NetBeans JVM TrustStore Configuration for Custom SSL Certificates
25.5K reputation · 20 Jun 2020, 14:13 UTC
JRE TrustStore Integration
\nNetBeans relies on the Java Runtime Environment (JRE) cacerts file for SSL/TLS certificate validation. While global proxy settings are managed within the IDE options, the import of custom or self-signed certificates typically requires external manipulation of the JRE keystore using the keytool utility.
Configuration Constraints
\nModifying the default JRE truststore impacts all Java applications utilizing that specific runtime. To isolate certificate trust to the IDE, the netbeans.conf file supports JVM arguments such as -Djavax.net.ssl.trustStore to point to a dedicated keystore file.
When utilizing a custom truststore via netbeans.conf, it is unclear if the IDE maintains a merged trust relationship with the default JRE cacerts or if the specified store completely replaces the default validation chain.
- \n
- Does specifying a custom trustStore in
netbeans.confoverride or append to the system JRE certificates? \n - What is the recommended method to verify that NetBeans is utilizing the custom store during plugin updates? \n