This CLI can be used to manage keytools, including adding, storing, listing, and deleting certificates.
Syntax: ipsmanager keytool <arglist>
The following table lists the parameters:
Parameter | Description |
|---|---|
<arglist> | Provides the list of keystore arguments. |
Sample Output:
Important
The CustomJSSEcaCerts file (Manager trust store) is in the
/opt/IPSManager/App/config/CustomSecurity/CustomJSSEcaCertsdirectory.Copy the required file to the
/var/home/root/<file_name>directory.Example: my_server.cer file (server certificate to be imported) to
/var/home/root/my_server.cer
Add a customer server certificate to the Manager trust store using a unique alias:
IPSManager (config) # ipsmanager keytool "-keystool /opt/IPSManager/App/config/CustomSecurity/CustomJSSEcaCerts -storepass changeit -import -file /var/home/root/my_server.cer -alias my_server" Owner: C=US, ST=CA, L=Santa Clara, O=Trellix, OU=Intrusion Prevention Systems, CN=WIN-23PFD7631M3SS, EMAILADDRESS=Administrator@WIN-23PFD7631M3SS Issuer: C=US, ST=CA, L=Santa Clara, O=Trellix, OU=Intrusion Prevention Systems, CN=WIN-23PFD7631M3SS, EMAILADDRESS=Administrator@WIN-23PFD7631M3SS Serial number: 2560f6fb Valid from: Sun Nov 23 06:46:35 UTC 2025 until: Wed Nov 21 06:46:35 UTC 2035 Certificate fingerprints: SHA1: 1A:2A:3A:A4:5A:6A:BC:BC:BC:BC:BC:DE:DE:DE:DE:EF:EF SHA256: AA:AA:AA:AA:AA:AA:AA:AA:AA:BB:BB:BB:BB:BB:BB:CC:CC:CC:CC:DD:DD:DD:DD:EE:EE:EE:EE:FF:FF Signature algorithm name: SHA256WITHRSA Subject Public Key Algorithm: 2048-bit RSA key Version: 3 Trust this certificate? [no]: yes Certificate was added to keytool
List existing trusted certificates in the Manager trust store:
IPSManager (config) # ipsmanager keytool "-keytool /opt/IPSManager/App/config/CustomSecurity/CustomJSSEcaCerts -storepass changeit -list" % Keytool type: jks Keytool provider: SUN Your keystool contains 1 entry new_server, Jan 01, 2026, trustedCertEntry, Certificate fingerprint (SHA-256): AA:AA:AA:AA:AA:AA:AA:AA:AA
List the specific customer server certificate stored by a unique alias in the Manager trust store:
IPSManager (config) # ipsmanager keytool "-keytool /opt/IPSManager/App/config/CustomSecurity/CustomJSSEcaCerts -storepass changeit -list -alias my_server" my_servermy_server, Dec 12, 2025, trustedCertEntry, Certificate fingerprint (SHA-256): AA:AA:AA:AA:AA:AA:AA:AA:AA:BB:BB:BB:BB:BB:BB:CC:CC:CC:CC:DD:DD:DD:DD:EE:EE:EE:EE:FF:FF
Delete the specific customer server certificate for a given alias in the Manager trust store:
IPSManager (config) # ipsmanager keytool "-keytool /opt/IPSManager/App/config/CustomSecurity/CustomJSSEcaCerts -storepass changeit -delete -alias my_server"