You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Tomcat 8更换域名与SSL证书后出现有效证书SSLHandshakeException

Fixing SSLHandshakeException with Let's Encrypt Certificates When Generating PDFs

Hey there! Let's walk through the most common fixes for this issue, since you've switched domains to .com and moved to Let's Encrypt SSL while using Apache as a reverse proxy for Tomcat 8.

1. Update Java's Trust Store to Include Let's Encrypt Root Certificates

The most likely culprit here is that Tomcat's underlying JDK doesn't trust Let's Encrypt's root certificates (especially if you're using an older JDK version that predates Let's Encrypt's widespread adoption). Here's how to fix it:

  • Grab the Let's Encrypt root certificate: Run this command on your server to download the ISRG Root X1 certificate (the current primary root for Let's Encrypt):
    openssl s_client -showcerts -connect my.website.com:443 < /dev/null | sed -n '/-----BEGIN CERTIFICATE-----/,/-----END CERTIFICATE-----/p' > letsencrypt-root.crt
    
  • Import the certificate into Java's trust store: Use the keytool utility (included with your JDK) to add the certificate to the default cacerts store. Replace $JAVA_HOME with your actual JDK path (e.g., /usr/lib/jvm/java-8-openjdk-amd64):
    keytool -importcert -alias isrgrootx1 -file letsencrypt-root.crt -keystore $JAVA_HOME/jre/lib/security/cacerts
    
    When prompted, enter the default trust store password: changeit (you can change this later if needed, but the default works for setup).
  • Restart Tomcat: This ensures the updated trust store is loaded by the JVM.

2. Verify Your PDF Generation Code's Image Request Logic

Double-check that your PDF generation code is correctly handling the new domain and SSL setup:

  • Use the new .com domain for image URLs: Make sure all image requests in your code point to https://my.website.com (not the old .ie domain or plain HTTP). Hardcoded old URLs will cause SSL mismatches or untrusted connections.
  • Ensure your HTTP client uses the system trust store: If your code uses a custom HTTP client (like Apache HttpClient or OkHttp), avoid hardcoding SSL contexts that skip certificate validation or use a custom trust store. Instead, let the client use the default system trust store—this way it will pick up the Let's Encrypt certificate you just added.

    Example for Apache HttpClient: Remove any custom SSLContext configurations and use HttpClientBuilder.create().build() to get a client that uses system defaults.

  • Remove any certificate bypass code: If you had temporary code to skip SSL validation during testing, delete it now—your valid Let's Encrypt certificate should be trusted once the root is in the trust store.

3. Check Apache Reverse Proxy & SSL Configuration (If Needed)

While less likely, ensure your Apache setup isn't causing unexpected issues:

  • Confirm Apache is serving the full Let's Encrypt certificate chain (most Let's Encrypt clients like Certbot handle this automatically, but you can verify by checking your Apache SSL config for SSLCertificateChainFile or ensuring the SSLCertificateFile includes the full chain).
  • Make sure Apache is forwarding the correct Host header to Tomcat, so any internal requests from Tomcat to Apache use the correct domain. You can add this to your Apache proxy config:
    ProxyPreserveHost On
    

After trying these steps, test your PDF generation again—this should resolve the SSLHandshakeException since the JVM will now trust your Let's Encrypt certificate.

内容的提问来源于stack exchange,提问作者RTF

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:37:53