catalina.out
或localhost.log
,明确是证书过期、域名不匹配、信任库问题等。openssl x509 -in certificate.crt -noout -dates
检查有效期。cat cert.pem intermediate.pem > fullchain.pem
合并)。server.xml
中Connector
配置正确,如keystoreFile
路径、密码、协议(推荐TLSv1.2+
)及密码套件。keytool -import -alias mycert -file cert.crt -keystore $JAVA_HOME/lib/security/cacerts
。644
)。sudo systemctl restart tomcat
。openssl s_client -connect localhost:443
或在线工具测试SSL连接。参考来源: