Automated TLS certificate management for a single IIS website

Automate certificate lifecycles for a fully encrypted IIS website while preserving your existing Windows Server architecture.

A DigiCert Agent installed on the IIS server enables centralized certificate lifecycle management through DigiCert Trust Lifecycle Manager (TLM). In this scenario, end users connect to a single IIS website over HTTPS through the corporate firewall, while the website remains fully TLS-encrypted. The DigiCert Agent performs supported certificate automation locally on the Windows server and communicates with DigiCert services via outbound HTTPS connectivity, so no inbound firewall rules are required.

User HTTPS traffic and certificate-management traffic are separate. End users initiate HTTPS 443 connections to IIS. The DigiCert Agent initiates outbound HTTPS 443 management connectivity to Trust Lifecycle Manager.

Why this scenario matters

A single IIS website may seem simple, but its TLS certificate remains operationally critical. If the certificate expires or the IIS HTTPS binding points to the wrong certificate, users may see browser warnings or lose access to the application entirely. As public TLS certificate lifetimes continue to shorten, manual renewal, import, and binding processes become harder to manage reliably.

The goal is not to replace Microsoft IIS or the Windows Certificate Store. It is to automate certificate lifecycle management around the existing Windows and IIS architecture while keeping the live website encrypted over HTTPS.

How DigiCert fits

At a glance

Technical implementation details

DigiCert supports Agent-based managed automation for Microsoft IIS on supported Windows systems. Supported systems include Microsoft IIS 7, 7.5, 8.0, 8.5, and 10 on supported Windows platforms. DigiCert strives to support the latest IIS versions; please confirm the latest documentation before deployment.

The DigiCert Agent requires Administrator privileges on Windows and outbound HTTPS access over TCP 443 to the applicable DigiCert ONE platform, automation services, and discovery services. The DigiCert Agent is installed on the server that hosts the certificates it discovers and manages.

For DNS-based DCV, you can assign TLM DNS integrations to DigiCert Agents, so challenge records can be automated through the DNS provider. If you use HTTP-based validation, ensure the challenge path is reachable over HTTP and is not blocked by firewall rules, redirects, or IIS request-handling rules, and that you use a suitable third-party ACME client.

Before deployment, confirm the exact endpoints, supported versions, enrollment and profile settings, key-storage behavior, binding behavior, validation requirements, and proxy options in the current DigiCert documentation for the target environment.

Technical resources

Frequently asked questions

Can DigiCert automate certificate management for a single IIS website?
Yes, for supported Windows and IIS versions, DigiCert documents Agent-based managed automation for web servers. The DigiCert Agent runs on the IIS host and connects to TLM over outbound HTTPS.
Does Trust Lifecycle Manager require inbound management access to the IIS server?
No inbound TLM-to-Agent management connection is required. The DigiCert Agent uses a pull communication model and initiates outbound HTTPS connections to DigiCert services.
Is the IIS website still fully encrypted?
Yes, in this scenario, end users connect to the IIS website over HTTPS 443. Certificate-management traffic is a separate outbound management path and does not replace or proxy the user's TLS connection.
Which validation method should we use?
DNS-based validation is often a strong fit because it avoids opening inbound HTTP solely for validation and can be automated through a TLM DNS integration. HTTP-based validation is also possible when the IIS and network configuration can reliably serve the validation challenge.
What Windows and IIS versions are supported?
Support is version-specific and changes over time. Review DigiCert's current Supported systems documentation before designing or deploying the workflow.
Does the DigiCert Agent need Administrator privileges on Windows?
Yes, DigiCert's current Windows Agent requirements specify Administrator privileges. Confirm the complete Agent system and network requirements for the target server before installation.

Ready to evaluate your environment?

See how DigiCert Trust Lifecycle Manager can support certificate lifecycle automation across your enterprise.

Explore DigiCert Trust Lifecycle Manager Talk to DigiCert