diff --git a/closed/src/java.base/share/classes/openj9/internal/security/FIPSConfigurator.java b/closed/src/java.base/share/classes/openj9/internal/security/FIPSConfigurator.java index 5ac586fd787..8cfc53a7d8e 100644 --- a/closed/src/java.base/share/classes/openj9/internal/security/FIPSConfigurator.java +++ b/closed/src/java.base/share/classes/openj9/internal/security/FIPSConfigurator.java @@ -116,6 +116,11 @@ public static boolean configureFIPS(Properties props) { props.put("keystore.type", "PKCS11"); System.setProperty("javax.net.ssl.keyStore", "NONE"); + // Add trust store information. + System.setProperty("truststore.type", "PKCS11"); + System.setProperty("javax.net.ssl.trustStore", "NONE"); + System.setProperty("javax.net.ssl.trustStoreProvider", "SunPKCS11-NSS-FIPS"); + // Add FIPS disabled algorithms. String disabledAlgorithms = props.get("jdk.tls.disabledAlgorithms") + ", X25519, X448"