ACME and IIS with URL Rewrite Module

Automate IIS certificate lifecycles without making HTTP-to-HTTPS rewrite rules a validation dependency.

Microsoft IIS deployments often redirect HTTP traffic to HTTPS. That works well for application traffic, but ACME HTTP-01 validation still requires DigiCert to retrieve a token from the expected /.well-known/acme-challenge/ path over port 80.

If a URL Rewrite rule prevents that file from being served correctly, validation can fail even when the network path is open. DigiCert Trust Lifecycle Manager (TLM) supports agent-based IIS automation and DNS integrations, helping organizations choose a validation approach that fits their DNS, firewall, and web-server architecture.

is-url-rewrite-module.png

DNS-01 keeps domain validation independent of IIS request handling, while HTTP-01 requires the challenge path on port 80 to remain reachable and correctly served.

Why this scenario matters

HTTP-to-HTTPS redirection and ACME HTTP-01 solve different problems. Redirect rules help enforce HTTPS for normal users, while HTTP-01 proves control of a hostname by retrieving a challenge file over HTTP. When the IIS request pipeline rewrites or blocks the challenge path, the certificate workflow can fail even though port 80 is reachable.

Choose the validation method that fits the operating model. DNS-01 avoids an IIS-side challenge path and is especially useful when inbound HTTP is restricted, wildcard names are required, or teams want to reduce dependence on per-server rewrite configuration. HTTP-01 remains valid when port 80 is intentionally available, and the challenge path is correctly served.

How DigiCert fits

Agent-based IIS automation

A DigiCert agent discovers supported IIS certificates and can request, install, test, track, and renew them through managed automation.

DNS-integrated domain validation

TLM DNS integrations automate DNS-based domain control validation for public TLS certificates and can be assigned to agents or agent groups.

HTTP-01 when appropriate

For HTTP-01, port 80 must be publicly reachable and IIS must serve the expected file from /.well-known/acme-challenge/.

Central visibility and policy

TLM centralizes inventory, automation profiles, lifecycle-event status, and deployment verification so teams can distinguish issuance from installation.

At a glance

Environment
Supported Windows Server running IIS with URL Rewrite or another rule that changes HTTP requests
DigiCert deployment model
Trust Lifecycle Manager managed automation with a DigiCert agent on the IIS server.
Typical validation choice
DNS-01 avoids the IIS request path. HTTP-01 fits when port 80 is reachable and the ACME challenge path is correctly served.
What to verify before deployment
Supported IIS/Windows versions, agent/network requirements, DNS integration availability, port-80 reachability for HTTP-01, and rewrite behavior for /.well-known/acme-challenge/.

Technical implementation details

Microsoft IIS rules, supported Windows versions, agent destinations, DNS-provider credentials, and validation behavior can change over time. Always refer to the latest DigiCert and Microsoft documentation. For HTTP-01, the key requirement is that DigiCert can retrieve the expected challenge file over HTTP, as no single web.config example applies universally.

Frequently asked questions

Why can URL Rewrite interfere with ACME HTTP-01 validation?
HTTP-01 requires DigiCert to retrieve the expected challenge file over port 80 via a supported third-party ACME client. A redirect or rewrite can interfere if it prevents that file from being returned; DigiCert lists redirect rules among common HTTP-01 configuration issues.
Is DNS-01 always required for IIS when URL Rewrite is installed?
No, DNS-01 avoids the IIS request pipeline, but HTTP-01 can also work when port 80 is reachable, and the challenge path is correctly served. Choose based on DNS access, firewall policy, wildcard requirements, and operations.
Do we need inbound port 80 when using DNS-01?
Not for the ACME DNS-01 challenge itself. DNS-01 validates via a DNS TXT record, so IIS does not need to expose the ACME challenge path on port 80. Normal application traffic has separate requirements.
Does the DigiCert agent update the certificate in IIS?
Yes, for supported managed-automation workflows. The agent installs the certificate, configures the supported web-server application to use it, and performs a post-installation endpoint test to verify the deployment.

Ready to evaluate your environment?

See how DigiCert Trust Lifecycle Manager can support certificate lifecycle automation across your enterprise.

Explore DigiCert Trust Lifecycle Manager Talk to DigiCert