How to Install an SSL Certificate on Windows IIS

This article explains how to install an SSL certificate on a Windows Server using Internet Information Services (IIS).

Overview

After your SSL certificate is issued, it must be installed on the same Windows server where the CSR was generated. Then, the certificate must be assigned, or bound, to the correct IIS website so the website can load securely over HTTPS.

Note for Windows Hosting with Plesk

If your Windows hosting service uses Plesk, you do not need to install the SSL certificate manually through IIS Manager. SSL certificates for Plesk hosting should be installed and managed directly from Plesk.

For Plesk hosting, please refer to the following articles:

How to Install an SSL Certificate in Plesk
How to Manage Free SSL for Plesk Hosting from the Client Area

Prerequisites

Before you start, make sure you have:

  • Administrator access to the Windows Server.
  • IIS Manager installed.
  • The issued SSL certificate file, usually .cer, .crt, .p7b, or .pfx.
  • Access to the same server where the CSR was generated.
  • The domain name is already pointing to the server.

Important: If the CSR was generated on a different server, the certificate may not have the required private key. In this case, you may need to export and import the certificate as a .pfx file from the original server.

Step 1: Open IIS Manager

  1. Log in to your Windows Server.
  2. Open Server Manager.
  3. Go to Tools.
  4. Click Internet Information Services (IIS) Manager.

You can also open IIS Manager by running:

inetmgr

Step 2: Complete the Certificate Request

Use this method if the CSR was generated from IIS on the same Windows server.

  1. In IIS Manager, select the server name from the left-side Connections panel.
  2. Double-click Server Certificates.
  3. From the right-side Actions panel, click Complete Certificate Request.
  4. Browse and select the certificate file provided by the Certificate Authority.
  5. Enter a friendly name for the certificate, for example:
example.com SSL
  1. Select the certificate store. In most cases, choose Web Hosting or Personal.
  2. Click OK.

The certificate should now appear under Server Certificates.

If the certificate does not appear correctly or does not include a private key, the CSR may have been generated on another server.

Step 3: Import a PFX Certificate Instead

Use this method if you received a .pfx file, or if your SSL certificate and private key were exported from another server.

  1. In IIS Manager, select the server name.
  2. Open Server Certificates.
  3. Click Import from the right-side Actions panel.
  4. Select the .pfx file.
  5. Enter the PFX password.
  6. Choose the certificate store.
  7. Click OK.

A .pfx file includes both the SSL certificate and its private key. This is usually required when moving a certificate from one Windows server to another.

Step 4: Bind the SSL Certificate to the Website

After installing the certificate, you must assign it to the correct website in IIS.

  1. In IIS Manager, expand Sites.
  2. Select the website you want to secure.
  3. Click Bindings from the right-side Actions panel.
  4. Click Add.

Enter the following details:

FieldValue
Typehttps
IP addressAll Unassigned or the specific server IP
Port443
Host nameYour domain name, for example example.com
SSL certificateSelect the installed SSL certificate
  1. Click OK.
  2. Click Close.

Tip: If you are installing SSL for multiple websites on the same server, make sure the correct certificate is selected for each website binding.

Step 5: Restart the Website

After binding the certificate:

  1. Select the website in IIS Manager.
  2. Click Restart from the right-side Actions panel.

Alternatively, you can restart IIS using Command Prompt as Administrator:

iisreset

Step 6: Test the SSL Certificate

Open your website in a browser using HTTPS:

https://example.com

Check that:

  • The website loads without certificate warnings.
  • The browser shows the secure padlock icon.
  • The certificate is issued to the correct domain.
  • The certificate is not expired.
  • The certificate chain is valid.

You can also use an online SSL checker to confirm that the certificate and intermediate chain are installed correctly.

Optional: Redirect HTTP to HTTPS

Installing the SSL certificate enables HTTPS, but visitors may still access the website via HTTP unless a redirect is configured.

To force HTTPS, you can configure a redirect using the IIS URL Rewrite module.

  1. Select the website in IIS Manager.
  2. Open URL Rewrite.
  3. Click Add Rule(s).
  4. Select Blank Rule.
  5. Use the following match URL pattern:
(.*)
  1. Add a condition using:
{HTTPS}

Set it to match:

off
  1. Set the action type to Redirect.
  2. Use this redirect URL:
https://{HTTP_HOST}/{R:1}
  1. Set redirect type to Permanent (301).
  2. Save the rule.

This redirects visitors from HTTP to HTTPS automatically.

Note: URL Rewrite may not be installed by default on all Windows servers. If the URL Rewrite option is not available in IIS Manager, it may need to be installed first.

Common Issues

The certificate does not appear in IIS

Make sure you completed the certificate request on the same server where the CSR was generated.

If the CSR was generated elsewhere, you may need to import the certificate as a .pfx file instead.

The certificate is missing the private key

This usually means the CSR was generated on another server, or the private key is not available on this server.

To resolve this, export the certificate with the private key from the original server as a .pfx file, then import it into the current server.

HTTPS shows a certificate warning

Check that:

  • The certificate is issued for the correct domain name.
  • The domain points to the correct server.
  • The certificate has not expired.
  • The full certificate chain is installed.
  • The correct certificate is selected in the IIS binding.
  • The website is using the correct hostname in the HTTPS binding.

The website still opens with HTTP

SSL installation does not automatically force HTTPS.

To make all visitors use the secure version of the website, configure an HTTP-to-HTTPS redirect using IIS URL Rewrite or your website application configuration.

The certificate works for one domain but not another

Make sure the SSL certificate covers the exact domain being used.

For example:

  • A certificate for example.com may not automatically cover www.example.com.
  • A certificate for www.example.com may not automatically cover example.com.
  • A wildcard certificate such as *.example.com covers subdomains like mail.example.com and shop.example.com, but does not usually cover the root domain example.com unless it is included separately.

Share this:
FacebookXWhatsAppTelegramLinkedInGmailCopy Link
Updated on June 20, 2026
Was this article helpful?

Related Articles

Need Support?
Can't find the answer you're looking for?
Contact Support