How to install letsencrypt free ssl to glassfish 4.x server

Viewed 6820

I have scanned SO and found there is no detailed instructions on how to install letsencrypt.org SSL certificate on glassfish and specifically in this tutorial I will be using glassfish 4.1.2 build 1. After a lot of trial and error, I was able to put together the following guide. So I hope that it is fine to ask and answer my own question.

In this tutorial I shall be using an Ubuntu 16.04 LTS Server with Shell access from my Ubuntu 16.04 LTS desktop.

2 Answers

I have created a Perl script to assist in the installation of Let's Encrypt certificates in Glassfish and Payara. I have successfully used it to not only install a certificate for multiple domains in about five minutes, but to automatically renew - via a cron job - those certificates when they were about to expire.

What I've done is broken the process of obtaining a Let's Encrypt certificate into the following steps, not all of which will be necessary:

  1. Customize the script to the particular local installation 1a. List of domains for which a certificate is to be created 1b. Glassfish/Payara setup (where they're located in your filesystem) 1c. Password for Glassfish/Payara
  2. Change Glassfish/Payara to listen on ports 80 and 443
  3. Generate the Let's Encrypt certification keys
  4. Insure that the keystore password matches that of the server
  5. Create a keystore
  6. Import the created keystore into the Glassfish/Payara keystore
  7. Apply the new certificate to the https listener
  8. Update the domain SSL information
  9. Set (if necessary) the server admin password.
  10. Set up the https domain

Additionally, the script can be invoked periodically (typically via 'cron') to check to see if any domains need to be renewed and if so, renew them automatically.

See: https://github.com/hbrednek/letsencrypt_glassfish for the script.

Related