the launch command.
  • The wrong form was used: One equals sign is additive; two mean full replacement. Check the effective property values with the diagnostic options above.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.