Microsoft IIS¶
Tip
Before proceeding, verify that the machine is already created in Certificate Manager - SaaS. Also, ensure that you’ve completed the prerequisite configuration steps for the Microsoft IIS machine.
- In the Certificate Manager - SaaS toolbar, click Machines.
- Click the more options
button at the right end of the Microsoft IIS machine's row, and then select Provision. The Provision a certificate modal opens. -
From the Choose a certificate from the inventory field, begin typing the certificate name you want to provision. Click the certificate when you see it listed.
Verify that you've selected the correct certificate by reviewing the Subject DN, Validity, and Fingerprint.
-
From the CAPI Store drop down, select the certificate store you want the certificate installed in. The Web Hosting store is recommended for certificates used by IIS.
- Enter a Friendly Name for this certificate. The certificate will appear with this name when used in IIS.
-
(Optional) If you want to bind the certificate to the IIS website, toggle the Bind Certificate to IIS Web Site slider to the on position. In the IIS Web Site Name field, enter the site from your IIS server that you want to provision the certificate to.
-
If you want Certificate Manager - SaaS to create a new binding if a matching binding isn't found, click the Create Binding if not found slider.
What happens if I don't choose this and the binding doesn't exist?
If the specified binding doesn't exist and you've told Certificate Manager - SaaS not to create it, the certificate will be added to the CAPI store, and provisioning will result in an error.
-
In the Binding IP Address field, enter an IP address that is bound to Windows. The certificate will be available only for the IP address you enter here. Leave the field empty if you want the certificate to be available an all of the Windows server's IP addresses.
- In the Binding Port, enter a port number to add to the binding.
- In the Binding Hostname, enter a hostname to add to the binding if you want the binding to use Server Name Indication (SNI).
- Enable the Require Server Name Indication toggle to enforce SNI for the binding.
- Enable the Restart the IIS Web Site instance toggle to restart the IIS web site automatically. Otherwise, restart it manually before using the certificate.
-
-
If you don't want the certificate to be pushed when you save, toggle the Push upon saving slider to No.
-
Click Save.
Want to schedule your provisions?
Schedule your provisions daily, weekly, or monthly. Learn more
Are you requiring strict enforcement of PowerShell script signing?
The Microsoft IIS provisioning process uses PowerShell over WinRM to install certificates on the Windows machine. Certificate Manager - SaaS PowerShell scripts are signed using Venafi's DigiCert CodeSigning certificate. If your organization enforces strict signing requirements to execute PowerShell scripts, ensure Venafi's CodeSigning certificate is included of the Trusted Publishers location on the machine's CAPI store.
Typically, trusted publisher certificates are managed and distributed via Group Policy by your Active Directory administrators.
You can find the certificate in PEM format for your convenience here:
-----BEGIN CERTIFICATE----- MIIHkjCCBXqgAwIBAgIQBgA2T7ITSsnbtRYegJ4l6DANBgkqhkiG9w0BAQsFADBp MQswCQYDVQQGEwJVUzEXMBUGA1UEChMORGlnaUNlcnQsIEluYy4xQTA/BgNVBAMT OERpZ2lDZXJ0IFRydXN0ZWQgRzQgQ29kZSBTaWduaW5nIFJTQTQwOTYgU0hBMzg0 IDIwMjEgQ0ExMB4XDTI2MDkyNDAwMDAwMFoXDTI3MDkyMzIzNTk1OVowgZkxCzAJ BgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRQwEgYDVQQHEwtTYW50YSBD bGFyYTEhMB8GA1UEChMYUGFsbyBBbHRvIE5ldHdvcmtzLCBJbmMuMRkwFwYDVQQL ExBFbmdpbmVlcmluZyBWYWFTMSEwHwYDVQQDExhQYWxvIEFsdG8gTmV0d29ya3Ms IEluYy4wggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDXEoMfbTbxsvVa m0u6eml6k/yHeA9r0yUamSW0LSOUuLzGpuq0lvuzolkMYGRqlPFXDDdOKali4HyH sq/xTll1UqUXfETXD/c3OMcZHStIwaWAlo5KhvffZs9qHvZ5WHB0gSoDJjUY7nM2 TgAG6T+9xAdUFRVREMzgjFLV3LoILx4LCDhQwQndk+dMY8ngrkrE//N/G2ad15kn G6MEIsOTORUqXMs/9LTEkr65tUamAFOPkszlcnAQ1xmRzkCSFxw4N2LVSCWIxmrZ 0im9/pVTXwR4XaG7R1QyzIX/wMN/cYrglJgOVt+6IbIG/S68NGZH9g5LYL2EcTP4 Ki/3x3zEEi8UJ6IJ82tfv5e/Yr7hFg9Exzaau6rmIylr+IrjIcT0SJPX95FOEozv TV2lP459Wsk3mQg0M0KLF0W9EL6SwDfh+oWuejfGDAtq5TKDV/qDodECZr/8hgE5 e0m0LajxHAT0aROSnjU4moqaN6EUKKHbCvCwMuirJKWsGx0/0D613gUywt6cEG0z 69pJFwm3T0tAa7vUkYjD5j1UFqIy965Co7s0stexvhfQLqnsSIEYfmcAzmj94pvm oE/IXpCr6in91kvTv7Wvx+ZwxKX+IVMJvgQuoKw4NDBjOWNXUfZQBznrpILus8o+ ONK1cEpXh2jAtgDdSTS+KWIEMobyEwIDAQABo4ICAzCCAf8wHwYDVR0jBBgwFoAU aDfg67Y7+F8Rhvv+YXsIiGX0TkIwHQYDVR0OBBYEFK24lFT/8MnwqCz4ol4xBO0N lfv9MD4GA1UdIAQ3MDUwMwYGZ4EMAQQBMCkwJwYIKwYBBQUHAgEWG2h0dHA6Ly93 d3cuZGlnaWNlcnQuY29tL0NQUzAOBgNVHQ8BAf8EBAMCB4AwEwYDVR0lBAwwCgYI KwYBBQUHAwMwgbUGA1UdHwSBrTCBqjBToFGgT4ZNaHR0cDovL2NybDMuZGlnaWNl cnQuY29tL0RpZ2lDZXJ0VHJ1c3RlZEc0Q29kZVNpZ25pbmdSU0E0MDk2U0hBMzg0 MjAyMUNBMS5jcmwwU6BRoE+GTWh0dHA6Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9EaWdp Q2VydFRydXN0ZWRHNENvZGVTaWduaW5nUlNBNDA5NlNIQTM4NDIwMjFDQTEuY3Js MIGUBggrBgEFBQcBAQSBhzCBhDAkBggrBgEFBQcwAYYYaHR0cDovL29jc3AuZGln aWNlcnQuY29tMFwGCCsGAQUFBzAChlBodHRwOi8vY2FjZXJ0cy5kaWdpY2VydC5j b20vRGlnaUNlcnRUcnVzdGVkRzRDb2RlU2lnbmluZ1JTQTQwOTZTSEEzODQyMDIx Q0ExLmNydDAJBgNVHRMEAjAAMA0GCSqGSIb3DQEBCwUAA4ICAQAgLKMeHbYCDN1S PJELMA/8BPtutmNup27jrc/5n9BGoXdrD6gJgKXJVYYsAVZpe+S3V0XDqi5N5PgR lw74Jr5IbPSQfrgWgL9hkMzBMoIT4R9YsAQ0lQFREgexuZhVnZXViWc7WwpSBs62 1j+kE3E7zhCFiibnXvMjgVuAXls6SlikGuvdD/Pex7ZECz3IsS7Pf6CbqYbznTTf 9dXIKGPyMoZDLGmedDvCQWeubqS1k9lUIv06knKZw6EY/LXENSb15kzrkF6/MfHE aGDpxUsLGL8DIK0kAjl2brwBWrhdVc6OPJp4SZXqjm9+/ZhC6dQQclVTb29BToug nN3IRBXtqHdXDkj0IEUYVuwLCx9P1IpMqOoXsDZp+CwCi6jy6jIflWpDv/5NRnZs iXKTbddsJLlrO21uNJusmhZcKFkq0prIoFuL6/yImG8DJ/UQGxISoGpfeURHI9JA V64jCRaJuydeeVENS6wm429WfgQ/fARxFg7YPRTwbHwurGQzHT/03Z2eiNgRnoi2 xmApiycAIEu1bOdBGYZ9nUHRuoVRnESYAiNCqW3c7DqIIRpPAoCSYsBx8mPWknX8 nXJHUFzFKDNH/j86tS43wmCgKPDW+zdarepfEmrg+lpUE3OhIHBnrB0qRxEU4N0Y fX7EDfCAv7velGAWDsLxrAPmCcoGhA== -----END CERTIFICATE-----