JKS (Java KeyStore) to PFX/P12

May 25, 2018 in Windows and Certificate FAQ

You may have to convert a JKS to a PKCS#12 for several reasons. For example, if you have to copy or transfer your certificate from a Tomcat server (or a platform using JKS file type) to a server using PKCS#12 file type such as Microsoft. The PKCS#12 could also be converted to be installed on platforms using PEM files (Apache for example).


  • Keytool application (supplied along with JDK 1.1 and higher)
  • A JKS file containing the certificate, the private key and the certification chain

Command to create the PFX/P12 file:

> keytool -importkeystore -srckeystore jksFileName.jks -destkeystore pkcs12FileName.p12 -srcstoretype JKS -deststoretype PKCS12

You'll need to modify these parameters:

  1. pkcs12FileName.p12: path to the PKCS#12 file (.p12 or .pfx extension) that is going to be created.
  2. jksFileName.jks: path to the keystore that you want to convert.

Related Article :