If you are unfamiliar with the difference between a keystore and a truststore, check out this article.

  1. In the WebSphere admin console, expand Security and select SSL certificate and key management.
  2. Select key stores and certificates.
  3. Select a truststore.
  4. Select Personal certificates or Signer certificates.
  5. Check mark the certificate you want to extract and select Extract.
  6. Enter any file name, such as mycert.crt and select OK. The filename must end with a validate certificate file extension, such as .crt or .cer or .pem.

The certificate will be extracted to a directory on your server, such as /opt/WebSphere/AppServer/profiles/profile001/etc/mycert.crt.


