You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为AWS Route 53托管区域名配置GoDaddy SSL证书

How to Configure GoDaddy SSL Certificate for Your AWS Route 53 & Tomcat EC2 Setup

Got it, let's walk through getting your GoDaddy SSL certificate set up with your existing AWS setup. I'll break this down into actionable steps tailored to your scenario:

1. Export Your SSL Certificate from GoDaddy

First, you need to grab the certificate files from your GoDaddy account:

  • Log into your GoDaddy account, navigate to the SSL Certificates section, and locate the certificate for myapp.myapp.com.
  • Download the certificate package. You should get at least three files: the main certificate (usually .crt or .pem), your private key (.key), and the intermediate/chain certificate bundle (often named something like gd_bundle.crt).
  • If GoDaddy provided a PFX file instead, use OpenSSL to convert it to PEM format with this command:
    openssl pkcs12 -in your_certificate.pfx -out converted_cert.pem -nodes
    
    You can then extract the private key and certificate sections from the converted PEM file.

2. Prepare the Certificate for Tomcat

Tomcat works best with a keystore file. We'll use PKCS12 (a modern, widely supported format) instead of the older JKS:

  • Use Java's built-in keytool command to import your private key into a PKCS12 keystore:
    keytool -importkeystore -srckeystore your_private_key.key -srcstoretype PKCS8 -destkeystore tomcat.p12 -deststoretype PKCS12
    
  • Next, import the GoDaddy intermediate certificate bundle to ensure full chain trust:
    keytool -import -alias root -trustcacerts -file gd_bundle.crt -keystore tomcat.p12
    
  • Important: Make a note of the keystore password you set here—you'll need it for Tomcat's configuration.

3. Update Tomcat's HTTPS Configuration

Now, let's configure Tomcat to use the SSL certificate:

  • Navigate to your Tomcat installation directory and open conf/server.xml in a text editor.
  • Find (or add) the HTTPS Connector block. Replace any existing placeholder with this configuration:
    <Connector port="443" protocol="org.apache.coyote.http11.Http11NioProtocol"
               maxThreads="150" SSLEnabled="true">
        <SSLHostConfig>
            <Certificate certificateKeystoreFile="conf/tomcat.p12"
                         type="RSA"
                         certificateKeystorePassword="YOUR_KEYSTORE_PASSWORD"
                         certificateKeystoreType="PKCS12"/>
        </SSLHostConfig>
    </Connector>
    
  • Don't forget to replace YOUR_KEYSTORE_PASSWORD with the password you set earlier.
  • Critical Check: Head over to your EC2 instance's security group in the AWS Console and add an inbound rule allowing HTTPS (port 443) traffic from all sources (or restricted to your needs).

4. Verify DNS and Restart Tomcat

  • Confirm your Route 53 record myapp.myapp.com is still pointing correctly to your EC2 instance's public IP/elastic IP. You can use nslookup myapp.myapp.com or dig myapp.myapp.com to check—wait for DNS propagation if needed (this can take 5-30 minutes depending on your TTL setting).
  • Restart Tomcat to apply the changes:
    • If using systemd: sudo systemctl restart tomcat
    • If using the default scripts: ./bin/shutdown.sh && ./bin/startup.sh

5. Test the HTTPS Connection

Finally, verify everything works:

  • Open your browser and visit https://myapp.myapp.com. You should see a secure lock icon in the address bar indicating the certificate is valid.
  • If you run into issues, check Tomcat's logs/catalina.out file for errors—common issues include incorrect keystore paths, wrong passwords, or missing intermediate certificates.

内容的提问来源于stack exchange,提问作者Tim Biegeleisen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:50:04