---
title: How to import a custom CA certificate into Hyperglance's truststore (Legacy Docker Guide)
description: How to add a Root CA certificate.  This will fix PKIX errors.
---

[Skip to content](https://support.hyperglance.com/knowledge/how-to-import-a-custom-ca-certificate-into-hyperglances-truststore-legacydocker#main-content)

English

Show submenu for translations

[More support](https://support.hyperglance.com/knowledge/kb-tickets/new?hsLang=en)

![](https://support.hyperglance.com/hs-fs/hubfs/hyperglance.png?width=100&height=75&name=hyperglance.png)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [More support](https://support.hyperglance.com/knowledge/kb-tickets/new)
- [Contact Us](https://www.hyperglance.com/contact/)

[Contact Us](https://www.hyperglance.com/contact/)

 How can we help you?

- There are no suggestions because the search field is empty.

1. [Hyperglance Support](https://support.hyperglance.com/knowledge?hsLang=en)
2. [Setup & Configuration](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en)
3. [Legacy Docker-based deployments](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#legacy-docker-based-deployments)

# How to import a custom CA certificate into Hyperglance's truststore (Legacy Docker Guide)

## This guide will show how to import a root CA certificate into Hyperglance's Java truststore. 

THIS GUIDE IS DEPRECATED AND PERTAINS TO THE LEGACY DOCKER BASED ARCHITECTURE.  [SEE LATEST VERSION.](https://support.hyperglance.com/knowledge/how-to-import-a-custom-ca-certificate-into-hyperglances-truststore?hsLang=en)

If you are experiencing "PKIX path building failed" errors then it is likely that you need to add your company's root CA certificate to Hyperglance's truststore.

Note: This is not the same as the SSL/TLS server certificate that Hyperglance presents to web browsers. To change that see [\[this article\]](https://support.hyperglance.com/knowledge/how-to-set-a-custom-https-ssl/tls-certificate-legacydocker?hsLang=en)

**STEP BY STEP GUIDE:**

1\) Copy your root CA certificate pem file from your local computer to `/var/lib/data/hyperglance/` on the Hyperglance system.

2\) Gain terminal access (SSH) to the Hyperglance instance/VM to run the following commands...

3\) Copy Java's default cacerts file out from the container:

```
sudo docker cp wildfly:/opt/wildfly/java/lib/security/cacerts /var/lib/data/hyperglance/
```

4\) Ensure the file is owned by the wildfly user:

```
sudo chown wildfly:wildfly /var/lib/data/hyperglance/cacerts
```

5\) Sanity check.  List the directory and make sure you see a cacerts file and your root CA certificate and that cacerts is owned by wildfly:

```
ls -la /var/lib/data/hyperglance
```

6\) Add your pem file to the cacerts truststore.

If your root CA file is not called `rootca.pem` then adjust the the `-v` mapping in the command accordingly.

If you are running this multiple times to add more than one cert then give each one a unique alias.

```
sudo docker run --rm \  -v "/var/lib/data/hyperglance/cacerts:/tmp/cacerts" \  -v "/var/lib/data/hyperglance/rootca.pem:/tmp/custom.crt" \  --user root --entrypoint bash \  hyperglance/wildfly-v2 -c "\    /opt/wildfly/java/bin/keytool \      -importcert -trustcacerts -noprompt \      -keystore /tmp/cacerts \      -storepass changeit \      -alias hyperglance-user-added-ca \      -file /tmp/custom.crt"
```

After running this command you should see this message:

```
Certificate was added to keystore
```

7\) Add a volume mapping for your cacerts truststore:

```
echo "      - /var/lib/data/hyperglance/cacerts:/opt/wildfly/java/lib/security/cacerts:ro" | sudo tee -a /etc/docker-compose.yml
```

8\) Update the service (Note: Hyperglance will restart and re-ingest all data)

```
sudo docker-compose -f /etc/docker-compose.yml up -d
```

 

Hyperglance will now be using your new CA root certificate.

- [Before You Start](https://support.hyperglance.com/knowledge/before-you-start?hsLang=en#main-content)

    - [Kubernetes](https://support.hyperglance.com/knowledge/before-you-start?hsLang=en#kubernetes)
    - [GCP](https://support.hyperglance.com/knowledge/before-you-start?hsLang=en#gcp)
    - [AWS](https://support.hyperglance.com/knowledge/before-you-start?hsLang=en#aws)
    - [Azure](https://support.hyperglance.com/knowledge/before-you-start?hsLang=en#azure)
- [Using Hyperglance](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#main-content)

    - [Automations](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#automations)
    - [Inventory & Diagrams](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#inventory-diagrams)
    - [Rules](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#rules)
    - [Cost Management](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#cost-management)
    - [Dashboards](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#dashboards)
    - [Security & Compliance](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#security-compliance)
- [Setup & Configuration](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#main-content)

    - [Updating & Migrating](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#updating-migrating)
    - [General](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#general)
    - [RBAC & Users](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#rbac-users)
    - [STIGS & FIPS](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#stigs-fips)
    - [AWS](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#aws)
    - [Azure](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#azure)
    - [Kubernetes](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#kubernetes)
    - [GCP](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#gcp)
    - [API](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#api)
    - [Legacy Docker-based deployments](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#legacy-docker-based-deployments)
    - [AI](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#ai)

[![Chill listening crop-3](https://support.hyperglance.com/hs-fs/hubfs/hyperglance.png?width=134&height=24&name=hyperglance.png "Chill listening crop-3")](https://www.hyperglance.com/)

2880 Zanker Road, Suite 203, San Jose, CA 95134

<https://www.linkedin.com/company/hyperglance/>

Copyright © 2025 Hyperglance. All rights reserved.