Apache NetBeans SSL trust limits: custom trust store scope for plugin and Maven connections
0 reputation · 07 Oct 2024, 22:06 UTC
Apache NetBeans validates its own HTTPS connections — Plugin Portal update checks and Maven repository access — against the trust store of the Java runtime hosting the IDE. The netbeans.conf file accepts JVM arguments, including -Djavax.net.ssl.trustStore, which can point validation at a specific keystore file instead of the runtime's default cacerts.
The limits of that mechanism are what remain unclear. Under standard JVM behavior, an explicitly configured trust store is generally consulted instead of the default one, so a store holding only an internal CA could break validation for public endpoints. Whether NetBeans inherits those replacement semantics across all of its network features, and how the runtime selected through netbeans_jdkhome changes which default store applies, needs a clear answer before choosing between an IDE-scoped override and edits to the shared runtime keystore.
- Does a trust store set via
netbeans.conffully replace the default JREcacertsfor NetBeans plugin and Maven connections, or are both consulted? - Is there a supported IDE-level way to trust a single additional CA without modifying the shared runtime
cacerts? - Which runtime's
cacertsgoverns validation whennetbeans_jdkhomepoints to a JDK other than the launcher's default?