Why does Payara set -Djavax.net.ssl.trustStore?

87 views
Skip to first unread message

Dan Fraser

unread,
Aug 10, 2017, 3:52:29 PM8/10/17
to Payara Forum

I find it confusing that Payara trusts a different set of certificates from the stock JDK. 

I'm curious -- why does it do this?

Thanks,

Dan

Steve Millidge

unread,
Aug 12, 2017, 1:50:01 PM8/12/17
to Payara Forum
This is so you can change the contents of the truststore when creating a domain. Many operating system configurations with java installed won't allow an end user to update the jvm installed truststore and Payara needs to add certs as it uses 2 way ssl between the das and standalone instances.

Dan Fraser

unread,
Aug 15, 2017, 9:36:50 AM8/15/17
to Payara Forum
So copying the JVM's truststore files into the payara distribution isn't a problem, as long as we're not using a separate DAS.  Makes sense.

I imagine it must also modify the truststore for enable-secure-admin.  Thanks for your response!
Reply all
Reply to author
Forward
0 new messages