The documentations says "Tomcat currently operates only on JKS or PKCS12 format keystores". This is wrong! I statically installed a Sun PKCS#11 provider and used the keystore on a smartcard (Kobil mIdentity). I only had to change the "keystoreType" in the server.xml file to "PKCS11" and it worked. Maybe you want to change the documentation.
Thanks for the information. The docs have been updated in SVN and will be included in 5.5.21 onwards and 6.0.3 onwards.
see also Bug 37018