What are Tomcat and JKS?
Tomcat is a free program that runs Java websites. An SSL certificate is a digital badge that lets visitors reach your site over safe HTTPS. A JKS file is a Java keystore. It is a locked box that holds your private key and your certificate. Tomcat reads this box when it starts.
Before you start
You need three things from your certificate provider: your signed certificate, the intermediate (chain) certificate, and the root certificate. You also need the keystore file that you made when you created your certificate request (CSR). Back up your keystore before you change it.
Steps
- Log in to your server with SSH.
- Copy your certificate files and keystore into one folder, for example
/opt/ssl. - Import the root certificate:
This adds the root certificate to your keystore.keytool -import -trustcacerts -alias root -file root.crt -keystore mysite.jks - Import the intermediate certificate:
keytool -import -trustcacerts -alias intermediate -file intermediate.crt -keystore mysite.jks - Import your own certificate. Use the same alias you used when you made the keystore:
Type the keystore password when asked.keytool -import -trustcacerts -alias tomcat -file yourdomain.crt -keystore mysite.jks - Open the Tomcat file
server.xml. It is usually in theconffolder inside the Tomcat folder. - Find or add a connector for port 8443 or 443:
Change the file path and password to your own.<Connector port="443" protocol="HTTP/1.1" SSLEnabled="true" scheme="https" secure="true" keystoreFile="/opt/ssl/mysite.jks" keystorePass="your_password" clientAuth="false" sslProtocol="TLS" /> - Save the file.
- Restart Tomcat. The command depends on your setup. A common one is:
systemctl restart tomcat - Open
https://yourdomain.comin a browser and check for the padlock.
Tip: Import the certificates in the order root, intermediate, then your own. A wrong order is a common cause of errors. Tomcat versions differ a little, so check which version you use. Ask Hostvento support if you are unsure.
If it does not work
- Check the alias name matches the one used when the keystore was created.
- Check the keystore password in
server.xml. - Make sure port 443 is open in your firewall.
- Look at the Tomcat log file in the
logsfolder for clues.
Quick recap
- A JKS file holds your key and certificate for Tomcat.
- Import root, intermediate and your certificate with
keytool. - Edit the connector in
server.xmlto point to the keystore. - Restart Tomcat and test with HTTPS.