I'm coming into this conversation late, so what I say could be
completely irrelevant, but when I recently set up an independent (i.e.,
not behind httpd) Tomcat server on one of our AWS EC2 instances, and
could not get certbot to function at all, to save my life, I ended up
using something called "LEGO." It *does* require one to shut the Tomcat
server down during the renewal process (because it has to take over the
port briefly), but it also *does* play nicely with a Tomcat server
that's doing its own SSL.
--
James H. H. Lampert
---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org
For additional commands, e-mail: users-h...@tomcat.apache.org