java 路径为 /opt/java.

KEYTOOL=/opt/java/bin/keytool
CACERTS=/opt/java/jre/lib/security/cacerts

DOMAIN=qiansw.com(修改为你的二级域名)
DOMAIN_ALIAS=`echo $DOMAIN|sed 's/\.//g'`
$KEYTOOL -delete -alias $DOMAIN_ALIAS -keystore $CACERTS -storepass changeit
$KEYTOOL -genkey -v -alias $DOMAIN_ALIAS -keyalg RSA -storetype pkcs12 -keystore keystore -validity 36500 \
-dname "CN=*.$DOMAIN,OU=$DOMAIN_ALIAS,O=$DOMAIN_ALIAS,L=BJ,ST=BJ,C=CN" -storepass changeit -keypass changeit
$KEYTOOL -export -alias $DOMAIN_ALIAS -storetype pkcs12 -keystore keystore -file $DOMAIN_ALIAS.cer -storepass changeit
$KEYTOOL -import -trustcacerts -alias $DOMAIN_ALIAS -keystore $CACERTS -file $DOMAIN_ALIAS.cer -storepass changeit