Automated certificate renewal for Microsoft IIS
The IIS package imports each renewed certificate into the Windows certificate store, points the site's HTTPS binding at it, checks the binding and removes the certificate it replaced - on every renewal, on every web server.
package windows-iis-target 3.0.0
importensureBindingassignBindingverifyBindingcleanupwhen configured
At a glance
- Package
windows-iis-target 3.0.0- Compatibility
Windows Server / IIS >=2016 <2030- Runs from
- A Windows agent on the server
- Mechanism
- PowerShell
- Authentication
- Local - no remote login
- Capabilities
- Import certificate and keyCreate bindingUpdate bindingVerify deploymentRemove old certificate
- Deployment steps
- import → ensureBinding → assignBinding → verifyBinding → cleanup*
- Rollback
- Defined by the package
- Key usage
- Server authentication
* conditional step
What it does
An aethercert agent on the IIS server generates the key, obtains the certificate and runs the package locally in PowerShell. The certificate is imported into LocalMachine\My (or WebHosting), tagged with a friendly name so the next renewal can find it again.
The package creates the HTTPS binding if it does not exist - with or without SNI - and assigns the new certificate to it. If verification fails, a rollback step restores the previous binding.
How it runs
- 01
import
The certificate and key are imported into the configured store, non-exportable by default.
- 02
ensureBinding
The HTTPS binding for the site, host name and port is created if missing.
- 03
assignBinding
The binding is switched to the new certificate.
- 04
verifyBinding
The package checks that the binding now references the new certificate.
- 05
cleanup
Older certificates with the same friendly name are removed, if enabled.
What you configure
- IIS site name (default: Default Web Site)
- Binding host name for SNI, or empty for an IP-based binding
- Binding port (default 443)
- Certificate store and friendly name
- Whether to remove the previous certificate
Prerequisites
- A Windows agent installed on the IIS server
- IIS with the WebAdministration PowerShell module
- A certificate whose names match the site's host names
Limitations
- One site binding per deploy target; use several targets for several sites.
Doing it by hand
The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.
Related features
Solutions
More in Microsoft and Windows Server
Documentation
Frequently asked questions
Microsoft IIS
Does it work with SNI?
Yes. Set the binding host name and the package creates or updates an SNI binding; leave it empty for an IP-based binding.
What happens if the binding update fails?
The deployment fails, the rollback step restores the previous binding, and the failure is recorded in the event log.
Automate Microsoft IIS
Enroll an agent, attach the package, and the next renewal installs itself.
Community plan, no card required. Open registration - your account is ready in a few minutes.