Skip to content

Microsoft IIS

Deploy TLS certificates to Microsoft Internet Information Services (IIS) and automate renewal using SSL-CLM.


  • SSL-CLM Agent installed on the Windows server running IIS
  • Agent registered and in ONLINE status
  • IIS configured with an HTTPS binding (existing or new)
  • Agent process running with permissions to manage the Windows Certificate Store

Unlike file-based web servers (NGINX, Apache), IIS uses the Windows Certificate Store for certificate management. The SSL-CLM agent:

  1. Imports the certificate (as PFX/PKCS#12) into the Windows Certificate Store
  2. Binds the certificate to the specified IIS site
  3. IIS automatically picks up the new binding — no manual reload needed

Navigate to Infrastructure → Certificate Stores → + Add Store

Select IIS from the Application Server category.

FieldDescriptionExample
NameStore display nameProduction IIS - Web01
AgentSelect the agent on the IIS serverweb-server-01
Site NameIIS website nameDefault Web Site
Store NameWindows certificate storeWebHosting or My
Binding IPIP address for the HTTPS binding* (all IPs)
Binding PortPort for the HTTPS binding443
Binding HostnameSNI hostname (for multi-site servers)www.example.com
Store NameUse Case
My (Personal)General-purpose certificate store
WebHostingRecommended for IIS — designed for large numbers of certs
RootTrusted Root CAs (do not deploy leaf certs here)

Use WebHosting for production IIS deployments with many certificates. Use My for single-site servers.


  1. Navigate to Certificates and select the certificate
  2. Click Deploy
  3. Select the IIS store
  4. Confirm deployment

The agent will:

  1. Receive the DEPLOY_CERT job
  2. Convert the certificate + key to PFX format
  3. Import into the specified Windows Certificate Store
  4. Create or update the HTTPS binding on the IIS site
  5. Remove the old certificate from the binding (if replacing)
  6. Report success

After deployment, verify:

Terminal window
# Check Windows Certificate Store
Get-ChildItem Cert:\LocalMachine\WebHosting
# Check IIS binding
Get-WebBinding -Name "Default Web Site" -Protocol https
# Test externally
openssl s_client -connect www.example.com:443 -servername www.example.com

For servers hosting multiple HTTPS sites, configure the Binding Hostname field:

  • Each site gets its own certificate store entry in SSL-CLM
  • Each binding uses a unique hostname (SNI)
  • IIS serves the correct certificate based on the requested hostname

Example:

  • Store 1: Site www.example.com, port 443, hostname www.example.com
  • Store 2: Site api.example.com, port 443, hostname api.example.com

SSL-CLM handles IIS certificate renewal end-to-end:

  1. Policy detects certificate approaching expiry
  2. Renewal job issues a new certificate from the CA
  3. Deploy job pushes new certificate to the IIS store
  4. Agent imports new PFX and updates the binding
  5. IIS immediately serves the new certificate
  6. No downtime — no IIS restart required

The agent generates a temporary PFX password for the import operation. The password is not stored after import.

The agent imports the full certificate chain (leaf + intermediates). Ensure the CA integration provides the complete chain.

  • If an HTTPS binding already exists for the site + IP + port + hostname combination, the agent updates it with the new certificate
  • If no binding exists, the agent creates a new HTTPS binding

The agent process needs:

  • Local Administrator or appropriate certificate store permissions
  • Permission to modify IIS bindings (typically requires running as LocalSystem or an admin account)

IssuePossible CauseResolution
Import failsAgent lacks certificate store permissionsRun agent as LocalSystem or admin
Binding not createdSite name mismatchVerify exact IIS site name (case-sensitive)
Old cert still servedBrowser cache or existing connectionsWait for connection timeout, or restart IIS (iisreset)
PFX import errorKey format incompatibleEnsure certificate was issued with RSA or ECDSA key
Multiple bindings conflictDuplicate hostname bindingsRemove conflicting bindings in IIS Manager