TLS offloading

Apache Tomcat

3min
this document provides information regarding the configuration of apache tomcat with our hsms and how tls handshake offloading works for additional questions related to your hsm, see the relevant user guide about apache tomcat from the apache tomcat website the apache tomcat software is an open source implementation of the java servlet, java server pages, java expression language, and java web socket technologies apache tomcat software powers numerous large scale, mission critical web application across a diverse range of industries and organizations apache tomcat integration overview in this integration, you create tomcat web server certificates, which are required for client application connections with the webserver, by using the keytool feature embedded in java using keytool, you can create the rsa key pair and the certificate for the tomcat server the private key for this certificate is stored in the hsm by using {{futurex}} pkcs #11 (fxpkcs11) libraries and the java sunpkcs11 provider the connection between the pkcs #11 library and the hsm should be a tls connection you must create tls/ssl certificates (by using openssl or an external ca) to provide certificates for the hsm and the server where the pkcs #11 library is running guardian integration the {{guard}} introduces mission critical viability to core cryptographic infrastructure, including centralization of device management elimination of points of failure distribution of transaction loads group specific function blocking user defined grouping systems see the applicable guide in the {{futurex}} portal for configuring hsms with the {{guard}} , including pkcs #11 and cng configuration