Microsoft IIS
Microsoft IIS Integration
Section titled “Microsoft IIS Integration”Deploy TLS certificates to Microsoft Internet Information Services (IIS) and automate renewal using SSL-CLM.
Prerequisites
Section titled “Prerequisites”- SSL-CLM Agent installed on the Windows server running IIS
- Agent registered and in ONLINE status
- IIS configured with an HTTPS binding (existing or new)
- Agent process running with permissions to manage the Windows Certificate Store
How It Works
Section titled “How It Works”Unlike file-based web servers (NGINX, Apache), IIS uses the Windows Certificate Store for certificate management. The SSL-CLM agent:
- Imports the certificate (as PFX/PKCS#12) into the Windows Certificate Store
- Binds the certificate to the specified IIS site
- IIS automatically picks up the new binding — no manual reload needed
Step 1 — Configure Certificate Store
Section titled “Step 1 — Configure Certificate Store”Navigate to Infrastructure → Certificate Stores → + Add Store
Select IIS from the Application Server category.
Configuration Fields
Section titled “Configuration Fields”| Field | Description | Example |
|---|---|---|
| Name | Store display name | Production IIS - Web01 |
| Agent | Select the agent on the IIS server | web-server-01 |
| Site Name | IIS website name | Default Web Site |
| Store Name | Windows certificate store | WebHosting or My |
| Binding IP | IP address for the HTTPS binding | * (all IPs) |
| Binding Port | Port for the HTTPS binding | 443 |
| Binding Hostname | SNI hostname (for multi-site servers) | www.example.com |
Windows Certificate Stores
Section titled “Windows Certificate Stores”| Store Name | Use Case |
|---|---|
My (Personal) | General-purpose certificate store |
WebHosting | Recommended for IIS — designed for large numbers of certs |
Root | Trusted Root CAs (do not deploy leaf certs here) |
Use WebHosting for production IIS deployments with many certificates. Use My for single-site servers.
Step 2 — Deploy a Certificate
Section titled “Step 2 — Deploy a Certificate”- Navigate to Certificates and select the certificate
- Click Deploy
- Select the IIS store
- Confirm deployment
The agent will:
- Receive the DEPLOY_CERT job
- Convert the certificate + key to PFX format
- Import into the specified Windows Certificate Store
- Create or update the HTTPS binding on the IIS site
- Remove the old certificate from the binding (if replacing)
- Report success
Step 3 — Verify Deployment
Section titled “Step 3 — Verify Deployment”After deployment, verify:
# Check Windows Certificate StoreGet-ChildItem Cert:\LocalMachine\WebHosting
# Check IIS bindingGet-WebBinding -Name "Default Web Site" -Protocol https
# Test externallyopenssl s_client -connect www.example.com:443 -servername www.example.comSNI (Server Name Indication)
Section titled “SNI (Server Name Indication)”For servers hosting multiple HTTPS sites, configure the Binding Hostname field:
- Each site gets its own certificate store entry in SSL-CLM
- Each binding uses a unique hostname (SNI)
- IIS serves the correct certificate based on the requested hostname
Example:
- Store 1: Site
www.example.com, port 443, hostnamewww.example.com - Store 2: Site
api.example.com, port 443, hostnameapi.example.com
Automated Renewal
Section titled “Automated Renewal”SSL-CLM handles IIS certificate renewal end-to-end:
- Policy detects certificate approaching expiry
- Renewal job issues a new certificate from the CA
- Deploy job pushes new certificate to the IIS store
- Agent imports new PFX and updates the binding
- IIS immediately serves the new certificate
- No downtime — no IIS restart required
IIS-Specific Considerations
Section titled “IIS-Specific Considerations”PFX Password
Section titled “PFX Password”The agent generates a temporary PFX password for the import operation. The password is not stored after import.
Certificate Chain
Section titled “Certificate Chain”The agent imports the full certificate chain (leaf + intermediates). Ensure the CA integration provides the complete chain.
Binding Update vs. Create
Section titled “Binding Update vs. Create”- If an HTTPS binding already exists for the site + IP + port + hostname combination, the agent updates it with the new certificate
- If no binding exists, the agent creates a new HTTPS binding
Permissions
Section titled “Permissions”The agent process needs:
- Local Administrator or appropriate certificate store permissions
- Permission to modify IIS bindings (typically requires running as LocalSystem or an admin account)
Troubleshooting
Section titled “Troubleshooting”| Issue | Possible Cause | Resolution |
|---|---|---|
| Import fails | Agent lacks certificate store permissions | Run agent as LocalSystem or admin |
| Binding not created | Site name mismatch | Verify exact IIS site name (case-sensitive) |
| Old cert still served | Browser cache or existing connections | Wait for connection timeout, or restart IIS (iisreset) |
| PFX import error | Key format incompatible | Ensure certificate was issued with RSA or ECDSA key |
| Multiple bindings conflict | Duplicate hostname bindings | Remove conflicting bindings in IIS Manager |
Related Pages
Section titled “Related Pages”- Web Server Integrations — Overview of all web server integrations
- Certificate Stores — Store configuration
- Agents — Windows agent setup
- Microsoft AD CS — Windows CA integration