The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

ipsmanager keytool

Prev Next

This CLI can be used to manage keytools, including adding, storing, listing, and deleting certificates.

Syntax: ipsmanager keytool <arglist>

The following table lists the parameters:

Parameter

Description

<arglist>

Provides the list of keystore arguments.

Sample Output:

Important

  • The CustomJSSEcaCerts file (Manager trust store) is in the /opt/IPSManager/App/config/CustomSecurity/CustomJSSEcaCerts directory.

  • Copy the required file to the /var/home/root/<file_name> directory.

    Example: my_server.cer file (server certificate to be imported) to /var/home/root/my_server.cer

  • Add a customer server certificate to the Manager trust store using a unique alias:

    IPSManager (config) # ipsmanager keytool "-keystool /opt/IPSManager/App/config/CustomSecurity/CustomJSSEcaCerts -storepass changeit -import -file /var/home/root/my_server.cer -alias my_server"
    Owner: C=US, ST=CA, L=Santa Clara, O=Trellix, OU=Intrusion Prevention Systems, CN=WIN-23PFD7631M3SS, 
    EMAILADDRESS=Administrator@WIN-23PFD7631M3SS
    Issuer: C=US, ST=CA, L=Santa Clara, O=Trellix, OU=Intrusion Prevention Systems, CN=WIN-23PFD7631M3SS, 
    EMAILADDRESS=Administrator@WIN-23PFD7631M3SS
    Serial number: 2560f6fb
    Valid from: Sun Nov 23 06:46:35 UTC 2025 until: Wed Nov 21 06:46:35 UTC 2035
    Certificate fingerprints:         
          SHA1: 1A:2A:3A:A4:5A:6A:BC:BC:BC:BC:BC:DE:DE:DE:DE:EF:EF         
          SHA256: AA:AA:AA:AA:AA:AA:AA:AA:AA:BB:BB:BB:BB:BB:BB:CC:CC:CC:CC:DD:DD:DD:DD:EE:EE:EE:EE:FF:FF
    Signature algorithm name: SHA256WITHRSA
    Subject Public Key Algorithm: 2048-bit RSA key
    Version: 3
    Trust this certificate? [no]:  yes
    Certificate was added to keytool
  • List existing trusted certificates in the Manager trust store:

    IPSManager (config) # ipsmanager keytool "-keytool /opt/IPSManager/App/config/CustomSecurity/CustomJSSEcaCerts -storepass changeit -list"
    % Keytool type: jks
    Keytool provider: SUN
    
    Your keystool contains 1 entry
    
    new_server, Jan 01, 2026, trustedCertEntry,
    Certificate fingerprint (SHA-256): AA:AA:AA:AA:AA:AA:AA:AA:AA
  • List the specific customer server certificate stored by a unique alias in the Manager trust store:

    IPSManager (config) # ipsmanager keytool "-keytool /opt/IPSManager/App/config/CustomSecurity/CustomJSSEcaCerts -storepass changeit -list -alias my_server"
    my_servermy_server, Dec 12, 2025, trustedCertEntry,
    Certificate fingerprint (SHA-256): AA:AA:AA:AA:AA:AA:AA:AA:AA:BB:BB:BB:BB:BB:BB:CC:CC:CC:CC:DD:DD:DD:DD:EE:EE:EE:EE:FF:FF
  • Delete the specific customer server certificate for a given alias in the Manager trust store:

    IPSManager (config) # ipsmanager keytool "-keytool /opt/IPSManager/App/config/CustomSecurity/CustomJSSEcaCerts -storepass changeit 
    -delete -alias my_server"