PKIX path building failed after truststore update in Quarkus
28K reputation · 13 Jun 2022, 17:53 UTC
Goal
Determine whether a running Quarkus application can recognize newly added CA certificates in its truststore without requiring a full restart.
Constraints and uncertainty
Quarkus relies on the default Java SSLContext unless a custom configuration is provided. The documentation states that truststore changes are not picked up at runtime, but it does not specify whether any extension or configuration flag exists to trigger a reload. This behavior may differ between JVM mode and native executables, where static networking libraries could further affect certificate reloading.
Specific questions:
- Is there a supported Quarkus API or configuration property to programmatically reload the truststore at runtime?
- Can the underlying Java security properties be refreshed via Quarkus lifecycle events without restarting the application?
- Does the native image mode provide any alternative mechanism for truststore updates compared to the JVM mode?
1 answer
0 question comments
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.