Ubuntu 16.04下Tomcat8配置Let's Encrypt SSL证书遇阻求助
Hey there, I’ve tackled this exact setup before—let’s get your HTTPS up and running smoothly. The key here is converting Let’s Encrypt’s PEM files into a format Tomcat understands (PKCS12) and then tweaking your server.xml correctly. Here’s the step-by-step breakdown:
Step 1: Convert Let’s Encrypt PEM Files to PKCS12
Tomcat works best with PKCS12 keystores, so we’ll combine your privkey.pem (private key) and fullchain.pem (certificate + intermediate chain) into one file. Run this command in the directory where your Let’s Encrypt files are stored:
openssl pkcs12 -export -in fullchain.pem -inkey privkey.pem -out tomcat.p12 -name tomcat -CAfile chain.pem -caname root
You’ll be prompted to set an export password—remember this, you’ll need it for Tomcat’s config. I usually use changeit (Tomcat’s default keystore password) for simplicity, but feel free to use a secure custom password.
Step 2: Update Tomcat’s server.xml
Open your server.xml file (usually located at /etc/tomcat8/server.xml or /usr/share/tomcat8/conf/server.xml) and find the SSL Connector section—it’s probably commented out with <!-- ... -->. Replace that section with this configured Connector:
<Connector port="443" protocol="org.apache.coyote.http11.Http11NioProtocol" maxThreads="150" SSLEnabled="true" scheme="https" secure="true" keystoreFile="/path/to/your/tomcat.p12" keystoreType="PKCS12" keystorePass="your-password-here" clientAuth="false" sslProtocol="TLS" ciphers="TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_DHE_RSA_WITH_AES_128_GCM_SHA256,TLS_DHE_DSS_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_SHA256,TLS_ECDHE_ECDSA_WITH_AES_128_SHA256,TLS_ECDHE_RSA_WITH_AES_128_SHA,TLS_ECDHE_ECDSA_WITH_AES_128_SHA,TLS_ECDHE_RSA_WITH_AES_256_SHA384,TLS_ECDHE_ECDSA_WITH_AES_256_SHA384,TLS_ECDHE_RSA_WITH_AES_256_SHA,TLS_ECDHE_ECDSA_WITH_AES_256_SHA,TLS_DHE_RSA_WITH_AES_128_SHA256,TLS_DHE_RSA_WITH_AES_128_SHA,TLS_DHE_DSS_WITH_AES_128_SHA256,TLS_DHE_RSA_WITH_AES_256_SHA256,TLS_DHE_DSS_WITH_AES_256_SHA,TLS_DHE_RSA_WITH_AES_256_SHA"/>
Important Notes:
- Replace
/path/to/your/tomcat.p12with the actual path where you saved the PKCS12 file (I recommend moving it to/var/lib/tomcat8/conf/for security). - Replace
your-password-herewith the password you set in Step 1. - If you don’t want to use port 443 (standard HTTPS port), you can use 8443 instead—just update the
portvalue.
Step 3: Optional - Redirect HTTP to HTTPS
To force all traffic to use HTTPS, update your HTTP Connector (usually port 8080) by adding redirectPort="443":
<Connector port="8080" protocol="HTTP/1.1" connectionTimeout="20000" redirectPort="443"/>
For an extra layer of enforcement, add this security constraint to your web.xml (located in the same conf directory):
<security-constraint> <web-resource-collection> <web-resource-name>Entire Application</web-resource-name> <url-pattern>/*</url-pattern> </web-resource-collection> <user-data-constraint> <transport-guarantee>CONFIDENTIAL</transport-guarantee> </user-data-constraint> </security-constraint>
Step 4: Fix Permissions & Restart Tomcat
Tomcat needs read access to your PKCS12 file. If you moved it to /var/lib/tomcat8/conf/, run these commands:
sudo chown tomcat8:tomcat8 /var/lib/tomcat8/conf/tomcat.p12 sudo chmod 600 /var/lib/tomcat8/conf/tomcat.p12
Then restart Tomcat to apply changes:
sudo systemctl restart tomcat8 # Or if systemd isn't working for you: # sudo service tomcat8 restart
Troubleshooting Common Issues
- Port 443 Permission Denied: Tomcat runs as a non-root user by default, which can’t bind to ports below 1024. Fix this with
authbind:- Install authbind:
sudo apt-get install authbind - Create a port file:
sudo touch /etc/authbind/byport/443 - Set permissions:
sudo chmod 500 /etc/authbind/byport/443 && sudo chown tomcat8 /etc/authbind/byport/443 - Edit Tomcat’s startup script (e.g.,
/etc/init.d/tomcat8) and change theEXECline to:AUTHBIND=/usr/bin/authbind $EXEC
- Install authbind:
- Keystore Errors: Double-check the
keystoreFilepath andkeystorePass—typos here are the most common culprits. - SSL Handshake Failures: Ensure you used
fullchain.pem(not justcert.pem) when creating the PKCS12 file—missing intermediate certificates cause handshake issues.
Now test your setup by visiting https://your-domain.com in a browser, or run curl -v https://your-domain.com to verify the SSL connection.
内容的提问来源于stack exchange,提问作者padawan_IT

