Skip to content

Web Hardware Bridge – Site Certificate Installation Guide

Purpose

This guide explains how to install a site SSL certificate into the Web Hardware Bridge (WHB) Java certificate store using keytool.

This is required when Web Hardware Bridge needs to establish a secure HTTPS connection to a local or internal site whose certificate is not already trusted by WHB.


Prerequisites

Before starting, make sure you have:

  • [ ] The site certificate file, for example site.crt
  • [ ] Access to the Windows machine where Web Hardware Bridge is installed
  • [ ] Administrator privileges
  • [ ] The Web Hardware Bridge installation path

Step 1 – Download the Site Certificate from Browser

The certificate should be downloaded directly from the actual HTTPS website.

For this example, we will download the certificate for:

https://ils.live

1. Open the Website

Open browser and navigate to:

https://ils.live

2. Open the Certificate Information

Click the padlock icon 🔒 next to the website address.

Depending on your browser version:

  1. Click the padlock / site information icon.
  2. Select Connection is secure.
  3. Select Certificate is valid.

This will open the certificate information window.

3. Open the Certificate Details

In the certificate window, review the certificate details.

You should see information such as:

Issued to: ils.live
Issued by: ...
Valid from: ...
Valid to: ...

4. Export the Certificate

Open the Details tab.

Select the certificate and use the option to Export the certificate.

If browser opens the Windows Certificate Viewer, select:

Details → Copy to File...

The Certificate Export Wizard will open.

5. Select the Certificate Format

Select:

Base-64 encoded X.509 (.CER)

Click:

Next

6. Save the Certificate

Save the certificate somewhere convenient, for example:

C:\Users\xxxxx\Downloads\site.crt

If browser/Windows saves it as:

site.cer

you can rename it to:

site.crt

The important part is that it contains the exported X.509 certificate.

Example: For https://ils.live, the exported certificate can be saved as site.crt.


Step 2 – Locate the Web Hardware Bridge Keytool

Web Hardware Bridge includes its own Java Runtime Environment (JRE), which contains the keytool.exe utility.

The default keytool location is:

C:\Users\xxxxx\AppData\Local\WebApp Hardware Bridge\jre\bin\keytool.exe

Step 3 – Locate the Web Hardware Bridge Certificate Store

Web Hardware Bridge uses the Java cacerts trust store to determine which certificates it trusts.

The default certificate store location is:

C:\Users\xxxxx\AppData\Local\WebApp Hardware Bridge\jre\lib\security\cacerts

This is the certificate store that needs to be updated.


Step 4 – Open Command Prompt as Administrator

  1. Open the Windows Start Menu.
  2. Search for:
Command Prompt
  1. Right-click Command Prompt.
  2. Select Run as administrator.
  3. Click Yes if Windows asks for permission.

Important: Run CMD as Administrator because the cacerts file is located inside the Web Hardware Bridge installation directory and may require elevated permissions.


Step 5 – Import the Certificate

Use the following command:

"<-- Keytool Path -->" -importcert -alias myserver -file "<-- Certificate Path -->" -keystore "<-- WHB CA Certificate Path -->"

Replace the placeholders with the actual paths.

Example

"C:\Users\xxxx\AppData\Local\WebApp Hardware Bridge\jre\bin\keytool.exe" -importcert -alias myserver -file "C:\Users\xxxx\Downloads\site.crt" -keystore "C:\Users\xxxx\AppData\Local\WebApp Hardware Bridge\jre\lib\security\cacerts"

Step 6 – Enter the Keystore Password

After executing the command, keytool will ask for the password of the Java keystore.

You may see:

Enter keystore password:

Enter the password configured for the Web Hardware Bridge Java cacerts store.

If the certificate is being imported into the standard Java cacerts store and the default password has not been changed, the password is commonly:

changeit

Note: If changeit does not work, use the password configured by your Web Hardware Bridge installation or administrator. Do not repeatedly guess passwords.


Step 7 – Confirm the Certificate Import

After entering the password, keytool should display information about the certificate and ask:

Trust this certificate? [no]:

Enter:

yes

You should then see a message similar to:

Certificate was added to keystore

This confirms that the certificate was successfully imported.


Step 8 – Verify the Certificate

To verify that the certificate was added successfully, run:

"<-- Keytool Path -->" -list -keystore "<-- WHB CA Certificate Path -->" -alias myserver

Example

"C:\Users\xxxx\AppData\Local\WebApp Hardware Bridge\jre\bin\keytool.exe" -list -keystore "C:\Users\xxxx\AppData\Local\WebApp Hardware Bridge\jre\lib\security\cacerts" -alias myserver

Enter the keystore password when prompted.

If the certificate exists, keytool will display information similar to:

Alias name: myserver
Creation date: ...
Entry type: trustedCertEntry

Owner: CN=...
Issuer: CN=...

Step 9 – Exit and Start Web Hardware Bridge Again

After successfully importing the certificate, Web Hardware Bridge must be completely restarted so that the updated certificate store is loaded.

  1. Close any application currently using Web Hardware Bridge.
  2. Exit Web Hardware Bridge completely.
  3. Check the Windows system tray and make sure the Web Hardware Bridge icon is no longer running.
  4. If Web Hardware Bridge is still running, use Exit/Quit from the system tray.
  5. Start Web Hardware Bridge again.
  6. Wait for Web Hardware Bridge to fully start.
  7. Reopen the application that uses Web Hardware Bridge.
  8. Test the HTTPS connection again.

Important: Simply closing the browser or application may not be enough. Web Hardware Bridge itself must be completely exited and started again so that the updated Java cacerts certificate store is reloaded.

If Web Hardware Bridge Does Not Restart Correctly

If the certificate still does not work after restarting:

  1. Exit Web Hardware Bridge again.
  2. Verify that the Web Hardware Bridge process is no longer running in Task Manager.
  3. Start Web Hardware Bridge again.
  4. Test the connection.

If necessary, restart the Windows machine and test again.


Complete Example

Paths

Keytool Path:

C:\Users\xxxx\AppData\Local\WebApp Hardware Bridge\jre\bin\keytool.exe

Certificate Path:

C:\Users\xxxx\Downloads\site.crt

WHB CA Certificate Path:

C:\Users\xxxx\AppData\Local\WebApp Hardware Bridge\jre\lib\security\cacerts

Import Command

Run CMD as Administrator and execute:

"C:\Users\xxxx\AppData\Local\WebApp Hardware Bridge\jre\bin\keytool.exe" -importcert -alias myserver -file "C:\Users\admin\Downloads\site.crt" -keystore "C:\Users\admin\AppData\Local\WebApp Hardware Bridge\jre\lib\security\cacerts"

Enter the keystore password when prompted.

When asked:

Trust this certificate? [no]:

Enter:

yes

Expected result:

Certificate was added to keystore

Troubleshooting

1. keytool is not recognized

If you run:

keytool

and Windows reports that it cannot find the command, use the full path to keytool.exe as shown in this guide.

Example:

"C:\Users\xxxx\AppData\Local\WebApp Hardware Bridge\jre\bin\keytool.exe"

2. FileNotFoundException

If you receive an error indicating that the certificate cannot be found, verify that the certificate exists at the specified path.

Example:

C:\Users\xxxx\Downloads\site.crt

You can verify it by opening the path in Windows File Explorer.


3. Keystore was tampered with, or password was incorrect

This normally means the entered keystore password is incorrect.

Verify the password for the WHB cacerts file.


4. Certificate already exists

If you receive an error indicating that the alias already exists, check the existing certificate:

"<-- Keytool Path -->" -list -keystore "<-- WHB CA Certificate Path -->" -alias myserver

If necessary, remove the existing alias before importing the new certificate:

"<-- Keytool Path -->" -delete -alias myserver -keystore "<-- WHB CA Certificate Path -->"

Then import the certificate again.

Warning: Only delete the alias if you are sure it is the certificate that needs to be replaced.


5. HTTPS error still occurs after importing

If Web Hardware Bridge still reports an SSL/TLS certificate error:

  • Verify that the correct certificate was downloaded.
  • Verify that the certificate matches the HTTPS site.
  • Verify that the certificate chain is trusted.
  • Verify that the certificate was imported into the Web Hardware Bridge JRE's cacerts, not another Java installation.
  • Verify that the alias exists in the WHB cacerts.
  • Restart Web Hardware Bridge.
  • Check whether the server certificate has expired.
  • Check whether the server requires an intermediate CA certificate.

Quick Reference

Item Path
Keytool C:\Users\xxxxx\AppData\Local\WebApp Hardware Bridge\jre\bin\keytool.exe
Site Certificate C:\Users\xxxxx\Downloads\site.crt
WHB Certificate Store C:\Users\xxxxx\AppData\Local\WebApp Hardware Bridge\jre\lib\security\cacerts

Import

"<Keytool Path>" -importcert -alias myserver -file "<Certificate Path>" -keystore "<WHB CA Certificate Path>"

Verify

"<Keytool Path>" -list -keystore "<WHB CA Certificate Path>" -alias myserver

Restart

After successful installation, restart Web Hardware Bridge before testing the connection again.