# Expired certificate payara5

**URL:** <https://forum.payara.fish/t/expired-certificate-payara5/1614>\
**Category:** Technical Discussion\
**Created:** [January 31, 2025, 10:08pm UTC](https://forum.payara.fish/t/expired-certificate-payara5/1614 "2025-01-31T22:08:21Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jmjamison](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.payara.fish/jmjamison/32/279_2.png) [@jmjamison](https://forum.payara.fish/u/jmjamison)\
**Post date:** [January 31, 2025, 10:08pm UTC](https://forum.payara.fish/t/expired-certificate-payara5/1614/1 "2025-01-31T22:08:21Z")

</div>

I’m running payara5 for the Dataverse repository software. The certificate has expired and I’ve tried importing a new one but getting error:  
NCLS-ADMIN-00010  
javax.net.ssl.SSLHandshakeException: NotAfter: Sun Aug 18 13:30:10 UTC 2024

Do I need to delete or remove expired certificates before the new ones are used. I’ve followed the directions from:  
[https://docs.payara.fish/community/docs/5.201/documentation/payara-server/server-configuration/ssl-certificates.html](https://docs.payara.fish/community/docs/5.201/documentation/payara-server/server-configuration/ssl-certificates.html)

Thank you in advnace,  
Jamie

---

<div class="post-metadata">

**Author:** ![StevenHachel](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.payara.fish/stevenhachel/32/137_2.png) [@StevenHachel](https://forum.payara.fish/u/StevenHachel)\
**Post date:** [February 7, 2025, 7:37pm UTC](https://forum.payara.fish/t/expired-certificate-payara5/1614/2 "2025-02-07T19:37:30Z")

</div>

Hello,

I like to use the [Keystore Explorer](https://keystore-explorer.org) for this. This allows you to simply delete your certificates located in the /glassfish/domains/domain1/config folder and add the newly created certificates.  
I hope that helps a bit.

Steven

---

<div class="post-metadata">

**Author:** ![jmjamison](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.payara.fish/jmjamison/32/279_2.png) [@jmjamison](https://forum.payara.fish/u/jmjamison)\
**Post date:** [February 12, 2025, 8:44pm UTC](https://forum.payara.fish/t/expired-certificate-payara5/1614/3 "2025-02-12T20:44:17Z")

</div>

Yes, that is very helpful. I have keystore explorer installed locally and will try that out.

---

<div class="post-metadata">

**Author:** ![jmjamison](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.payara.fish/jmjamison/32/279_2.png) [@jmjamison](https://forum.payara.fish/u/jmjamison)\
**Post date:** [February 20, 2025, 10:30pm UTC](https://forum.payara.fish/t/expired-certificate-payara5/1614/4 "2025-02-20T22:30:21Z")

</div>

I tried keystore. It looks really helpful but my payara server is headless so until I get around that problem I won’t be able to use keystore.

But thank you for the suggestion.

---

<div class="post-metadata">

**Author:** ![rbillapati](https://avatars.discourse-cdn.com/v4/letter/r/c67d28/32.png) [@rbillapati](https://forum.payara.fish/u/rbillapati)\
**Post date:** [April 3, 2025, 1:28pm UTC](https://forum.payara.fish/t/expired-certificate-payara5/1614/5 "2025-04-03T13:28:55Z")

</div>

Hi Jamie,

You can proceed to remove the expired certificates by using the following keytool command -

> keytool -delete -alias _cert-alias_ -keystore _/path/to/keystore_ -storepass _password_.

Or you can use the following asadmin command to remove all the expired certificates from the domain _mydomainname_ -

> asadmin remove-expired-certificates --domainname _mydomainname_

Then, you can import the new certificates using the following commands -

To add the certificate to the Keystore using the keytool command -

> keytool -importkeystore -destkeystore keystore.p12 -srckeystore mycert.p12 -srcstoretype PKCS12 -alias _cert-alias_

To add the certificate to the Keystore using Asadmin command -

> asadmin add-to-keystore --file _mycert.p12_ _cert-alias_

To add the certificate to the Truststore using keytool command -

> keytool -importcert -trustcacerts -destkeystore cacerts.jks -file _mycert.crt_ -alias _cert-alias_

To add the certificate to the Truststore using Asadmin command -

> asadmin add-to-truststore --file _mycert.crt__cert-alias_

For more information, please refer to the following blog post -

> **[Securing Payara Server with Custom SSL Certificate](https://blog.payara.fish/securing-payara-server-with-custom-ssl-certificate)**
>
> See how to set up certificates to secure either HTTP protocol or remote access to the Payara Server administration interface.

Thanks & regards  
Ramya
