单服务器多Tomcat8实例共用单证书的SSL配置问题咨询
1. Can a single certificate be used for both Tomcat instances?
Absolutely! Since both instances run on the same server (devserver) and are accessed via that hostname, a single SSL certificate issued to devserver will work for both. SSL certificates are tied to the domain/hostname, not the port—so as long as your access URLs use the same hostname (even with different ports), one certificate is all you need.
2. Single certificate vs. multiple, and cacerts installation?
You only need one certificate for both instances. Here’s the breakdown:
- Store the certificate in a Java keystore file (typically created with the
keytoolcommand). Both Tomcats can either share this same keystore (just ensure both Tomcat services have read access to it) or you can make a copy for each instance—sharing is more efficient. - Installing the certificate into Java’s
cacertstruststore is not required for serving HTTPS. That’s only necessary if your applications need the JVM to trust the certificate (e.g., for internal HTTPS calls to other services). For Tomcat to serve HTTPS, it just needs access to the keystore containing the certificate and private key.
3. Can both Tomcats use the same jvm.dll?
Definitely. Since both are 64-bit Tomcat 8 instances running on Java 8 64-bit, they can safely use the same JRE/JDK installation’s jvm.dll. To set this up:
- Ensure both Tomcats point to the same
JAVA_HOMEorJRE_HOME(you can define this in each Tomcat’ssetenv.batfile if needed). - Multiple Java processes can use the same
jvm.dllsimultaneously on Windows—no conflicts here.
4. server.xml modifications for HTTPS in each Tomcat
Each Tomcat needs its own SSL Connector configuration in conf/server.xml. Here’s what to do for each instance:
Step 1: Add/Uncomment the SSL Connector
Find the default SSL Connector section (usually commented out) and modify it. Use unique ports for each Tomcat (e.g., 8443 for the first, 8444 for the second). Example config:
<Connector port="8443" protocol="org.apache.coyote.http11.Http11NioProtocol" maxThreads="150" SSLEnabled="true"> <SSLHostConfig> <Certificate certificateKeystoreFile="C:\path\to\your\keystore.jks" type="RSA" certificateKeystorePassword="your-keystore-pass" certificateKeyPassword="your-private-key-pass"/> </SSLHostConfig> </Connector>
- Replace
portwith a unique value for each Tomcat (8443/8444 are common choices). - Update
certificateKeystoreFileto the full path of your keystore (shared or copied). - Fill in your actual keystore and private key passwords.
Step 2: Optional - Redirect HTTP to HTTPS
If you want to send HTTP traffic (8080/8081) to HTTPS, add a Valve to the Engine section of server.xml:
<Engine name="Catalina" defaultHost="localhost"> <!-- Existing config here --> <Valve className="org.apache.catalina.valves.rewrite.RewriteValve" /> </Engine>
Then create a conf/rewrite.config file with:
RewriteCond %{HTTPS} !=on RewriteRule ^/(.*) https://%{SERVER_NAME}:8443/$1 [R,L]
Adjust the port to match the Tomcat’s HTTPS port.
Step 3: Restart Tomcat
After editing server.xml, restart each Tomcat instance. You can now access them via https://devserver:8443/ and https://devserver:8444/.
内容的提问来源于stack exchange,提问作者Shekar

