After Upgrade to Java SE 7 Update 131, Aliases in the Cacerts Truststore within Java Have [jdk] Appended to the Alias

(Doc ID 2281277.1)

Last updated on JULY 02, 2017

Applies to:

Java SE JDK and JRE - Version 7 and later
Information in this document applies to any platform.


The cacerts truststore in Java has the Alias Name appended with [jdk] starting from JDK7u131 and JDK8u131.  Earlier versions, such as Java SE 7u111, do not.

******* 1.7.0_131-b31********

$ grep 'digicertglobalrootca' res_131
Alias name: digicertglobalrootca [jdk]

Alias name: globalsigneccrootcar5 [jdk]
Alias name: starfieldservicesrootg2ca [jdk]
Alias name: ttelesecglobalrootclass2ca [jdk]
Alias name: addtrustqualifiedca [jdk]
Alias name: digicertglobalrootca [jdk]


$ grep digicertglobalrootca res_111
Alias name: digicertglobalrootca

Alias name: secomevrootca1
Alias name: dtrustclass3ca2ev
Alias name: verisignclass1g2ca
Alias name: comodoeccca
Alias name: godaddyrootg2ca



Upgrading to Java SE 7u131 or 8u131.


Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms