Integrations
Apache Tomcat / Java Certificate Automation
First-Party Linux Target
SSLNexus manages Java/Tomcat certificates through the existing Linux SSH + Ansible provisioner. The adapter generates the private key and CSR inside the target PKCS#12 keystore, so the private key does not return to SSLNexus.
Workflow
- Register the host as a Linux target and select Apache Tomcat / Java.
- Configure the Tomcat home,
server.xml, PKCS#12 keystore path, alias, systemd service and HTTPS port. - Set the keystore password as the application secret.
- SSLNexus runs
keytoolon the target to create the key and CSR. - The selected CA signs that CSR.
- SSLNexus imports the certificate into the existing key entry, restarts only the configured service and verifies the HTTPS listener.
Key custody: the private key is generated and retained in the customer-controlled Java keystore.
Renewal Binding
The keystore, key alias, service name and listener port are retained in the deployment binding so later renewals reuse the explicit target relationship.

