catalina.out或localhost.log,明确是证书过期、域名不匹配、信任库问题等。openssl x509 -in certificate.crt -noout -dates检查有效期。cat cert.pem intermediate.pem > fullchain.pem合并)。server.xml中Connector配置正确,如keystoreFile路径、密码、协议(推荐TLSv1.2+)及密码套件。keytool -import -alias mycert -file cert.crt -keystore $JAVA_HOME/lib/security/cacerts。644)。sudo systemctl restart tomcat。openssl s_client -connect localhost:443或在线工具测试SSL连接。参考来源: