We will see how to configure Tomcat to support SSl or Https using Keystore command
1.Gegerate Keystore File
Create Key store file using keytool command for self-signed certificate.Follow the steps mentioned below to generate key store file<$Tomcat-Home>\bin>keytool -genkey -alias javatutorialscorner -keyalg RSA -keystore c:\javatutorialscornerstore
Enter keystore password:
Re-enter new password:
What is your first and last name?
[Unknown]: Java Tutorials Corner
What is the name of your organizational unit?
…
….
…
[no]: yes
Enter key password for <javatutorialscorner >
(RETURN if same as keystore password):
Re-enter new password:
<$Tomcat-Home>\bin>
data:image/s3,"s3://crabby-images/05563/05563b50968c71efe4e83af276faa66e8ef6aac6" alt="keystore keystore"
Now your keystore file ready to use.you can find your key store file at mentioned location
2.Edit connector in server.xml
you can find your server.xml at your <tomcat home>/conf folder .connector in server.xml befor edit
<Connector port="8080" protocol="HTTP/1.1"
connectionTimeout="20000"
redirectPort="8443" />
data:image/s3,"s3://crabby-images/9f58e/9f58ea193a973a305ea42caad4271d90eed8433e" alt="server xml _1 server xml _1"
Edit port 8080 to 80.If your using port 80 you don’t need to mention port in url
<Connector port="80" protocol="HTTP/1.1"
connectionTimeout="20000"
redirectPort="8443" />
data:image/s3,"s3://crabby-images/117d3/117d3aee2127b7f16d75df66e863ce87411f3c35" alt="connector_port80 connector_port80"
Add the following content just below the connector for configure your key store file with tomcat
1.keystoreFile - keystore file location
2.keyAlias - alias name given by you
3.keystorePass - password given by you
<Connector port="443" protocol="org.apache.coyote.http11.Http11Protocol" SSLEnabled="true"
maxThreads="150" scheme="https" secure="true"
keyAlias="javatutorialscorner" keystoreFile="C:\javatutorialscornerstore" keystorePass="PASSWORD"
clientAuth="false" sslProtocol="TLS" />
data:image/s3,"s3://crabby-images/973da/973dae3e5828c2e0e9564999f02144461d564c38" alt="ssl_config ssl_config"
Now your tomcat ready to support SSL/Https.Start tomcat just give https://localhost ,you can see the following warning page
data:image/s3,"s3://crabby-images/804c7/804c735bb88e58adb87591b356d825a90d596776" alt="tomcat_warning tomcat_warning"
Click I Understand the risk and add exception then it will go to tomcat home page thats it
data:image/s3,"s3://crabby-images/fb89e/fb89e314410367b84ad3180f2b028c63be1c3fb5" alt="add exception add exception"
data:image/s3,"s3://crabby-images/8fa13/8fa1394f020fd27edc3b0a5edc7b9511889b1451" alt="tomcat home page tomcat home page"
0 comments:
Post a Comment