
Securing your web applications with HTTPS is essential for protecting data in transit and improving user trust. This article explains how to install a free Let's Encrypt SSL/TLS certificate on Windows Server using Internet Information Services (IIS).
In this article, you’ll use the win-acme client to request and apply a certificate, bind it in IIS, and enable automatic HTTPS redirection. Optional instructions for Certbot and manual .pfx conversion are also included for advanced use cases.
IIS is a built-in feature on Windows Server that you can enable using Server Manager.
Open Server Manager from the Start menu.
Click Add Roles and Features.
Choose Role-based or feature-based installation, then select your server.
On the Server Roles screen, check Web Server (IIS).
Add any additional features you need, then click Install.
After installation, test the setup by visiting your public server IP in a browser:
You should see the default IIS welcome page.
To verify that IIS is serving content correctly, create a basic HTML application:
Open File Explorer and create a folder for your website.
Press Win + R, type notepad, and press Enter.
Paste the following HTML code into Notepad:
Save the file as index.html in the folder you just created.
Next, you’ll add this directory as a site in IIS and map it to your domain.
After creating your web files, configure a new IIS site that maps your domain to the correct folder.
Open IIS Manager from the Start Menu under Windows Administrative Tools.
In the Connections pane, expand your server name and right-click Sites, then select Add Website.
In the Add Website window, configure the following:
example.com).... and select the folder you created earlier.http.80.example.com).Click OK to create and start the site.
To verify the setup, open a browser and navigate to:
You should see the "Hello World" page you created earlier.
You can install a free SSL/TLS certificate from Let's Encrypt using one of two tools:
Review both methods below and choose the one that best suits your workflow.
Win-acme is a lightweight Let's Encrypt client that installs certificates directly into the IIS certificate store and configures HTTPS bindings automatically.
wacs.exe as Administrator.N to create a new certificate.A to apply the certificate to all bindings.Y to continue, open in IIS, agree to Let's Encrypt terms).Win-acme automatically:
Once complete, visit https://example.com in a browser to verify HTTPS is active.
Use the IIS URL Rewrite module to automatically redirect all HTTP traffic to HTTPS.
In IIS Manager, expand your server and select your site under Sites.
Double-click URL Rewrite.
In the Actions pane, click Add Rules.
Under Inbound Rules, select Blank rule and click OK.
Name your rule (e.g., Redirect to HTTPS).
Keep Requested URL as Matches the Pattern, Using as Regular Expressions.
Set the Pattern to:
Uncheck Ignore case.
Expand Conditions and click Add.
Set Condition input to:
Leave Check if input string as Matches the Pattern.
Set Pattern to:
Click OK.
Scroll to Action settings and configure:
Action type: Redirect
Redirect URL:
Uncheck Append query string
Set Redirect type to Permanent (301)
Click Apply in the Actions pane.
Open your browser and visit:
You should be redirected to the HTTPS version automatically.
In this article, you learned how to secure a website hosted on Internet Information Services (IIS) with a free Let's Encrypt SSL/TLS certificate on Windows Server. You set up IIS, deployed a basic web application, installed the certificate using Certbot or win-acme, configured HTTPS bindings, and redirected HTTP traffic to HTTPS.
With SSL properly configured, your server is now ready for secure web hosting. To build on this setup, you can install WordPress on IIS or set up PHP Manager to support dynamic web applications.
0 Comments
Be the first to comment and share your perspective with the community.