Here is my bash script:
#!/bin/bash
#Convert LetsEncrypt certificate to PKCS12
openssl pkcs12 -export -in /etc/letsencrypt/live/<FQDN>/fullchain.pem -inkey /etc/letsencrypt/live/<FQDN>/privkey.pem -out /var/lib/tomcat/webapps/cert.p12 -name guacamole -passout pass:guacamole
#Remove old certificate from Java keystore
keytool -keystore /var/lib/tomcat/webapps/.keystore -delete -alias guacamole -storepass guacamole -noprompt
#Import PKCS12 certificate into Java keystore
keytool -importkeystore -deststorepass guacamole -destkeypass guacamole -destkeystore /var/lib/tomcat/webapps/.keystore -srckeystore /var/lib/tomcat/webapps/cert.p12 -srcstoretype PKCS12 -srcstorepass guacamole -noprompt
#Remove PKCS12 certificate
rm -rf /var/lib/tomcat/webapps/cert.p12
#Restart tomcat
systemctl stop tomcat
systemctl start tomcat