跳到主要內容

Setup Tomcat HTTPS (with JDK 8 to Java 15) in 2 mins

 Setup Tomcat 9 HTTPS/SSL

To have a quick view, you may see the video(s):

https://www.youtube.com/watch?v=WDGoF13vhZU



1. Generate Keystore

I am using JDK 15 to generate the keystore. But the steps are similar with Tomcat 6 + openjdk 8(as I have tried it before writing this doc)

  1. Use “keytool” command to create a self-signed certificate.
    During the keystore creation process, you need to assign a password and fill in the certificate’s details.

D:\apache-tomcat-9.0.38\conf>keytool -genkey -alias tomcatks -keyalg RSA -keystore D:\apache-tomcat-9.0.38\conf\tomcatks


When enter the passwords during generation, please make sure the two passwords you entered are
the
SAME. This is the requirement of Tomcat. Here is the abstract from Tomcat installation 

Finally, you will be prompted for the key password, which is the password specifically for this Certificate
(as opposed to any other Certificates stored in the same keystore file). You MUST use the same
password here as was used for the keystore password itself. This is a restriction of the Tomcat
implementation. (Currently, the keytool prompt will tell you that pressing the ENTER key does this
for you automatically.) 

2. Connector in server.xml

Next, locate your Tomcat’s server configuration file at D:\apache-tomcat-9.0.38\conf\server.xml,
modify it by adding a
connector element to support for SSL or https connection.




Note that if you choose HTTP/1.1 instead of org.apache.coyote.http11.Http11Protocol, just like below.
Tomcat will automatically choose the following selection based on your installation.

I failed the first time because I happened to have installed the first one (APR implementation).
Please follow the official guide for more information for APR implementation setup.

  • the APR implementation, which uses the OpenSSL engine by default.

  • the JSSE implementation provided as part of the Java runtime (since 1.4)

<Connector port="8443" protocol="HTTP/1.1" SSLEnabled="true"

              maxThreads="150" scheme="https" secure="true"

              clientAuth="false" sslProtocol="TLS"

      keystoreFile="conf/tomcatks"

      keystorePass="password" />


   <!--
    <Connector port="8443" protocol="org.apache.coyote.http11.Http11AprProtocol"
               maxThreads="150" SSLEnabled="true" >
        <UpgradeProtocol className="org.apache.coyote.http2.Http2Protocol" />
        <SSLHostConfig>
            <Certificate certificateKeyFile="conf/localhost-rsa-key.pem"
                         certificateFile="conf/localhost-rsa-cert.pem"
                         certificateChainFile="conf/localhost-rsa-chain.pem"
                         type="RSA" />
        </SSLHostConfig>
    </Connector>
	-->
	
		<Connector
           protocol="org.apache.coyote.http11.Http11NioProtocol"
           port="8443" maxThreads="200"
           scheme="https" secure="true" SSLEnabled="true"
           keystoreFile="conf/tomcatks" keystorePass="password"
           clientAuth="false" sslProtocol="TLS"/>
	

    <!-- Define an AJP 1.3 Connector on port 8009 -->
    <!--
    <Connector protocol="AJP/1.3"
               address="::1"
               port="8009"
               redirectPort="8443" />
    -->


3) Restart Tomcat

D:\apache-tomcat-9.0.38\bin>startup



Reference.




留言

這個網誌中的熱門文章

全港乒乓球錦標賽 09 甲組賽事

今天換個輕鬆一點的題目,看看精彩的乒乓球 我在這裏介紹有個Channel有很清晰的乒乓球比賽片段,是全港乒乓球錦標賽甲組的賽事,其中有高澤禮在香港比賽的最新的片段 ,我相信這種場面很少有機會見到,因為,第一是業餘對專業,我在電視中都未看過,是認真比賽的那一種,不是國家隊奧運完結之後派冠軍來的表演賽,大家放軟手腳逗下逗下的那一種,可觀性高很多,第二,拍攝很有現場感,就算電視台都很少見到這樣的角度,就像親臨現場一樣。 雖然高禮澤貴為國際頂級球員,但落到這場地區賽事的時候都非常認真;雖然他技術高幾班,但認真程度從有球滴死對手時,球証看不清楚,而他正領先下,他都幫忙指証便可看出。 他是港隊中又有善又認真的專業球員,希望給年輕球員有認真對陣高水準球員的機會。 http://www.youtube.com/watch?v=nSo6Kg0vEus (這幾局可能是平均分數最接近的比賽) http://www.youtube.com/watch?v=LTJuYI906AI 還有很多其他攝錄質素很高的片段 謝嘉俊(港隊代表) vs 趙頌熙(港隊少年代表,在港有乒乓神童之稱,曾在11歲時贏得中國全國兒童賽冠軍) http://www.youtube.com/watch?v=zNEG2CzrDMI 謝嘉俊(港隊代表) vs 王德龍 09全港公開乒乓球單項錦標賽 Part 1 http://www.youtube.com/watch?v=OIeSo9V5V-0 趙頌熙(青少年港隊代表) 對 陳嘉耀 09全港公開乒乓球單項錦標賽 決勝局 Part 1 http://www.youtube.com/watch?v=jpaXjLL1bT4 陳文鋒 對 蔡鎮滔 2009全港公開乒乓球單項錦標賽 Part 2 http://www.youtube.com/watch?v=ZdcG8-I0buw&feature=channel_page 或者可以直接溜灠這個channel頻道 http://www.youtube.com/ppball

Files sharing problem between Windows 2003 server host and virtual machine

Regarding VMServer 1.08, when I copy files between a Windows 2003 host and a vm(no matter it is Windows XP or Windows 2003 Server), the following error prompted out arbitrarily, usually for copying large files. First I thought I had solved it by disabling the Jumbo frame and any kind of flow control in network card advance setting. It corrected the problem for most of the cases until I came across a situation to copy a 600MB file, the captioned error "network name is no longer available " prompted out after 10 to 20 seconds. It was not easy to find the solution as there are many cases, with different reasons, having the same symptom, thus I jot it down for a record. 1. Disable Jumbo frame, or any kind of flow control (try disabling Jumbo frame first) 2. Disable Denial of service attack in Windows 2003. Microsoft had acknowledged it has problem by itself in some cases. VMWare Server and "...network name is no longer available..." Did you ever receive following erro...