We are assuming that you already have installed working Tomcat server in your system. If not you can visit to earlier article Install Tomcat 7 on CentOS, RHEL or Ubuntu, Debian Systems. This article can be used for Linux as well as Windows hosts both, the only thing we need to change directory path of keystore.
Step 1 – Create a Keystore
A Java KeyStore (JKS) is a repository of security certificates. keytool is the command line utility for creating and managing keystore. This command is available with JDK and JRE both. We just need to make sure that JDK or JRE is configured with PATH environment variable.
keytool -genkey -alias svr1.tecadmin.net-keyalg RSA -keystore /etc/pki/keystore
Enter keystore password: Re-enter new password: What is your first and last name? [Unknown]:
Rahul KumarWhat is the name of your organizational unit? [Unknown]: WebWhat is the name of your organization? [Unknown]: TecAdmin Inc.What is the name of your City or Locality? [Unknown]: DelhiWhat is the name of your State or Province? [Unknown]: DelhiWhat is the two-letter country code for this unit? [Unknown]: INIs CN=Rahul Kumar, OU=Web, O=TecAdmin Inc., L=Delhi, ST=Delhi, C=IN correct? [no]: yesEnter key password for (RETURN if same as keystore password): Re-enter new password:
Step 2 – Get CA Signed SSL [
Ignore SelfSigned Users ]
You don’t need to do this step if you are going to use self-signed SSL certificate. If you want to purchase a valid ssl from certificate authorities, then you need to first create a CSR, Use the following command to do it.
keytool -certreq -keyalg RSA -alias svr1.tecadmin.net -file svr1.csr -keystore /etc/pki/keystore
Above command will prompt for keystore password and generate the CSR file. Use this CSR and purchase ssl certificate from any certificate authorities.
After issued certificate by CA, you will have following files – root certificate, intermediate certificate, and certificate file. In my case the filenames are
A. root.crt (root certificate)
B. intermediate.crt (intermediate certificate)
C. svr1.tecadmin.net.crt ( Issued certificate by CA )
Install the root certificate:
keytool -import -alias root -keystore /etc/pki/keystore-trustcacerts -file root.crt
Install the intermediate certificate:
keytool -import -alias intermed -keystore /etc/pki/keystore-trustcacerts -file intermediate.crt
Install the issued certificate:
keytool -import -alias svr1.tecadmin.net-keystore /etc/pki/keystore-trustcacerts -file svr1.tecadmin.net.crt
Step 3 – Setup Tomcat Keystore
Now go to your Tomcat installation directory and edit conf/server.xml file in your favorite editor and update the configuration as below. You may also change the port from 8443to some other port if required.
8443" protocol="HTTP/1.1" connectionTimeout="20000" redirectPort="8443" SSLEnabled=" true" scheme=" https" secure=" true" sslProtocol=" TLS" keystoreFile=" /etc/pki/keystore" keystorePass=" _password_" />
Step 4 – Restart Tomcat
Use your init script (if have) to restart tomcat service, In my case i use shell scripts (startup.sh and shutdown.sh) for stopping and starting tomcat.
Step 5 – Verify Setup
As we have done all the required configuration for tomcat setup. lets access tomcat in your browser on the configured port in step 2.
Note: This article has been tested with Tomcat 7 on CentOS 6.5 using Java 8.