A developer utility for fetching, inspecting, and trusting remote TLS
certificates — so you stop wrestling with raw keytool/openssl incantations
to fix ValidatorException: PKIX path building failed against internal servers.
getcertgo inspect <url>— Pull a host's certificate chain and print a color-coded table (role, CN, issuer, validity, SHA-256 fingerprint). Expired/expiring certs are highlighted.getcertgo import <url>— Fetch the chain, interactively pick which certificates to trust, and add them to a Java keystore. Auto-discovers the JVMcacerts(viaJAVA_HOMEand common OS paths) unless--keystoreis given. Useskeytoolwhen available (lossless), otherwise writes natively.getcertgo list [filter]— List trusted certificates in a keystore, with an optional case-insensitive filter over alias / CN / issuer.getcertgo doctor <url>— Do a real verifying handshake using trust anchors from the Java keystore or the OS trust store (--system) to confirm a host is now trusted.
The fetch phase uses a "blind trust" TLS client (verification disabled) so it can retrieve certificates from self-signed or untrusted internal hosts without crashing first.
Requires Go 1.22+.
# Install directly
go install github.com/ravocode/get-cert-go@latest
# Or build from source
go mod tidy
go build -o getcertgo . # produces ./getcertgo (getcertgo.exe on Windows)Pre-built binaries are published on every release. Download the one for your platform from the Releases page:
| Platform | Asset |
|---|---|
| Linux x64 | getcertgo-linux-amd64 |
| Linux ARM64 | getcertgo-linux-arm64 |
| macOS Intel | getcertgo-darwin-amd64 |
| macOS Apple Silicon | getcertgo-darwin-arm64 |
| Windows x64 | getcertgo-windows-amd64.exe |
No Go toolchain required — just download, make executable (chmod +x on
Linux/macOS), and run.
# Inspect a chain before trusting anything
getcertgo inspect https://dev-cluster.local
# Import into the default JVM cacerts (interactive selection + password prompt)
getcertgo import https://dev-cluster.local
# Import the whole chain non-interactively into a custom store
getcertgo import https://dev-cluster.local --all --keystore ./my-store.jks
# Search what's already trusted
getcertgo list "enterprise ca"
# Verify the host now validates against the keystore
getcertgo doctor https://dev-cluster.local
# Verify using the OS trust store instead
getcertgo doctor https://dev-cluster.local --system| Flag | Description |
|---|---|
--keystore <path> |
Keystore to target (default: auto-discovered cacerts) |
--password <pw> |
Keystore password (default: prompt, falls back to changeit) |
--timeout <dur> |
Connection timeout (default 10s) |
--no-color |
Disable ANSI colors |
| Flag | Description |
|---|---|
--all |
Import every certificate in the chain without prompting |
--alias <name> |
Alias to use (single-certificate imports only) |
--native |
Force native Go keystore writing instead of keytool |
--system |
Import into the OS trust store instead of a Java keystore |
--machine |
With --system, target the machine-wide store (needs admin/root) |
getcertgo import <url> --system installs the selected certificate(s) as trusted
roots in the operating system trust store, which is honored by Chrome, Edge and
Safari (and by curl/Python on macOS/Linux). Per OS:
| OS | Mechanism | Default scope | Machine scope (--machine) |
|---|---|---|---|
| Windows | certutil -addstore Root |
CurrentUser\\Root (no admin) |
LocalMachine\\Root (admin) |
| macOS | security add-trusted-cert |
login keychain (no sudo) | System keychain (sudo) |
| Linux | copy to CA anchors + update-ca-certificates/update-ca-trust |
machine-wide (root) | machine-wide (root) |
Notes:
- Import the root CA; browsers build the chain from the leaf plus the intermediates the server sends.
- The "Not secure" warning only clears if the certificate is otherwise valid:
present SAN matching the hostname (CN alone is ignored), not expired, and
EKU = serverAuth. Restart the browser afterwards. - Firefox uses its own (NSS) trust store and is unaffected; enable
security.enterprise_roots.enabledinabout:configor import into Firefox directly.
- JKS (legacy default) — read and written natively with 100% fidelity.
- PKCS12 (JDK 9+ default) — read natively where possible. Writing delegates
to
keytoolif installed to perfectly preserve existing entry aliases.
keytool is discovered automatically by checking next to the target keystore
(e.g., ../bin/keytool), checking JAVA_HOME/bin, and finally searching your system PATH.
If keytool is not installed:
getcertgostill works entirely on its own via native Go implementations!- JKS operations remain completely lossless.
- Native PKCS12 writes will succeed, but you'll see a warning that the "friendly names" (aliases) of pre-existing entries in the keystore might be regenerated.
- Caveat: Some modern JDKs (like JDK 21) use a MAC-less PKCS12 format for
cacertsthat the strict native decoder rejects. If you encounter apkcs12: no MAC in dataerror, you will need to install a JDK sogetcertgocan usekeytoolas a fallback.
--docker— inject certs into a running Docker daemon / container store.
