, , (Certificate Authority) Let Encrypt. Certbot ACME ( ) https://certbot.eff.org/. root- .
1) Cerbot, certbot-auto script
wget https:
chmod a+x ./certbot-auto
./certbot-auto --help
2) , webroot. 80 443, . Webroot .
certbot-auto certonly --standalone --standalone-supported-challenges http-01 -d yourdomain.com
webroot certbot certonly /etc/letencrypt/live/.
3) Let Encrypt ( 90 ),
certbot-auto renew
4) , , PKCS12 Java.
openssl pkcs12 -export -in /etc/letsencrypt/live/yourdomain.com/fullchain.pem -inkey /etc/letsencrypt/live/yourdomain.com/privkey.pem -out /etc/letsenscrypt/live/yourdomain.com/pkcs.p12 -name mytlskeyalias -passout pass:mykeypassword
keytool -keystore /path/to/my/keystore -delete -alias ‘mytlskeyalias’ -storepass ‘mystorepassword’
keytool -importkeystore -deststorepass mystorepassword -destkeypass mykeypassword -destkeystore /path/to/my/keystore -srckeystore /etc/letsencrypt/live/mydomain.com/pkcs.p12 -srcstoretype PKCS12 -srcstorepass mykeypassword -alias mytlskeyalias
https://vaadin.com/blog/-/blogs/enabling-https-in-your-java-server-using-a-free-certificate
, SSL/TLS.