This article explains how to install an SSL certificate on a Windows Server using Internet Information Services (IIS).
Overview
After your SSL certificate is issued, it must be installed on the same Windows server where the CSR was generated. Then, the certificate must be assigned, or bound, to the correct IIS website so the website can load securely over HTTPS.
Prerequisites
Before you start, make sure you have:
- Administrator access to the Windows Server.
- IIS Manager installed.
- The issued SSL certificate file, usually
.cer,.crt,.p7b, or.pfx. - Access to the same server where the CSR was generated.
- The domain name is already pointing to the server.
Step 1: Open IIS Manager
- Log in to your Windows Server.
- Open Server Manager.
- Go to Tools.
- Click Internet Information Services (IIS) Manager.
You can also open IIS Manager by running:
inetmgr
Step 2: Complete the Certificate Request
Use this method if the CSR was generated from IIS on the same Windows server.
- In IIS Manager, select the server name from the left-side Connections panel.
- Double-click Server Certificates.
- From the right-side Actions panel, click Complete Certificate Request.
- Browse and select the certificate file provided by the Certificate Authority.
- Enter a friendly name for the certificate, for example:
example.com SSL
- Select the certificate store. In most cases, choose Web Hosting or Personal.
- Click OK.
The certificate should now appear under Server Certificates.
If the certificate does not appear correctly or does not include a private key, the CSR may have been generated on another server.
Step 3: Import a PFX Certificate Instead
Use this method if you received a .pfx file, or if your SSL certificate and private key were exported from another server.
- In IIS Manager, select the server name.
- Open Server Certificates.
- Click Import from the right-side Actions panel.
- Select the
.pfxfile. - Enter the PFX password.
- Choose the certificate store.
- Click OK.
A .pfx file includes both the SSL certificate and its private key. This is usually required when moving a certificate from one Windows server to another.
Step 4: Bind the SSL Certificate to the Website
After installing the certificate, you must assign it to the correct website in IIS.
- In IIS Manager, expand Sites.
- Select the website you want to secure.
- Click Bindings from the right-side Actions panel.
- Click Add.
Enter the following details:
| Field | Value |
|---|---|
| Type | https |
| IP address | All Unassigned or the specific server IP |
| Port | 443 |
| Host name | Your domain name, for example example.com |
| SSL certificate | Select the installed SSL certificate |
- Click OK.
- Click Close.
Step 5: Restart the Website
After binding the certificate:
- Select the website in IIS Manager.
- Click Restart from the right-side Actions panel.
Alternatively, you can restart IIS using Command Prompt as Administrator:
iisreset
Step 6: Test the SSL Certificate
Open your website in a browser using HTTPS:
https://example.com
Check that:
- The website loads without certificate warnings.
- The browser shows the secure padlock icon.
- The certificate is issued to the correct domain.
- The certificate is not expired.
- The certificate chain is valid.
You can also use an online SSL checker to confirm that the certificate and intermediate chain are installed correctly.
Optional: Redirect HTTP to HTTPS
Installing the SSL certificate enables HTTPS, but visitors may still access the website via HTTP unless a redirect is configured.
To force HTTPS, you can configure a redirect using the IIS URL Rewrite module.
- Select the website in IIS Manager.
- Open URL Rewrite.
- Click Add Rule(s).
- Select Blank Rule.
- Use the following match URL pattern:
(.*)
- Add a condition using:
{HTTPS}
Set it to match:
off
- Set the action type to Redirect.
- Use this redirect URL:
https://{HTTP_HOST}/{R:1}
- Set redirect type to Permanent (301).
- Save the rule.
This redirects visitors from HTTP to HTTPS automatically.
Common Issues
The certificate does not appear in IIS
Make sure you completed the certificate request on the same server where the CSR was generated.
If the CSR was generated elsewhere, you may need to import the certificate as a .pfx file instead.
The certificate is missing the private key
This usually means the CSR was generated on another server, or the private key is not available on this server.
To resolve this, export the certificate with the private key from the original server as a .pfx file, then import it into the current server.
HTTPS shows a certificate warning
Check that:
- The certificate is issued for the correct domain name.
- The domain points to the correct server.
- The certificate has not expired.
- The full certificate chain is installed.
- The correct certificate is selected in the IIS binding.
- The website is using the correct hostname in the HTTPS binding.
The website still opens with HTTP
SSL installation does not automatically force HTTPS.
To make all visitors use the secure version of the website, configure an HTTP-to-HTTPS redirect using IIS URL Rewrite or your website application configuration.
The certificate works for one domain but not another
Make sure the SSL certificate covers the exact domain being used.
For example:
- A certificate for
example.commay not automatically coverwww.example.com. - A certificate for
www.example.commay not automatically coverexample.com. - A wildcard certificate such as
*.example.comcovers subdomains likemail.example.comandshop.example.com, but does not usually cover the root domainexample.comunless it is included separately.