Certificates - CertiNext - How to Configure Automatic Certificate Deployment for Apache Tomcat Using Certbot

Self-Help Article (External)

Purpose

This article explains how to configure Apache Tomcat to use Certbot-managed certificates and automatically deploy renewed certificates obtained through the CertiNext ACME service.

Requirements

Step-by-Step Procedures

Step 1: Identify the Certificate
  1. Identify the certificate name.
    Command:

    sudo certbot certificates
  2. Review the results and identify the certificate name associated with the website.
Step 2: Create a PKCS#12 Keystore for Tomcat
  1. Create a directory for the Tomcat certificate files if it does not already exist.
    Command:

    sudo mkdir -p /opt/tomcat/certs
  2. Create a PKCS#12 keystore using the Certbot-managed certificate.
    Command:

    sudo openssl pkcs12 -export \
    -in /etc/letsencrypt/live/<certificate-name>/fullchain.pem \
    -inkey /etc/letsencrypt/live/<certificate-name>/privkey.pem \
    -out /opt/tomcat/certs/tomcat.p12 \
    -name tomcat
  3. Enter and confirm a keystore password when prompted.

    Notes:
    - Replace <certificate-name> with the certificate name identified in Step 1.
    - Tomcat typically uses a PKCS#12 keystore rather than the PEM files managed directly by Certbot.
    - The deployment hook configured later in this procedure will automatically recreate this keystore after certificate renewal.
Step 3: Configure Apache Tomcat to Use the Keystore
  1. Open the Tomcat configuration file.
    Command:

    sudo vi /opt/tomcat/conf/server.xml
  2. Locate the HTTPS Connector configuration.
  3. Configure the Tomcat HTTPS Connector to use the PKCS#12 keystore.
    Command:

    <Connector
        port="8443"
        protocol="org.apache.coyote.http11.Http11NioProtocol"
        SSLEnabled="true"
        scheme="https"
        secure="true">

        <SSLHostConfig>
            <Certificate
                    certificateKeystoreFile="/opt/tomcat/certs/tomcat.p12"
                    certificateKeystorePassword="change-password"
                    certificateKeystoreType="PKCS12" />
        </SSLHostConfig>
    </Connector>
  4. Save the configuration file.

    Notes:
    - Use the keystore password specified in Step 2.

    - Configuration details may vary depending on the Tomcat version deployed.
Step 4: Restart Apache Tomcat
  1. Restart the Tomcat service.
    Command:

    sudo systemctl restart tomcat
  2. Verify the Tomcat service is running.
    Command:

    systemctl status tomcat
  3. Confirm the service status is active (running).

    Notes:
    - This restart applies the certificate configuration changes made in Step 3.

    - Apache Tomcat must be restarted to load the updated keystore and begin serving the certificate. Depending on the application and traffic levels, a restart may briefly interrupt active connections.
Step 5: Configure Automatic Certificate Deployment Following Renewal
  1. Create the Certbot deploy hook directory if it does not already exist.
    Command:

    sudo mkdir -p /etc/letsencrypt/renewal-hooks/deploy
  2. Create a directory to store the Tomcat PKCS#12 keystore if it does not already exist.
    Command:

    sudo mkdir -p /opt/tomcat/certs
  3. Set ownership on the Tomcat certificate directory so the Tomcat service can access the keystore.
    Command:

    sudo chown tomcat:tomcat /opt/tomcat/certs
  4. Create a deployment hook script.
    Command:

    sudo vi /etc/letsencrypt/renewal-hooks/deploy/reload-tomcat.sh
  5. Add the following content:
    #!/bin/bash

    openssl pkcs12 -export \
    -in /etc/letsencrypt/live/<certificate-name>/fullchain.pem \
    -inkey /etc/letsencrypt/live/<certificate-name>/privkey.pem \
    -out /opt/tomcat/certs/tomcat.p12 \
    -name tomcat \
    -passout pass:YOUR_KEYSTORE_PASSWORD

    systemctl restart tomcat
  6. Replace:
    <certificate-name> with the certificate name identified in Step 1.
    YOUR_KEYSTORE_PASSWORD with the password used for the Tomcat keystore.
  7. Save the file.
  8. Make the script executable.
    Command:

    sudo chmod 755 /etc/letsencrypt/renewal-hooks/deploy/reload-tomcat.sh

    Notes:
    - Initial Configuration
    -- The manual restart performed in Step 4 applies the initial certificate configuration.
    - Deployment Hook
    -- Certbot automatically runs deployment hook scripts located in /etc/letsencrypt/renewal-hooks/deploy/ after a successful certificate renewal.
    -- The deployment hook automatically recreates the Tomcat keystore using the renewed certificate.
    - -The deployment hook automatically restarts Tomcat so the renewed certificate is loaded.
    - Certificate Renewals
    -- Future certificate renewals will automatically deploy the renewed certificate without requiring manual intervention.
    -  Routine Certbot renewal checks that do not result in a certificate renewal do not trigger a Tomcat restart.

    Important Notes:
    - Because Tomcat uses a service restart, active connections will be briefly interrupted while Tomcat restarts.
    - The timing of the Tomcat restart is determined by the certbot-renew.timer schedule.
    - Tomcat is restarted automatically only after a successful certificate renewal.
Step 6: Test Automatic Certificate Deployment
  1. Run a simulated certificate renewal.
    Command:

    sudo certbot renew --dry-run
  2. Review the results.
  3. Confirm the following message is displayed:
    Congratulations, all simulated renewals succeeded.
  4. Verify that no Tomcat errors are reported during the renewal process.
  5. Resolve any reported errors before relying on automatic certificate deployment in production.

    Notes:
    - The --dry-run option performs a simulated certificate renewal.

    - No new certificate is permanently installed during the test.
    - Successful completion confirms that automatic certificate renewal, keystore recreation, and Tomcat restart are expected to function correctly during an actual renewal.
Automatic Certificate Renewal and Deployment Workflow

certbot-renew.timer runs
↓
Certbot checks certificate expiration
↓
Certificate eligible for renewal?
↓
No → Renewal check completes
↓
Yes
↓
Certificate is renewed
↓
Certbot updates certificate files in
/etc/letsencrypt/live/<certificate-name>/
↓
Certbot executes deploy hook
(reload-tomcat.sh)
↓
PKCS#12 keystore is recreated
↓
Tomcat restarts
↓
Tomcat loads updated certificate
↓
Website serves renewed certificate

 

Notes:
- The timing of certificate renewal and any associated Tomcat restart is controlled by the certbot-renew.timer schedule.
- Routine renewal checks that do not result in a certificate renewal do not trigger a Tomcat restart.