We ran into the same problem. After generating a CSR for Tomcat and getting the commercial certificate we did not have a .key file to use with Postfix because keytool doesn't export it or provide anyway of exporting it.
After some research we found a solution for exporting the .key file from keytool for the purpose of using along with the .crt/.pem file, sent by the Certificate Authority, in Postfix or Apache: http://www.zimbra.com/forums/adminis...ix-apache.html

I hope this helps.