Apache Tomcat
Automate TLS certificate enrollment and renewal on Apache Tomcat with the Horizon Client.
The Horizon Client automates the full TLS certificate lifecycle on Apache Tomcat. The certificate is stored in a Java keystore (JKS or PKCS#12) and Tomcat is restarted automatically after each enrollment or renewal.
Tomcat automation is supported on both Linux and Windows.
Prerequisites
- Apache Tomcat installed and running
- Horizon Client installed and configured (see Installation & Configuration)
- A PKI connector configured in Horizon. See Configure SwissSign MPKI.
- A certificate profile configured in Horizon. See Certificate Profiles.
- An automation policy configured in Horizon. See Automation Policies.
- Root or sudo access (Linux), or Administrator privileges (Windows)
Setting up TLS on a new Tomcat server
Use init when Tomcat does not yet have an HTTPS connector configured:
# Linux
sudo horizon-cli automate init --target=tomcat --automation-policy=<policy># Windows
horizon-cli.exe automate init --target=tomcat --automation-policy=<policy>To set up HTTPS on a non-standard port:
# Linux
sudo horizon-cli automate init --target=tomcat --automation-policy=<policy> --port=<port># Windows
horizon-cli.exe automate init --target=tomcat --automation-policy=<policy> --port=<port>Taking control of an existing certificate
Use enroll when Tomcat is already serving HTTPS. The client detects the existing keystore from the Tomcat configuration, re-enrolls the certificate under the automation policy, and updates the keystore:
# Linux
sudo horizon-cli automate enroll --target=tomcat --automation-policy=<policy># Windows
horizon-cli.exe automate enroll --target=tomcat --automation-policy=<policy>If Tomcat uses a keystore password that cannot be read from the configuration file, provide it explicitly:
sudo horizon-cli automate enroll --target=tomcat --automation-policy=<policy> --keystore-password=<password>To preview what the client finds without making any changes:
sudo horizon-cli automate enroll --target=tomcat --automation-policy=<policy> --analyze-onlyScheduled renewal
Once enrolled, run routine to check for and perform renewals:
sudo horizon-cli automate routineCreate a periodic task to run this automatically:
# Linux (cron)
sudo horizon-cli automate create-periodic-task
# Windows (Scheduled Task)
horizon-cli.exe automate create-periodic-taskThe period can be any value between 1h and 24h. The default is 6h. To remove the task:
sudo horizon-cli automate remove-periodic-taskCertificate storage and backup
The certificate is stored in a Java keystore (JKS or PKCS#12), which the Horizon Client detects from the Tomcat configuration. On each renewal:
- The keystore is updated with the new certificate.
- The previous keystore is backed up in
/opt/horizon/cert/backup/(Linux) orC:\ProgramData\EverTrust\Horizon\cert\backup\(Windows). - The original keystore from before Horizon took management is always preserved.
To see which certificates are currently managed and find their IDs:
horizon-cli automate listIDs follow the format <target>-*:<port>, for example tomcat-*:8443.
To remove a certificate from Horizon management and restore the original, pass the ID from automate list:
# Linux
sudo horizon-cli automate remove <id> --restore# Windows
horizon-cli.exe automate remove <id> --restoreFor trigger-based workflows and other advanced automation configuration, refer to the Evertrust Horizon documentation.