SSL / TLS Encryption & HTTP/2 Configuration
PKCS12 keystore generation, modern TLSv1.3 connectors, certificate binding, and HTTPS redirects.
1. Generate Modern PKCS12 Keystore
PKCS12 is the industry standard format replacing legacy JKS. Generate a 2048/4096-bit RSA keypair:
keytool -genkeypair -alias tomcat -keyalg RSA -keysize 2048 -validity 365 \ -keystore /opt/tomcat/conf/keystore.p12 -storetype PKCS12 \ -storepass ChangeMe123 -keypass ChangeMe123 \ -dname "CN=app.example.com, OU=IT, O=Enterprise, L=Riyadh, C=SA" sudo chmod 600 /opt/tomcat/conf/keystore.p12 sudo chown tomcat:tomcat /opt/tomcat/conf/keystore.p12
2. Modern HTTPS Connector with HTTP/2 (conf/server.xml)
Configure an encrypted NIO connector with HTTP/2 multiplexing enabled on port 8443 or 443:
<!-- Modern SSL/TLS Connector with HTTP/2 Support -->
<Connector port="8443" protocol="org.apache.coyote.http11.Http11NioProtocol"
maxThreads="200" SSLEnabled="true" scheme="https" secure="true">
<UpgradeProtocol className="org.apache.coyote.http2.Http2Protocol" />
<SSLHostConfig protocols="TLSv1.2+TLSv1.3"
ciphers="TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256">
<Certificate certificateKeystoreFile="conf/keystore.p12"
certificateKeystorePassword="ChangeMe123"
certificateKeystoreType="PKCS12"
type="RSA" />
</SSLHostConfig>
</Connector>
3. Enforce Global HTTPS Redirects (conf/web.xml)
Redirect all plain HTTP traffic automatically to secure HTTPS at the container level:
<security-constraint>
<web-resource-collection>
<web-resource-name>Entire Application</web-resource-name>
<url-pattern>/*</url-pattern>
</web-resource-collection>
<user-data-constraint>
<transport-guarantee>CONFIDENTIAL</transport-guarantee>
</user-data-constraint>
</security-constraint>