ACME and IIS with URL Rewrite Module
Automate IIS certificate lifecycles without making HTTP-to-HTTPS rewrite rules a validation dependency.
Microsoft IIS deployments often redirect HTTP traffic to HTTPS. That works well for application traffic, but ACME HTTP-01 validation still requires DigiCert to retrieve a token from the expected /.well-known/acme-challenge/ path over port 80.
If a URL Rewrite rule prevents that file from being served correctly, validation can fail even when the network path is open. DigiCert Trust Lifecycle Manager (TLM) supports agent-based IIS automation and DNS integrations, helping organizations choose a validation approach that fits their DNS, firewall, and web-server architecture.
DNS-01 keeps domain validation independent of IIS request handling, while HTTP-01 requires the challenge path on port 80 to remain reachable and correctly served.
Why this scenario matters
HTTP-to-HTTPS redirection and ACME HTTP-01 solve different problems. Redirect rules help enforce HTTPS for normal users, while HTTP-01 proves control of a hostname by retrieving a challenge file over HTTP. When the IIS request pipeline rewrites or blocks the challenge path, the certificate workflow can fail even though port 80 is reachable.
Choose the validation method that fits the operating model. DNS-01 avoids an IIS-side challenge path and is especially useful when inbound HTTP is restricted, wildcard names are required, or teams want to reduce dependence on per-server rewrite configuration. HTTP-01 remains valid when port 80 is intentionally available, and the challenge path is correctly served.
How DigiCert fits
Agent-based IIS automation
A DigiCert agent discovers supported IIS certificates and can request, install, test, track, and renew them through managed automation.
DNS-integrated domain validation
TLM DNS integrations automate DNS-based domain control validation for public TLS certificates and can be assigned to agents or agent groups.
HTTP-01 when appropriate
For HTTP-01, port 80 must be publicly reachable and IIS must serve the expected file from /.well-known/acme-challenge/.
Central visibility and policy
TLM centralizes inventory, automation profiles, lifecycle-event status, and deployment verification so teams can distinguish issuance from installation.
At a glance
Technical implementation details
Microsoft IIS rules, supported Windows versions, agent destinations, DNS-provider credentials, and validation behavior can change over time. Always refer to the latest DigiCert and Microsoft documentation. For HTTP-01, the key requirement is that DigiCert can retrieve the expected challenge file over HTTP, as no single web.config example applies universally.
- DigiCert agents and sensors — understand how the agent discovers and manages certificates on supported web servers.
- Managed automation solution — understand how to automate certificates on servers, network appliances, cloud services, and vaults.
- Install and activate a DigiCert agent — review current Windows permissions and agent deployment guidance.
- Add a DNS integration for domain validation — see how DNS integrations automate validation and are assigned to agents or groups.
- HTTP-01 challenge requirements — confirm port-80 access and challenge-file retrieval requirements for HTTP-01.
Frequently asked questions
Ready to evaluate your environment?
See how DigiCert Trust Lifecycle Manager can support certificate lifecycle automation across your enterprise.