Tomcat8.5 / 9 安装ssl证书

来源:互联网 发布:域名劫持会出现什么 编辑:程序博客网 时间:2024/06/05 20:27

Tomcat 8.5 以上版本支持 SNI ( 同IP可以安装多个证书 ), 至少 jre 7 以上版本

<Connector port="8443"protocol="org.apache.coyote.http11.Http11Nio2Protocol"maxThreads="150"SSLEnabled="true"defaultSSLHostConfigName="tomcat.gworg.com" ><SSLHostConfig hostName="tomcat.gworg.com" ><Certificate certificateKeystoreFile="conf/gworg.com.jks"certificateKeystorePassword="123456"type="RSA" />       </SSLHostConfig>// 其他站点复制多个 SSLHostConfig</Connector>

使用Apache证书安装SSL

 <Connector port="8443" protocol="org.apache.coyote.http11.Http11AprProtocol"                          maxThreads="150" SSLEnabled="true">          <SSLHostConfig>                       <Certificate certificateKeyFile="conf/ssl/server.key"                            certificateFile="conf/ssl/server.crt"                            certificateChainFile="conf/ssl/server.ca-bundle"                            type="RSA" />         </SSLHostConfig></Connector>

protocol 可选: 

org.apache.coyote.http11.Http11NioProtocol - non blocking Java NIO connectororg.apache.coyote.http11.Http11Nio2Protocol - non blocking Java NIO2 connectororg.apache.coyote.http11.Http11AprProtocol - the APR/native connector.

具体的配置参数请参考 tomcat官方文档

https://tomcat.apache.org/tomcat-9.0-doc/config/http.html

1 0
原创粉丝点击