Hi. From the latest message in this thread:
https://mail.openjdk.org/pipermail/security-dev/2025-January/043768.html
there have been some changes in this area but I don't think they
address the initial concerns from the original post on the thread. Like the
original poster, I'm working in an enterprise environment that
has company-specific certificates stored in the Apple System Keychain and
the Internet-issued certificates in the Apple System Root Keychain.

Many of the HTTP interactions that the software has to perform involve
going to internal company APIs, which typically require the
company-specific certificates, and also to go out to the Internet to call
APIs. So, both groups of certificates are required in the configured
truststore. At the moment, we're meeting this demand by exporting the
certificates from the Apple Keychains into a combined PKCS12 file and using
that as the truststore.

It would be more convenient if we had a KeychainStore-ALL option to set as
the trustStore system property which would combine the loading behaviour of
KeychainStore and KeychainStore-ROOT.

We're on Java 25 and keeping up-to-date with LTS versions, so no need to
backport anything on my account. It would just be great to have the -ALL
option going forward.

Many thanks,
David

Reply via email to