aethercert
Microsoft and Windows Server

Automated certificate renewal for Microsoft IIS

The IIS package imports each renewed certificate into the Windows certificate store, points the site's HTTPS binding at it, checks the binding and removes the certificate it replaced - on every renewal, on every web server.

The deployment steps defined in this package's manifest.

At a glance

Package
windows-iis-target 3.0.0
Compatibility
Windows Server / IIS >=2016 <2030
Runs from
A Windows agent on the server
Mechanism
PowerShell
Authentication
Local - no remote login
Capabilities
Import certificate and keyCreate bindingUpdate bindingVerify deploymentRemove old certificate
Deployment steps
import → ensureBinding → assignBinding → verifyBinding → cleanup*
Rollback
Defined by the package
Key usage
Server authentication

* conditional step

What it does

An aethercert agent on the IIS server generates the key, obtains the certificate and runs the package locally in PowerShell. The certificate is imported into LocalMachine\My (or WebHosting), tagged with a friendly name so the next renewal can find it again.

The package creates the HTTPS binding if it does not exist - with or without SNI - and assigns the new certificate to it. If verification fails, a rollback step restores the previous binding.

How it runs

  1. 01

    import

    The certificate and key are imported into the configured store, non-exportable by default.

  2. 02

    ensureBinding

    The HTTPS binding for the site, host name and port is created if missing.

  3. 03

    assignBinding

    The binding is switched to the new certificate.

  4. 04

    verifyBinding

    The package checks that the binding now references the new certificate.

  5. 05

    cleanup

    Older certificates with the same friendly name are removed, if enabled.

What you configure

  • IIS site name (default: Default Web Site)
  • Binding host name for SNI, or empty for an IP-based binding
  • Binding port (default 443)
  • Certificate store and friendly name
  • Whether to remove the previous certificate

Prerequisites

  • A Windows agent installed on the IIS server
  • IIS with the WebAdministration PowerShell module
  • A certificate whose names match the site's host names

Limitations

  • One site binding per deploy target; use several targets for several sites.

Doing it by hand

The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.

Manual replacement guide

Frequently asked questions

Microsoft IIS

Does it work with SNI?

Yes. Set the binding host name and the package creates or updates an SNI binding; leave it empty for an IP-based binding.

What happens if the binding update fails?

The deployment fails, the rollback step restores the previous binding, and the failure is recorded in the event log.

Automate Microsoft IIS

Enroll an agent, attach the package, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.