* Announcement
GMO GlobalSign has announced the migration of the root certificate and intermediate CA certificate used for SSL server certificate.
For detailed information regarding the migration of the certificates, please refer to the attached materials below released by Seiko Solutions Inc.
SSL_Server_Certificate_Root_CA_Migration_for_TS.pdf
This certificate is used in the timestamping process for PDFs in IM-PDFTimeStamper.
Customers using this feature are requested to complete the necessary checks and actions for migration before the SSL server certificate renewal scheduled for early February 2027.
(In environments where the migration has not yet been completed, processes may not be possible after the above date)
* Checks and Actions Procedures
Since IM-PDFTimeStamper's timestamp process is a function that runs in Java, the new certificate must be added to the "Java Trusted Certificate Store (cacerts)" of the server you perform processes.
Please follow the steps below to verify that the new certificate has been added.
1. On the server that performs the timestamp process (Standalone configuration: iAP server, Distributed configuration: timestamp process server), execute the following command to obtain a list of information about the certificates stored in the keystore.
* Since a certain amount of output will be generated as a result of the execution, we recommend saving it to a text file or similar before reviewing it.
- For Java 8 or earlier versions
keytool -list -v -keystore $JAVA_HOME/jre/lib/security/cacerts -storepass changeit
* The path to the cacerts file may differ depending on your environment.
- For Java 11 or later
keytool -list -v -cacerts -storepass changeit
2. Verify that the following new certificate has been added to the list of acquired certificates.
・GlobalSign Root R46
Serial number: 11d2bbb9d723189e405f0a9d2dd0df2567d1
If the new certificate has not been added, you need to add it using one of the following methods.
A) Manually install the certificate
Please follow the steps below to install the new certificate.
https://jp.globalsign.com/support/ssl/confinfo/rootcert-import-java.html
B) Update Java to a version that supports the new certificate
For Oracle JDK, the following versions are supported:
To be sure, please update it to the latest version, including other JDKs (such as OpenJDK/Amazon Corretto).
- JDK 8: 8u421 or later (Reference: https://www.oracle.com/java/technologies/javase/8u421-relnotes.html#R180_421)
- JDK 11: 11.0.24 or later (Reference: https://www.oracle.com/java/technologies/javase/11all-relnotes.html#R11_0_24)
- JDK 17: 17.0.12 or later (Reference: https://www.oracle.com/java/technologies/javase/17-0-12-relnotes.html#R17_0_12)
- JDK 21: 21.0.4 or later (Reference: https://www.oracle.com/java/technologies/javase/21-0-4-relnotes.html)
* About proxy servers
If you are using an SSL proxy certificate (HTTPS relay via a proxy) to process timestamps on PDFs, the proxy server must also support the new certificate chain.
If you manage your certificates and certificate chains independently, you may need to take action, so please check your proxy server settings.
FAQID:1498
Request for confirmation and application regarding the root certificate migration for the SSL server certificate