You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Tomcat中导入通配符SSL证书时遇NET::ERR_CERT_AUTHORITY_INVALID错误

Fixing NET::ERR_CERT_AUTHORITY_INVALID for Wildcard SSL Cert in Tomcat

Let's break down why you're hitting this error and how to resolve it—this is a super common pitfall when deploying SSL certificates in Tomcat, almost always tied to incomplete certificate chains or misconfigured keystores.

First, the NET::ERR_CERT_AUTHORITY_INVALID error means your browser can't verify the trust chain of your certificate. Even though you signed your CSR with SSL2Buy's CA, if the full chain (root CA → intermediate CA → your wildcard cert) isn't properly packaged into Tomcat's keystore, browsers will reject the certificate as untrusted.

Here's step-by-step troubleshooting and fixes:

1. Verify Your Full Certificate Chain is Complete

Your PKCS#7 certificate from SSL2Buy should include your wildcard cert, intermediate CA certs, and the root CA cert—but sometimes it's missing critical pieces. Let's convert it to PEM format to inspect:

# Convert PKCS#7 to PEM to view all certificates in the chain
openssl pkcs7 -in your-cert.p7b -print_certs -out full-chain.pem

Open full-chain.pem and look for multiple -----BEGIN CERTIFICATE-----/-----END CERTIFICATE----- blocks. You should see:

  • Your wildcard certificate (CN=*.mydomain.com)
  • One or more intermediate CA certificates (from SSL2Buy's certificate hierarchy)
  • The root CA certificate (pre-trusted by major browsers)

If any of these are missing, go back to SSL2Buy's portal and download the complete certificate chain bundle for your order.

2. Create a Valid Keystore for Tomcat

Tomcat works best with PKCS12 keystores (the modern replacement for JKS). You need to combine your decrypted private key, wildcard cert, and full chain into a single keystore:

# First, decrypt your private key (if you set a passphrase when generating it)
openssl rsa -in appServer.key -out appServer-decrypted.key

# Combine private key, wildcard cert, and full chain into a PKCS12 keystore
openssl pkcs12 -export -in your-wildcard-cert.crt -inkey appServer-decrypted.key -certfile full-chain.pem -out keystore.p12 -name tomcat

When prompted, set a keystore password—you'll need this for Tomcat's configuration later. The -certfile flag is critical here: it ensures all intermediate and root certificates are included in the keystore.

If you prefer using the older JKS format, convert the PKCS12 file:

keytool -importkeystore -srckeystore keystore.p12 -srcstoretype PKCS12 -destkeystore keystore.jks -deststoretype JKS

3. Update Tomcat's server.xml Configuration

Make sure your SSL Connector in conf/server.xml points to the correct keystore, uses the right type, and includes all necessary settings:

<Connector port="443" protocol="org.apache.coyote.http11.Http11NioProtocol"
           maxThreads="150" SSLEnabled="true">
    <SSLHostConfig>
        <Certificate certificateKeystoreFile="conf/keystore.p12"
                     type="RSA"
                     certificateKeystorePassword="your-keystore-password"
                     certificateKeystoreType="PKCS12"/>
    </SSLHostConfig>
</Connector>
  • Replace your-keystore-password with the password you set when creating the keystore.
  • If using JKS, change certificateKeystoreType to JKS.
  • Use an absolute path for certificateKeystoreFile if Tomcat can't locate the file (e.g., /opt/tomcat/conf/keystore.p12).

4. Validate the Certificate Chain

Test if Tomcat is serving the full chain correctly with this command:

openssl s_client -connect your-domain.com:443 -showcerts

Look for Verify return code: 0 (ok) at the end of the output. If you see anything else (like 21 (unable to verify the first certificate)), your chain is still incomplete—double-check the full-chain.pem file.

Quick Checks to Avoid Common Mistakes

  • Private Key & CSR Match: Ensure the private key you used to generate the CSR is the same one you're using now. Verify with:
    openssl rsa -noout -modulus -in appServer.key | openssl md5
    openssl req -noout -modulus -in appServer.csr | openssl md5
    
    The two MD5 hashes must be identical—if not, you're using the wrong private key.
  • Wildcard CN Correctness: Confirm your certificate's CN is exactly *.mydomain.com (no typos, extra dots, etc.).
  • Root CA Trust: Some root CAs aren't pre-trusted by older browsers—if needed, manually import the root CA into the browser (but this is a last resort; prefer fixing the chain in Tomcat).

内容的提问来源于stack exchange,提问作者sweta

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 12:20:48