SSL questions come in two kinds. Pick yours:
A. You want users to reach your AwareIM site over https.
B. AwareIM calls another server (REST, SMTP, LDAP) and fails with PKIX path building failed.
A. HTTPS for your AwareIM site
🅰️ Reverse proxy (easiest, recommended)
In this setup Tomcat stays on plain http on the server. A proxy handles the certificate.
Good choices:
- IIS with URL Rewrite and ARR, plus win-acme for free Let’s Encrypt certificates that renew themselves (Windows).
- NGINX or Caddy with certbot (Linux).
There are no Java keystores, and renewal is automatic. Block the Tomcat port in the firewall so users can only come in through the proxy.
🅱️ Certificate directly in Tomcat
- Get your certificate as a .pfx / .p12 file that includes the private key and the intermediate certificates. Tomcat does not use the Windows certificate store.
- In
AwareIM/Tomcat/conf/server.xml, add a connector:
xml <Connector port="443" protocol="org.apache.coyote.http11.Http11NioProtocol"
SSLEnabled="true" maxThreads="150" scheme="https" secure="true">
<SSLHostConfig protocols="TLSv1.2+TLSv1.3">
<Certificate certificateKeystoreFile="C:/certs/mysite.pfx"
certificateKeystoreType="PKCS12"
certificateKeystorePassword="your-password"/>
</SSLHostConfig> </Connector>
- Restart AwareIM.
- In the Configuration Tool, go to File → Settings and set the Web URL to
https://<name-on-certificate>:443/AwareIM.
🔄 Renewing
Replace the .pfx file with the new one. Keep the same file name and password, then restart. You do not need to edit server.xml.
⚠️ Common errors
| Error | Cause / fix |
| Browser says the certificate is incomplete, or other servers get PKIX errors when they call you | The intermediate certificates are missing. Rebuild the .pfx with the full chain. Check the result with an online SSL checker |
Certificate reply does not contain public key for <tomcat> | The certificate does not match the key in the keystore. Use the key that made the CSR, or get the certificate as a .pfx |
| PEM files (`.crt` + `.key`) | Convert them to .pfx: openssl pkcs12 -export -in cert.crt -inkey private.key -certfile ca-bundle.crt -out mysite.pfx |
| Page loads but parts are blank or show a warning | Something on the page still uses http:// (images, iframes, DISPLAY URL). Change it to https:// |
B. PKIX path building failed / unable to find valid certification path
The Java inside AwareIM does not trust the other server’s certificate.
âś… Fix:
- Upgrade to a current AwareIM build first. Newer builds ship a newer Java that trusts more certificate authorities. Often this alone fixes it.
- If the error stays, get the other server’s **root or intermediate** certificate:
openssl s_client -connect api.example.com:443 -showcerts
Import it into the AwareIM Java:
C:\AwareIM\JDK\bin\keytool -importcert -cacerts -alias example-ca -file example-ca.pem
The default password is changeit.
3. Restart AwareIM.
Two warnings:
- Import the root or intermediate certificate, not the site’s own certificate. The site’s own certificate changes at every renewal, and then the error comes back.
- If the certificate issuer is your antivirus (for example “Bitdefender … CA”), the antivirus is intercepting the traffic. Turn off its HTTPS scanning on the server. Do not import that certificate.
Still stuck? Post the full error from the server output, the URL or host AwareIM is calling, and your AwareIM version and build.