Keytool -import using a specific TrustStrore

We've set up our own specific Truststore that holds just the CAs relevant to the our organisation for use with ssl requests. This works quite happily, but it has come up to key renewal time. This truststore is separate from the listener and client keys which each live in their own jks files.

Looking through the keytool manual, I don't see a way to specify using this truststore while importing the signed certificate. As the organisations Authorities haven't been added to the default cacerts store I get a "Failed to establish chain from reply" error.

This error is entirely appropriate because the chain doesn't exist in the cacerts default store. Is there a way to get keytool to use a local truststore.jks file without replacing the default cacerts, or importing the CAs into the listener/client jks files?