1. List Trusted cacerts
keytool -list -v -keystore $JAVA_HOME/jre/lib/security/cacerts
2. Import New cert into keystore (e.g. Amazon)
keytool -import -trustcacerts -file [filename] -alias [alias] -keystore $JAVA_HOME/jre/lib/security/cacerts
->
keytool -import -trustcacerts -file AmazonRootCA1.cer -alias AmazonRootCA1 -keystore $JAVA_HOME/jre/lib/security/cacerts
3. Delete cert from keystore
keytool -delete -alias [alias] -keystore $JAVA_HOME/jre/lib/security/cacerts
Ref: https://www.sslshopper.com/article-most-common-java-keytool-keystore-commands.html