Searching...
2013年5月22日 星期三

Tomcat設定https

使用keytool產生RSA
# cd /usr/java/jdk1.7.0_21/bin/
# ./keytool -genkey -alias tomcat -keyalg RSA
Enter keystore password:
Re-enter new password:
What is your first and last name?
[Unknown]: udn
What is the name of your organizational unit?
[Unknown]: udn
What is the name of your organization?
[Unknown]: udn
What is the name of your City or Locality?
[Unknown]: taipei
What is the name of your State or Province?
[Unknown]: taiwan
What is the two-letter country code for this unit?
[Unknown]: TW
Is CN=udn, OU=udn, O=udn, L=taipei, ST=taiwan, C=TW correct?
[no]: y

Enter key password for
(RETURN if same as keystore password):


然後在編輯server.xml
# vim /usr/data/apache-tomcat-7.0.40/conf/server.xml
取消對Connector port="8443"的註解,增加keystorePass的描述
                   maxThreads="150" scheme="https" secure="true" keystorePass="keytool時設定的pass"
clientAuth="false" sslProtocol="TLS" />

最後在重新啟動tomcat

0 意見:

張貼留言