在Tomcat中导入通配符SSL证书时遇NET::ERR_CERT_AUTHORITY_INVALID错误
Let's break down why you're hitting this error and how to resolve it—this is a super common pitfall when deploying SSL certificates in Tomcat, almost always tied to incomplete certificate chains or misconfigured keystores.
First, the NET::ERR_CERT_AUTHORITY_INVALID error means your browser can't verify the trust chain of your certificate. Even though you signed your CSR with SSL2Buy's CA, if the full chain (root CA → intermediate CA → your wildcard cert) isn't properly packaged into Tomcat's keystore, browsers will reject the certificate as untrusted.
Here's step-by-step troubleshooting and fixes:
1. Verify Your Full Certificate Chain is Complete
Your PKCS#7 certificate from SSL2Buy should include your wildcard cert, intermediate CA certs, and the root CA cert—but sometimes it's missing critical pieces. Let's convert it to PEM format to inspect:
# Convert PKCS#7 to PEM to view all certificates in the chain openssl pkcs7 -in your-cert.p7b -print_certs -out full-chain.pem
Open full-chain.pem and look for multiple -----BEGIN CERTIFICATE-----/-----END CERTIFICATE----- blocks. You should see:
- Your wildcard certificate (CN=*.mydomain.com)
- One or more intermediate CA certificates (from SSL2Buy's certificate hierarchy)
- The root CA certificate (pre-trusted by major browsers)
If any of these are missing, go back to SSL2Buy's portal and download the complete certificate chain bundle for your order.
2. Create a Valid Keystore for Tomcat
Tomcat works best with PKCS12 keystores (the modern replacement for JKS). You need to combine your decrypted private key, wildcard cert, and full chain into a single keystore:
# First, decrypt your private key (if you set a passphrase when generating it) openssl rsa -in appServer.key -out appServer-decrypted.key # Combine private key, wildcard cert, and full chain into a PKCS12 keystore openssl pkcs12 -export -in your-wildcard-cert.crt -inkey appServer-decrypted.key -certfile full-chain.pem -out keystore.p12 -name tomcat
When prompted, set a keystore password—you'll need this for Tomcat's configuration later. The -certfile flag is critical here: it ensures all intermediate and root certificates are included in the keystore.
If you prefer using the older JKS format, convert the PKCS12 file:
keytool -importkeystore -srckeystore keystore.p12 -srcstoretype PKCS12 -destkeystore keystore.jks -deststoretype JKS
3. Update Tomcat's server.xml Configuration
Make sure your SSL Connector in conf/server.xml points to the correct keystore, uses the right type, and includes all necessary settings:
<Connector port="443" protocol="org.apache.coyote.http11.Http11NioProtocol" maxThreads="150" SSLEnabled="true"> <SSLHostConfig> <Certificate certificateKeystoreFile="conf/keystore.p12" type="RSA" certificateKeystorePassword="your-keystore-password" certificateKeystoreType="PKCS12"/> </SSLHostConfig> </Connector>
- Replace
your-keystore-passwordwith the password you set when creating the keystore. - If using JKS, change
certificateKeystoreTypetoJKS. - Use an absolute path for
certificateKeystoreFileif Tomcat can't locate the file (e.g.,/opt/tomcat/conf/keystore.p12).
4. Validate the Certificate Chain
Test if Tomcat is serving the full chain correctly with this command:
openssl s_client -connect your-domain.com:443 -showcerts
Look for Verify return code: 0 (ok) at the end of the output. If you see anything else (like 21 (unable to verify the first certificate)), your chain is still incomplete—double-check the full-chain.pem file.
Quick Checks to Avoid Common Mistakes
- Private Key & CSR Match: Ensure the private key you used to generate the CSR is the same one you're using now. Verify with:
The two MD5 hashes must be identical—if not, you're using the wrong private key.openssl rsa -noout -modulus -in appServer.key | openssl md5 openssl req -noout -modulus -in appServer.csr | openssl md5 - Wildcard CN Correctness: Confirm your certificate's CN is exactly
*.mydomain.com(no typos, extra dots, etc.). - Root CA Trust: Some root CAs aren't pre-trusted by older browsers—if needed, manually import the root CA into the browser (but this is a last resort; prefer fixing the chain in Tomcat).
内容的提问来源于stack exchange,提问作者sweta

