I have a requirement where new CA certificates (self signed or trusted) which are either imported by user or added to system trust store through a policy onto the Windows OS trust store (either to Trusted Root Certificate Authority or Intermediate CA's) to be synced or mirrored to Java's Jssecacerts or any custom Java trust store. Keytool does not have an option to read from OS system trust store and Java's SUNMSCAPI works okay with Windows_Root or Windows_My, but does not work as expected with system's Intermediate CA and also the its support is not that great.
Hence I want to know if there is any proven solution which works well in syncing/mirroring any new CA Certificates added to system Trusted Root CA and Intermediate CA to the Java Trust store so that Java can accept any server certificate issued by new RootCA or Intermediate CA.