You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu 16.04下Tomcat8配置Let's Encrypt SSL证书遇阻求助

Configure Tomcat 8 with Let's Encrypt SSL on Ubuntu 16.04

Hey there, I’ve tackled this exact setup before—let’s get your HTTPS up and running smoothly. The key here is converting Let’s Encrypt’s PEM files into a format Tomcat understands (PKCS12) and then tweaking your server.xml correctly. Here’s the step-by-step breakdown:

Step 1: Convert Let’s Encrypt PEM Files to PKCS12

Tomcat works best with PKCS12 keystores, so we’ll combine your privkey.pem (private key) and fullchain.pem (certificate + intermediate chain) into one file. Run this command in the directory where your Let’s Encrypt files are stored:

openssl pkcs12 -export -in fullchain.pem -inkey privkey.pem -out tomcat.p12 -name tomcat -CAfile chain.pem -caname root

You’ll be prompted to set an export password—remember this, you’ll need it for Tomcat’s config. I usually use changeit (Tomcat’s default keystore password) for simplicity, but feel free to use a secure custom password.

Step 2: Update Tomcat’s server.xml

Open your server.xml file (usually located at /etc/tomcat8/server.xml or /usr/share/tomcat8/conf/server.xml) and find the SSL Connector section—it’s probably commented out with <!-- ... -->. Replace that section with this configured Connector:

<Connector port="443" protocol="org.apache.coyote.http11.Http11NioProtocol"
           maxThreads="150" SSLEnabled="true" scheme="https" secure="true"
           keystoreFile="/path/to/your/tomcat.p12"
           keystoreType="PKCS12"
           keystorePass="your-password-here"
           clientAuth="false" sslProtocol="TLS"
           ciphers="TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_DHE_RSA_WITH_AES_128_GCM_SHA256,TLS_DHE_DSS_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_SHA256,TLS_ECDHE_ECDSA_WITH_AES_128_SHA256,TLS_ECDHE_RSA_WITH_AES_128_SHA,TLS_ECDHE_ECDSA_WITH_AES_128_SHA,TLS_ECDHE_RSA_WITH_AES_256_SHA384,TLS_ECDHE_ECDSA_WITH_AES_256_SHA384,TLS_ECDHE_RSA_WITH_AES_256_SHA,TLS_ECDHE_ECDSA_WITH_AES_256_SHA,TLS_DHE_RSA_WITH_AES_128_SHA256,TLS_DHE_RSA_WITH_AES_128_SHA,TLS_DHE_DSS_WITH_AES_128_SHA256,TLS_DHE_RSA_WITH_AES_256_SHA256,TLS_DHE_DSS_WITH_AES_256_SHA,TLS_DHE_RSA_WITH_AES_256_SHA"/>

Important Notes:

  • Replace /path/to/your/tomcat.p12 with the actual path where you saved the PKCS12 file (I recommend moving it to /var/lib/tomcat8/conf/ for security).
  • Replace your-password-here with the password you set in Step 1.
  • If you don’t want to use port 443 (standard HTTPS port), you can use 8443 instead—just update the port value.

Step 3: Optional - Redirect HTTP to HTTPS

To force all traffic to use HTTPS, update your HTTP Connector (usually port 8080) by adding redirectPort="443":

<Connector port="8080" protocol="HTTP/1.1"
           connectionTimeout="20000"
           redirectPort="443"/>

For an extra layer of enforcement, add this security constraint to your web.xml (located in the same conf directory):

<security-constraint>
    <web-resource-collection>
        <web-resource-name>Entire Application</web-resource-name>
        <url-pattern>/*</url-pattern>
    </web-resource-collection>
    <user-data-constraint>
        <transport-guarantee>CONFIDENTIAL</transport-guarantee>
    </user-data-constraint>
</security-constraint>

Step 4: Fix Permissions & Restart Tomcat

Tomcat needs read access to your PKCS12 file. If you moved it to /var/lib/tomcat8/conf/, run these commands:

sudo chown tomcat8:tomcat8 /var/lib/tomcat8/conf/tomcat.p12
sudo chmod 600 /var/lib/tomcat8/conf/tomcat.p12

Then restart Tomcat to apply changes:

sudo systemctl restart tomcat8
# Or if systemd isn't working for you:
# sudo service tomcat8 restart

Troubleshooting Common Issues

  • Port 443 Permission Denied: Tomcat runs as a non-root user by default, which can’t bind to ports below 1024. Fix this with authbind:
    1. Install authbind: sudo apt-get install authbind
    2. Create a port file: sudo touch /etc/authbind/byport/443
    3. Set permissions: sudo chmod 500 /etc/authbind/byport/443 && sudo chown tomcat8 /etc/authbind/byport/443
    4. Edit Tomcat’s startup script (e.g., /etc/init.d/tomcat8) and change the EXEC line to: AUTHBIND=/usr/bin/authbind $EXEC
  • Keystore Errors: Double-check the keystoreFile path and keystorePass—typos here are the most common culprits.
  • SSL Handshake Failures: Ensure you used fullchain.pem (not just cert.pem) when creating the PKCS12 file—missing intermediate certificates cause handshake issues.

Now test your setup by visiting https://your-domain.com in a browser, or run curl -v https://your-domain.com to verify the SSL connection.

内容的提问来源于stack exchange,提问作者padawan_IT

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 12:34:05