SSL / TLS & HTTP/2

1. Generate Modern PKCS12 Keystore

PKCS12 is the industry standard format replacing legacy JKS. Generate a 2048/4096-bit RSA keypair:

keytool -genkeypair -alias tomcat -keyalg RSA -keysize 2048 -validity 365 \
  -keystore /opt/tomcat/conf/keystore.p12 -storetype PKCS12 \
  -storepass ChangeMe123 -keypass ChangeMe123 \
  -dname "CN=app.example.com, OU=IT, O=Enterprise, L=Riyadh, C=SA"

sudo chmod 600 /opt/tomcat/conf/keystore.p12
sudo chown tomcat:tomcat /opt/tomcat/conf/keystore.p12

2. Modern HTTPS Connector with HTTP/2 (conf/server.xml)

Configure an encrypted NIO connector with HTTP/2 multiplexing enabled on port 8443 or 443:

<!-- Modern SSL/TLS Connector with HTTP/2 Support -->
<Connector port="8443" protocol="org.apache.coyote.http11.Http11NioProtocol"
           maxThreads="200" SSLEnabled="true" scheme="https" secure="true">
    <UpgradeProtocol className="org.apache.coyote.http2.Http2Protocol" />
    <SSLHostConfig protocols="TLSv1.2+TLSv1.3"
                   ciphers="TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256">
        <Certificate certificateKeystoreFile="conf/keystore.p12"
                     certificateKeystorePassword="ChangeMe123"
                     certificateKeystoreType="PKCS12"
                     type="RSA" />
    </SSLHostConfig>
</Connector>

3. Enforce Global HTTPS Redirects (conf/web.xml)

Redirect all plain HTTP traffic automatically to secure HTTPS at the container level:

<security-constraint>
    <web-resource-collection>
        <web-resource-name>Entire Application</web-resource-name>
        <url-pattern>/*</url-pattern>
    </web-resource-collection>
    <user-data-constraint>
        <transport-guarantee>CONFIDENTIAL</transport-guarantee>
    </user-data-constraint>
</security-constraint>