I have a Tomcat server with a certificate chain for HTTPS stored in a Java keystore. The chain includes the self-signed root CA certificate. Although this is apparently ok
keytool -delete -alias -keystore lib/security/cacerts -storepass changeit