From August 19th 2020, SECTIGO issues SSL certificates with a maximum lifetime of 398 days (13 months) as specified by CA/Browser consortium. SSL certificates with a longer lifetime must be re-issued annually (free of charge). You'll receive reminders via e-mail. SSL certificates issued before August 19th 2020 remain valid until their planned expiry date. Code Signing & S/MIME certificates are not affected and remain valid until their planned expiry date.

Tomcat CSR generation and CRT import (Java Keystore .JKS), Matrify, GlassFish, Wildfly ...

keytool -genkey -alias server -keyalg RSA -keysize 2048 -keystore
keytool -certreq -alias server -file csr.txt -keystore
cat csr.txt

When it asks for first and last name, this is NOT your first and last name, but rather it is your Fully Qualified Domain Name for the site you are securing (example: If you are ordering a Wildcard Certificate this must begin with the * character. (example: *

After you have placed the CSR in the interssl account and the certificate has been validated and issued, you can import it into the keystore, e.g. 

keytool -import -trustcacerts -alias server -file your_site_name.p7b -keystore your_site_name.jks

In case you didn't receive a .p7b file, you can also import the .ca-bundle and .crt files like this:  
keytool -import -trustcacerts -keystore -alias ca-bundle -file
keytool -import -trustcacerts -keystore -alias server -file www_domain_com.crt


You may find further details please on the COMODO CSR generation page:

For GlassFish specific details please have a look at:

