Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Install a JKS SSL Certificate on Tomcat

This guide shows you how to put an SSL certificate in a Java keystore (JKS) file and use it with the Tomcat server. You need root or admin access to your server.

SSL and Security2 min read10 steps

What are Tomcat and JKS?

Tomcat is a free program that runs Java websites. An SSL certificate is a digital badge that lets visitors reach your site over safe HTTPS. A JKS file is a Java keystore. It is a locked box that holds your private key and your certificate. Tomcat reads this box when it starts.

Before you start

You need three things from your certificate provider: your signed certificate, the intermediate (chain) certificate, and the root certificate. You also need the keystore file that you made when you created your certificate request (CSR). Back up your keystore before you change it.

Steps

  1. Log in to your server with SSH.
  2. Copy your certificate files and keystore into one folder, for example /opt/ssl.
  3. Import the root certificate:
    keytool -import -trustcacerts -alias root -file root.crt -keystore mysite.jks
    This adds the root certificate to your keystore.
  4. Import the intermediate certificate:
    keytool -import -trustcacerts -alias intermediate -file intermediate.crt -keystore mysite.jks
  5. Import your own certificate. Use the same alias you used when you made the keystore:
    keytool -import -trustcacerts -alias tomcat -file yourdomain.crt -keystore mysite.jks
    Type the keystore password when asked.
  6. Open the Tomcat file server.xml. It is usually in the conf folder inside the Tomcat folder.
  7. Find or add a connector for port 8443 or 443:
    <Connector port="443" protocol="HTTP/1.1" SSLEnabled="true"
      scheme="https" secure="true"
      keystoreFile="/opt/ssl/mysite.jks"
      keystorePass="your_password"
      clientAuth="false" sslProtocol="TLS" />
    Change the file path and password to your own.
  8. Save the file.
  9. Restart Tomcat. The command depends on your setup. A common one is:
    systemctl restart tomcat
  10. Open https://yourdomain.com in a browser and check for the padlock.
Tip: Import the certificates in the order root, intermediate, then your own. A wrong order is a common cause of errors. Tomcat versions differ a little, so check which version you use. Ask Hostvento support if you are unsure.

If it does not work

  • Check the alias name matches the one used when the keystore was created.
  • Check the keystore password in server.xml.
  • Make sure port 443 is open in your firewall.
  • Look at the Tomcat log file in the logs folder for clues.

Quick recap

  • A JKS file holds your key and certificate for Tomcat.
  • Import root, intermediate and your certificate with keytool.
  • Edit the connector in server.xml to point to the keystore.
  • Restart Tomcat and test with HTTPS.