Integrations

Apache Tomcat / Java Certificate Automation

First-Party Linux Target

SSLNexus manages Java/Tomcat certificates through the existing Linux SSH + Ansible provisioner. The adapter generates the private key and CSR inside the target PKCS#12 keystore, so the private key does not return to SSLNexus.

Workflow

  1. Register the host as a Linux target and select Apache Tomcat / Java.
  2. Configure the Tomcat home, server.xml, PKCS#12 keystore path, alias, systemd service and HTTPS port.
  3. Set the keystore password as the application secret.
  4. SSLNexus runs keytool on the target to create the key and CSR.
  5. The selected CA signs that CSR.
  6. SSLNexus imports the certificate into the existing key entry, restarts only the configured service and verifies the HTTPS listener.
Key custody: the private key is generated and retained in the customer-controlled Java keystore.

Renewal Binding

The keystore, key alias, service name and listener port are retained in the deployment binding so later renewals reuse the explicit target relationship.

Related Documentation

Deployment targets · CA connectors · Dependency & Impact