Request for confirmation and application regarding the root certificate migration for the SSL server certificate

 
* Announcement

GMO GlobalSign has announced the migration of the root certificate and intermediate CA certificate used for SSL server certificate.

For detailed information regarding the migration of the certificates, please refer to the attached materials below released by Seiko Solutions Inc.

SSL_Server_Certificate_Root_CA_Migration_for_TS.pdf

This certificate is used in the timestamping process for PDFs in IM-PDFTimeStamper.

Customers using this feature are requested to complete the necessary checks and actions for migration before the SSL server certificate renewal scheduled for early February 2027.
(In environments where the migration has not yet been completed, processes may not be possible after the above date)

* Checks and Actions Procedures

Since IM-PDFTimeStamper's timestamp process is a function that runs in Java, the new certificate must be added to the "Java Trusted Certificate Store (cacerts)" of the server you perform processes.

Please follow the steps below to verify that the new certificate has been added.

1. On the server that performs the timestamp process (Standalone configuration: iAP server,  Distributed configuration: timestamp process server), execute the following command to obtain a list of information about the certificates stored in the keystore.
* Since a certain amount of output will be generated as a result of the execution, we recommend saving it to a text file or similar before reviewing it.

- For Java 8 or earlier versions
    keytool -list -v -keystore $JAVA_HOME/jre/lib/security/cacerts -storepass changeit
    * The path to the cacerts file may differ depending on your environment.
- For Java 11 or later
    keytool -list -v -cacerts -storepass changeit

2. Verify that the following new certificate has been added to the list of acquired certificates.

・GlobalSign Root R46
    Serial number: 11d2bbb9d723189e405f0a9d2dd0df2567d1

If the new certificate has not been added, you need to add it using one of the following methods.

A) Manually install the certificate

Please follow the steps below to install the new certificate.

https://jp.globalsign.com/support/ssl/confinfo/rootcert-import-java.html

B) Update Java to a version that supports the new certificate

For Oracle JDK, the following versions are supported:
To be sure, please update it to the latest version, including other JDKs (such as OpenJDK/Amazon Corretto).

- JDK 8: 8u421 or later (Reference: https://www.oracle.com/java/technologies/javase/8u421-relnotes.html#R180_421)
- JDK 11: 11.0.24 or later (Reference: https://www.oracle.com/java/technologies/javase/11all-relnotes.html#R11_0_24)
- JDK 17: 17.0.12 or later (Reference: https://www.oracle.com/java/technologies/javase/17-0-12-relnotes.html#R17_0_12)
- JDK 21: 21.0.4 or later (Reference: https://www.oracle.com/java/technologies/javase/21-0-4-relnotes.html)

* About proxy servers

If you are using an SSL proxy certificate (HTTPS relay via a proxy) to process timestamps on PDFs, the proxy server must also support the new certificate chain.

If you manage your certificates and certificate chains independently, you may need to take action, so please check your proxy server settings.

FAQID:1498
Was this article helpful?
0 out of 0 found this helpful
Powered by Zendesk