Knowledge Base
How to install an SSL certificate on Tomcat
Overview
By the end of this article you will have an issued SSL certificate installed on your Tomcat server and Tomcat configured to accept secure connections on your chosen port. The article covers, in order: the Java KeyStore (JKS) file that holds your certificate and private key; the files you must have before you start, including the certificate issued by the Certification Authority (CA), the intermediate certificates, and the private key created with your Certificate Signing Request (CSR); converting those files from Privacy Enhanced Mail (PEM) format to Public Key Cryptography Standards #7 (PKCS#7) format; importing the converted file into your existing keystore with the keytool command; configuring the SSL connector in the Tomcat server configuration file; and verifying the result in a browser. If you have more than one server or device, repeat this procedure on each one you need to secure.
What is a Java KeyStore (JKS)?
A Java KeyStore (JKS) is a file used by Tomcat to store a private key together with the certificates that belong to it. When you generated your Certificate Signing Request (CSR), a keystore file and a private key were created and stored under an alias name. Your issued certificate must be imported back into that same keystore, under that same alias, so that Tomcat can match the certificate to its private key.
Prerequisites
Have all of the following available before you begin:
- Your server certificate — the certificate issued by the Certification Authority (CA) for your domain. It is usually sent to you by email; you can also download it from your Account Dashboard by opening your order.
- Intermediate certificates — these allow connecting devices to identify the issuing Certification Authority (CA). There may be more than one. If your certificate arrived in a ZIP folder, the intermediate certificates are included, sometimes labelled as a CA Bundle.
- Your private key — this file is on your server, or in your possession if you generated your Certificate Signing Request (CSR) with a separate generator tool. On some platforms, such as Microsoft Internet Information Services (IIS), the private key is tracked by the server and is not directly visible.
- The keystore and alias name used when the Certificate Signing Request (CSR) was created, and access to the directory holding them.
- Command-line access to the server and a text editor for the Tomcat configuration file.
Steps to Install the Certificate
Step 1 — Convert your certificate files to PKCS#7 format
Tomcat imports the certificate chain as a single Public Key Cryptography Standards #7 (PKCS#7) file, so convert your Privacy Enhanced Mail (PEM) files (.cer or .crt) first. In the certificate converter tool:
- Select PEM as the current type.
- Select P7B as the type to change to.
- Upload your server certificate.
- Upload the root Certification Authority (CA) certificate. This certificate is normally pre-installed on your server, but uploading it again helps build the correct certificate chain.
- Upload your intermediate certificates. If you have two intermediate files, upload the second one in the root certificate field. The root itself is already present on the server, so the chain still builds correctly.
- Click Convert and save the resulting
.p7bfile on your server or device.
Step 2 — Import the certificate into your existing keystore
Go to the directory where the keystore and the Certificate Signing Request (CSR) were saved. Install the certificate into that same keystore, under the same alias name, by running:
keytool -import -trustcacerts -alias server -file your_file_name.p7b -keystore your_domain_name.jks
Replace your_domain_name with the primary domain you are securing and your_file_name with the name of the Public Key Cryptography Standards #7 (PKCS#7) file you saved in Step 1. Enter Y or Yes when prompted to trust the certificate. A successful import returns the message: Certificate reply was installed in keystore.
Importing into a different keystore or a different alias causes the installation to fail, and you may have to repeat the process from the beginning.
Step 3 — Configure the SSL connector in Tomcat
The SSL connector is the Tomcat setting that allows the server to accept secure connections. Open the Tomcat configuration .xml file in a text editor such as Notepad; it is normally in the conf folder of the server's home directory.
- Locate the connector you want to secure with the new keystore, usually the one on port 443 or 8443.
- If the connector is commented out, remove the comment tags
<!--and-->. - Enter the keystore filename and password, as in this example:
<Connector port="443" maxHttpHeaderSize="8192" maxThreads="150"
minSpareThreads="25" maxSpareThreads="75" enableLookups="false"
disableUploadTimeout="true" acceptCount="100" scheme="https"
secure="true" SSLEnabled="true" clientAuth="false"
sslProtocol="TLS" keyAlias="server"
keystoreFile="/home/user_name/your_domain_name.jks"
keystorePass="your_keystore_password" />
On versions earlier than Tomcat 7, use keypass instead of keystorePass.
- Save the changes to the
.xmlfile. - Restart the Tomcat server so the new configuration takes effect.
How to Verify the Installation
Open your site in a browser at https://yourdomain.tld and view the certificate or site information. The connection should be secure, and the certificate details should show your domain, the issuing Certification Authority (CA), and the correct validity dates. If the browser still shows the previous certificate or an insecure connection, restart the Tomcat server again and retest.
Troubleshooting
Issue: The keytool import fails or the certificate does not appear in the keystore.
Cause: The certificate was imported into a different keystore or a different alias from the one used to create the Certificate Signing Request (CSR). Solution: Import the .p7b file into the original keystore file, using the original alias name.
Issue: The browser reports an incomplete or untrusted certificate chain.
Cause: One or more intermediate certificates were not included in the converted Public Key Cryptography Standards #7 (PKCS#7) file. Solution: Repeat Step 1, uploading every intermediate certificate supplied with your order, then import the new file again.
Issue: Tomcat starts but the site is still not reachable over HTTPS.
Cause: The SSL connector is still commented out, points at the wrong keystore file, or uses the wrong password. Solution: Recheck the connector entry in the .xml file, confirm the keystore path and password, save the file, and restart Tomcat.
Frequently Asked Questions
Do I need to install the certificate on every server?
Yes. If you have more than one server or device, install the certificate on each server or device you need to secure.
Can I import the certificate into a new keystore?
No. The certificate must be imported into the keystore that was used to generate the Certificate Signing Request (CSR), under the same alias name, because that keystore holds the matching private key.
Which port should the SSL connector use?
Most Tomcat installations use port 443 or 8443 for secure connections. Configure the connector that matches the port your site is served on.
Where is the Tomcat configuration file stored?
The .xml configuration file is generally stored in the conf folder inside the Tomcat server's home directory.
Similar Questions
- How do I install an SSL certificate on Tomcat?
- What are the steps to import a certificate into a Tomcat keystore?
- Tomcat SSL connector setup
- How do I convert a certificate to PKCS#7 for Tomcat?
- Why does Tomcat not use my new certificate after installation?
Related Articles:
How to Import and Configure an Existing SSL/TLS Certificate for HTTPS on Apache Tomcat (with IIS/Apache conversion examples) | Sectigo® Official
Need assistance?
Contact our team for help with your purchase or issuing your certificate.