The JDK 8 installation includes the keytool application, so you can run the keytool commands in this section with no additional configuration.
Generate a key pair and certificate
Perform the following steps to generate a server key pair and self-signed certificate:1
Execute the following command:
The -alias field sets a name to identify the key pair and certificate to be generated. It can be any name (for example, apksignerdemo).
Shell
2
When prompted, answer questions about the server certificate shown in the following example and enter the keystore password, which all keytool and jarsigner commands use moving forward:
None
Generate and export a CSR
Perform the following steps to generate and export a CSR:1
To generate and export a CSR, run the following command:
Shell
2
Enter the keystore password.
3
Get the CSR signed by a CA, either third-party or internal.
After it is signed, the server certificate returned by the CA is imported along with the CA certificate.
Import a CA root certificate
Perform the following steps to import a CA root certificate:1
To import the CA root certificate, run the following command:
Shell
2
Enter the keystore password.
3
When prompted to trust the certificate, enter Yes.
Shell
Import a server certificate
Perform the following steps to import a server certificate signed by a CA:1
To import the signed server certificate, run the following command:
Shell
2
Enter the keystore password.
If the command succeeds, you should see an output similar to the following:Certificate reply was installed in keystore.

