Skip to content

Install Certificates on Tomcat KeyStore

Tomcat usually uses a JKS or PKCS12 KeyStore.

Convert PFX to JKS

Replace the file name and password:

bash
keytool -importkeystore   -srckeystore domain-com.pfx   -srcstoretype pkcs12   -srcalias 1   -srcstorepass 123456   -destkeystore domain-com.jks   -deststoretype jks   -deststorepass 123456   -destalias server

Tomcat Connector Example

xml
<Connector port="443" protocol="org.apache.coyote.http11.Http11NioProtocol"
           maxThreads="150" SSLEnabled="true">
    <SSLHostConfig>
        <Certificate certificateKeystoreFile="/path/domain-com.jks"
                     certificateKeystorePassword="123456"
                     type="RSA" />
    </SSLHostConfig>
</Connector>

Restart Tomcat and open HTTPS.

Released under internal 12SSL documentation guidelines.