Self-Help Article (External)
Intended Audience: IT Staff
Purpose
This article explains how to configure Apache Tomcat to use Certbot-managed certificates and automatically deploy renewed certificates obtained through the CertiNext ACME service.
Requirements
Step-by-Step Procedures
Step 1: Identify the Certificate
- Identify the certificate name.
Command:
sudo certbot certificates
- Review the results and identify the certificate name associated with the website.
Step 2: Create a PKCS#12 Keystore for Tomcat
- Create a directory for the Tomcat certificate files if it does not already exist.
Command:
sudo mkdir -p /opt/tomcat/certs
- Create a PKCS#12 keystore using the Certbot-managed certificate.
Command:
sudo openssl pkcs12 -export \
-in /etc/letsencrypt/live/<certificate-name>/fullchain.pem \
-inkey /etc/letsencrypt/live/<certificate-name>/privkey.pem \
-out /opt/tomcat/certs/tomcat.p12 \
-name tomcat
- Enter and confirm a keystore password when prompted.
Notes:
- Replace <certificate-name> with the certificate name identified in Step 1.
- Tomcat typically uses a PKCS#12 keystore rather than the PEM files managed directly by Certbot.
- The deployment hook configured later in this procedure will automatically recreate this keystore after certificate renewal.
Step 3: Configure Apache Tomcat to Use the Keystore
- Open the Tomcat configuration file.
Command:
sudo vi /opt/tomcat/conf/server.xml
- Locate the HTTPS Connector configuration.
- Configure the Tomcat HTTPS Connector to use the PKCS#12 keystore.
Command:
<Connector
port="8443"
protocol="org.apache.coyote.http11.Http11NioProtocol"
SSLEnabled="true"
scheme="https"
secure="true">
<SSLHostConfig>
<Certificate
certificateKeystoreFile="/opt/tomcat/certs/tomcat.p12"
certificateKeystorePassword="change-password"
certificateKeystoreType="PKCS12" />
</SSLHostConfig>
</Connector>
- Save the configuration file.
Notes:
- Use the keystore password specified in Step 2.
- Configuration details may vary depending on the Tomcat version deployed.
Step 4: Restart Apache Tomcat
- Restart the Tomcat service.
Command:
sudo systemctl restart tomcat
- Verify the Tomcat service is running.
Command:
systemctl status tomcat
- Confirm the service status is active (running).
Notes:
- This restart applies the certificate configuration changes made in Step 3.
- Apache Tomcat must be restarted to load the updated keystore and begin serving the certificate. Depending on the application and traffic levels, a restart may briefly interrupt active connections.
Step 5: Configure Automatic Certificate Deployment Following Renewal
- Create the Certbot deploy hook directory if it does not already exist.
Command:
sudo mkdir -p /etc/letsencrypt/renewal-hooks/deploy
- Create a directory to store the Tomcat PKCS#12 keystore if it does not already exist.
Command:
sudo mkdir -p /opt/tomcat/certs
- Set ownership on the Tomcat certificate directory so the Tomcat service can access the keystore.
Command:
sudo chown tomcat:tomcat /opt/tomcat/certs
- Create a deployment hook script.
Command:
sudo vi /etc/letsencrypt/renewal-hooks/deploy/reload-tomcat.sh
- Add the following content:
#!/bin/bash
openssl pkcs12 -export \
-in /etc/letsencrypt/live/<certificate-name>/fullchain.pem \
-inkey /etc/letsencrypt/live/<certificate-name>/privkey.pem \
-out /opt/tomcat/certs/tomcat.p12 \
-name tomcat \
-passout pass:YOUR_KEYSTORE_PASSWORD
systemctl restart tomcat
- Replace:
<certificate-name> with the certificate name identified in Step 1.
YOUR_KEYSTORE_PASSWORD with the password used for the Tomcat keystore.
- Save the file.
- Make the script executable.
Command:
sudo chmod 755 /etc/letsencrypt/renewal-hooks/deploy/reload-tomcat.sh
Notes:
- Initial Configuration
-- The manual restart performed in Step 4 applies the initial certificate configuration.
- Deployment Hook
-- Certbot automatically runs deployment hook scripts located in /etc/letsencrypt/renewal-hooks/deploy/ after a successful certificate renewal.
-- The deployment hook automatically recreates the Tomcat keystore using the renewed certificate.
- -The deployment hook automatically restarts Tomcat so the renewed certificate is loaded.
- Certificate Renewals
-- Future certificate renewals will automatically deploy the renewed certificate without requiring manual intervention.
- Routine Certbot renewal checks that do not result in a certificate renewal do not trigger a Tomcat restart.
Important Notes:
- Because Tomcat uses a service restart, active connections will be briefly interrupted while Tomcat restarts.
- The timing of the Tomcat restart is determined by the certbot-renew.timer schedule.
- Tomcat is restarted automatically only after a successful certificate renewal.
Step 6: Test Automatic Certificate Deployment
- Run a simulated certificate renewal.
Command:
sudo certbot renew --dry-run
- Review the results.
- Confirm the following message is displayed:
Congratulations, all simulated renewals succeeded.
- Verify that no Tomcat errors are reported during the renewal process.
- Resolve any reported errors before relying on automatic certificate deployment in production.
Notes:
- The --dry-run option performs a simulated certificate renewal.
- No new certificate is permanently installed during the test.
- Successful completion confirms that automatic certificate renewal, keystore recreation, and Tomcat restart are expected to function correctly during an actual renewal.
Automatic Certificate Renewal and Deployment Workflow
certbot-renew.timer runs
↓
Certbot checks certificate expiration
↓
Certificate eligible for renewal?
↓
No → Renewal check completes
↓
Yes
↓
Certificate is renewed
↓
Certbot updates certificate files in
/etc/letsencrypt/live/<certificate-name>/
↓
Certbot executes deploy hook
(reload-tomcat.sh)
↓
PKCS#12 keystore is recreated
↓
Tomcat restarts
↓
Tomcat loads updated certificate
↓
Website serves renewed certificate
Notes:
- The timing of certificate renewal and any associated Tomcat restart is controlled by the certbot-renew.timer schedule.
- Routine renewal checks that do not result in a certificate renewal do not trigger a Tomcat restart.