{"version":"2.1.288","anchor":"keytool-import-no-longer-passes-trustcacerts","canonical_anchor":"keytool-import-no-longer-passes-trustcacerts","heading":"Importing a CA certificate into a Java truststore no longer uses -trustcacerts","tier":"notice","area":"Elsewhere","scope":"org","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288\/e\/keytool-import-no-longer-passes-trustcacerts","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288","markdown":"### Importing a CA certificate into a Java truststore no longer uses -trustcacerts\n\nWhen Claude Code imports a CA certificate with Java's keytool, it no longer passes the -trustcacerts option\n\n**Unclear.** When Claude Code runs this import, and what practical difference dropping the option makes, is not established.\n\n**What**\n\nJava programs keep the certificates they trust in a file called a truststore, and `keytool` is Java's command for managing it. When Claude Code imports a CA certificate (a certificate that vouches for other certificates, often a company's own) with `keytool -importcert`, it no longer adds the `-trustcacerts` option to that command.\n\n**Why**\n\nThis changes how custom CA certificates end up in a Java truststore. If you rely on Claude Code to set up a custom certificate for Java tools, the import now runs with a different set of options than before.\n\n- Area: Elsewhere\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5\n- Scope: org\n- Heads-up: no"}