Web Hardware Bridge – Site Certificate Installation Guide
Purpose
This guide explains how to install a site SSL certificate into the Web Hardware Bridge (WHB) Java certificate store using keytool.
This is required when Web Hardware Bridge needs to establish a secure HTTPS connection to a local or internal site whose certificate is not already trusted by WHB.
Prerequisites
Before starting, make sure you have:
- [ ] The site certificate file, for example
site.crt - [ ] Access to the Windows machine where Web Hardware Bridge is installed
- [ ] Administrator privileges
- [ ] The Web Hardware Bridge installation path
Step 1 – Download the Site Certificate from Browser
The certificate should be downloaded directly from the actual HTTPS website.
For this example, we will download the certificate for:
1. Open the Website
Open browser and navigate to:
2. Open the Certificate Information
Click the padlock icon 🔒 next to the website address.
Depending on your browser version:
- Click the padlock / site information icon.
- Select Connection is secure.
- Select Certificate is valid.
This will open the certificate information window.
3. Open the Certificate Details
In the certificate window, review the certificate details.
You should see information such as:
4. Export the Certificate
Open the Details tab.
Select the certificate and use the option to Export the certificate.
If browser opens the Windows Certificate Viewer, select:
The Certificate Export Wizard will open.
5. Select the Certificate Format
Select:
Click:
6. Save the Certificate
Save the certificate somewhere convenient, for example:
If browser/Windows saves it as:
you can rename it to:
The important part is that it contains the exported X.509 certificate.
Example: For
https://ils.live, the exported certificate can be saved assite.crt.
Step 2 – Locate the Web Hardware Bridge Keytool
Web Hardware Bridge includes its own Java Runtime Environment (JRE), which contains the keytool.exe utility.
The default keytool location is:
Step 3 – Locate the Web Hardware Bridge Certificate Store
Web Hardware Bridge uses the Java cacerts trust store to determine which certificates it trusts.
The default certificate store location is:
This is the certificate store that needs to be updated.
Step 4 – Open Command Prompt as Administrator
- Open the Windows Start Menu.
- Search for:
- Right-click Command Prompt.
- Select Run as administrator.
- Click Yes if Windows asks for permission.
Important: Run CMD as Administrator because the
cacertsfile is located inside the Web Hardware Bridge installation directory and may require elevated permissions.
Step 5 – Import the Certificate
Use the following command:
"<-- Keytool Path -->" -importcert -alias myserver -file "<-- Certificate Path -->" -keystore "<-- WHB CA Certificate Path -->"
Replace the placeholders with the actual paths.
Example
"C:\Users\xxxx\AppData\Local\WebApp Hardware Bridge\jre\bin\keytool.exe" -importcert -alias myserver -file "C:\Users\xxxx\Downloads\site.crt" -keystore "C:\Users\xxxx\AppData\Local\WebApp Hardware Bridge\jre\lib\security\cacerts"
Step 6 – Enter the Keystore Password
After executing the command, keytool will ask for the password of the Java keystore.
You may see:
Enter the password configured for the Web Hardware Bridge Java cacerts store.
If the certificate is being imported into the standard Java cacerts store and the default password has not been changed, the password is commonly:
Note: If
changeitdoes not work, use the password configured by your Web Hardware Bridge installation or administrator. Do not repeatedly guess passwords.
Step 7 – Confirm the Certificate Import
After entering the password, keytool should display information about the certificate and ask:
Enter:
You should then see a message similar to:
This confirms that the certificate was successfully imported.
Step 8 – Verify the Certificate
To verify that the certificate was added successfully, run:
Example
"C:\Users\xxxx\AppData\Local\WebApp Hardware Bridge\jre\bin\keytool.exe" -list -keystore "C:\Users\xxxx\AppData\Local\WebApp Hardware Bridge\jre\lib\security\cacerts" -alias myserver
Enter the keystore password when prompted.
If the certificate exists, keytool will display information similar to:
Step 9 – Exit and Start Web Hardware Bridge Again
After successfully importing the certificate, Web Hardware Bridge must be completely restarted so that the updated certificate store is loaded.
- Close any application currently using Web Hardware Bridge.
- Exit Web Hardware Bridge completely.
- Check the Windows system tray and make sure the Web Hardware Bridge icon is no longer running.
- If Web Hardware Bridge is still running, use Exit/Quit from the system tray.
- Start Web Hardware Bridge again.
- Wait for Web Hardware Bridge to fully start.
- Reopen the application that uses Web Hardware Bridge.
- Test the HTTPS connection again.
Important: Simply closing the browser or application may not be enough. Web Hardware Bridge itself must be completely exited and started again so that the updated Java
cacertscertificate store is reloaded.
If Web Hardware Bridge Does Not Restart Correctly
If the certificate still does not work after restarting:
- Exit Web Hardware Bridge again.
- Verify that the Web Hardware Bridge process is no longer running in Task Manager.
- Start Web Hardware Bridge again.
- Test the connection.
If necessary, restart the Windows machine and test again.
Complete Example
Paths
Keytool Path:
Certificate Path:
WHB CA Certificate Path:
Import Command
Run CMD as Administrator and execute:
"C:\Users\xxxx\AppData\Local\WebApp Hardware Bridge\jre\bin\keytool.exe" -importcert -alias myserver -file "C:\Users\admin\Downloads\site.crt" -keystore "C:\Users\admin\AppData\Local\WebApp Hardware Bridge\jre\lib\security\cacerts"
Enter the keystore password when prompted.
When asked:
Enter:
Expected result:
Troubleshooting
1. keytool is not recognized
If you run:
and Windows reports that it cannot find the command, use the full path to keytool.exe as shown in this guide.
Example:
2. FileNotFoundException
If you receive an error indicating that the certificate cannot be found, verify that the certificate exists at the specified path.
Example:
You can verify it by opening the path in Windows File Explorer.
3. Keystore was tampered with, or password was incorrect
This normally means the entered keystore password is incorrect.
Verify the password for the WHB cacerts file.
4. Certificate already exists
If you receive an error indicating that the alias already exists, check the existing certificate:
If necessary, remove the existing alias before importing the new certificate:
Then import the certificate again.
Warning: Only delete the alias if you are sure it is the certificate that needs to be replaced.
5. HTTPS error still occurs after importing
If Web Hardware Bridge still reports an SSL/TLS certificate error:
- Verify that the correct certificate was downloaded.
- Verify that the certificate matches the HTTPS site.
- Verify that the certificate chain is trusted.
- Verify that the certificate was imported into the Web Hardware Bridge JRE's
cacerts, not another Java installation. - Verify that the alias exists in the WHB
cacerts. - Restart Web Hardware Bridge.
- Check whether the server certificate has expired.
- Check whether the server requires an intermediate CA certificate.
Quick Reference
| Item | Path |
|---|---|
| Keytool | C:\Users\xxxxx\AppData\Local\WebApp Hardware Bridge\jre\bin\keytool.exe |
| Site Certificate | C:\Users\xxxxx\Downloads\site.crt |
| WHB Certificate Store | C:\Users\xxxxx\AppData\Local\WebApp Hardware Bridge\jre\lib\security\cacerts |
Import
"<Keytool Path>" -importcert -alias myserver -file "<Certificate Path>" -keystore "<WHB CA Certificate Path>"
Verify
Restart
After successful installation, restart Web Hardware Bridge before testing the connection again.