openssl pkcs12 -in cert.p12 -cacerts -nodes -nokeys > rootcert.pem also you could try to user KeyStore Explorer