Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Install an SSL Certificate on Microsoft IIS

This guide shows you how to create a certificate request, finish the install of the certificate you receive and connect it to your website on IIS. You need admin access to the Windows server.

SSL and Security2 min read21 steps

What is IIS?

IIS (Internet Information Services) is the program on Windows Server that shows websites to visitors. An SSL certificate is a digital badge that makes the site safe over HTTPS. To get one, you first make a CSR. A CSR (Certificate Signing Request) is a block of text with details about your site. You send it to the certificate company, and they send back your certificate.

Step 1: Create the CSR

  1. Log in to the server.
  2. Open Start, type inetmgr and press Enter.
  3. Click your server name in the left panel.
  4. Double-click Server Certificates.
  5. In the right panel, click Create Certificate Request.
  6. Fill in the form. Common name is your domain, such as www.yourdomain.com. Add your organization, city, state and country.
  7. Click Next. Keep the provider as default and choose a bit length of 2048 or higher.
  8. Click ... to choose a place to save the file, such as C:\csr.txt, then click Finish.
  9. Open the file. Copy all the text and paste it into the order form of your certificate company.

Step 2: Complete the request

After the company checks your details, they send you a certificate file, often ending in .cer or .crt.

  1. Save the file on the server.
  2. In IIS Manager, open Server Certificates again.
  3. Click Complete Certificate Request in the right panel.
  4. Choose your certificate file.
  5. Type a friendly name, like yourdomain 2025. It is only for you.
  6. Click OK.

If the company also sent intermediate files, install them in the Windows certificate store first. Double-click each file and choose Install Certificate.

Step 3: Bind it to your site

  1. Expand Sites and click your website.
  2. Click Bindings in the right panel.
  3. Click Add.
  4. Choose https, keep port 443.
  5. Pick your certificate in the SSL certificate list.
  6. Click OK.

Step 4: Test

Open https://www.yourdomain.com and check for the padlock.

Tip: Complete the request on the same server where you made the CSR. If you use another server, the certificate will not match the private key.

Quick recap

  • Create a CSR in Server Certificates.
  • Send it to the certificate company.
  • Use Complete Certificate Request with the file you get back.
  • Add an https binding on port 443.