For a local environment I typically use the following steps to setup a self-signed certificate.
http://tomcat.apache.org/tomcat-6.0-doc/ssl-howto.html
· Create a keystore file to store the server's private key and self-signed certificate by executing the following command:
Windows:
%JAVA_HOME%\bin\keytool -genkey -alias tomcat -keyalg RSA (In AwareIM - JDK\bin\keytool -genkey -alias tomcat -keyalg RSA)
and specify a password value of "changeit".
· Uncomment the "SSL HTTP/1.1 Connector" entry in $CATALINA_HOME/conf/server.xml and tweak as necessary. (In AwareIM - Tomcat/conf/server.xml)
This is a great way to setup a non-Chain Authority (Verisign, Thawte...) certificate. Perfectly applicable for local testing and verification. I have found that when setting up a live production SSL certificate it is very useful to get someone on the line from the certificate provider. They have steps for every type of implementation and can walk you through the process.