David,
I am just learning about cert installation myself. Its going to be a challenge having a typical hosting service do this for Tomcat, I think.
As Pete said, you can generate your own cert, although people who don't know you personally have no reason to trust it (because its self-issued and not backed by a certificate authority). Its the certs that are backed/issued by a CA that cost money. I think Godaddy.com has low prices (about 1/5 the cost of other places) and they aren't tied-in with the dodgy Verisign juggernaut (the rest of the CA brands are owned by Verisign).