[callcenter] Let’s Encryptで取得したSSL証明書を Tomcat で使用する手順。CentOS (2019/01/04) [2020/05/05]
Tomcat に入れる場合に keystore (JKS) 形式にする
# openssl pkcs12 -export -in cert.pem -inkey privkey.pem -certfile chain.pem -out pkcs12.pfx -passout pass:changeit
# keytool -importkeystore -srckeystore pkcs12.pfx -srcstoretype PKCS12 -srcstorepass changeit -destkeystore keystore.jks -deststoretype JKS -deststorepass changeit
# mv keystore.jks /tomact/conf/keystore
# vi /tomcat/conf/server.xml
<Connector port="8443" protocol="org.apache.coyote.http11.Http11Protocol"
maxThreads="1000" SSLEnabled="true" scheme="https" secure="true"
clientAuth="false" sslProtocol="TLS" keystoreFile="conf/keystore/keystore.jks" keystorePass="changeit" />