---
title: "Install an SSL Certificate on a Windows Core Managed Server"
source: "https://docs.nexcess.com/hosting/server-administration/windows/install-an-ssl-certificate-on-a-windows-core-managed-server/"
description: "Learn how to install an SSL certificate on your Windows Core Managed Server. Discover how to import your certificate in IIS and bind it to your website."
vertical: "Hosting"
date: "2024-03-04"
last_modified: "2026-10-05"
---

# Install an SSL Certificate on a Windows Core Managed Server

## Introduction

Installing an SSL certificate encrypts the data transmitted between your Windows Core Managed Server and your visitors. This secures sensitive customer information, builds trust, and prevents modern browsers from flagging your website as unsafe. By importing the certificate into Internet Information Services (IIS) and binding it to your site, you ensure all traffic is securely routed over HTTPS.

---

## Prerequisites

Before installing your certificate, ensure you have the following:

- **Server Access:** You must have administrative Remote Desktop Protocol (RDP) access to your Windows server.
- **Certificate File:** You need the `.cer` or `.crt` certificate file downloaded and saved locally on the server.
- **Matching Private Key:** You must have generated the original Certificate Signing Request (CSR) from this exact server so the private key matches.

---

## Step-by-step Instructions

1. Connect to your Windows server via RDP and open **Internet Information Services (IIS) Manager**.
2. In the left-hand Connections pane, click on your server name.
3. In the center window, double-click the **Server Certificates** icon.
4. In the right-hand Actions pane, click **Complete Certificate Request**. Fill out the requested information and select the Microsoft RSA Schannel **Cryptographic Service Provider** with at least 2048 bit length from the dropdown menu.
5. Choose a file name and location for the CSR, generally the name of the domain.csr.txt, saved where you can find it easily, like the documents folder.
6. [**Order an SSL Certificate**](https://docs.nexcess.com/hosting/security/ssl/ordering-an-ssl-certificate/) for your domain using the CSR you generated.
7. Click the **…** button, browse to the `.cer` or `.crt` file you saved on your server, and select it.
8. Enter a friendly name for the certificate (typically your domain name) and choose **Personal** as the certificate store. Click **OK** to import it.
9. Return to the left-hand Connections pane, expand the **Sites** folder, and select the specific website you want to secure.
10. In the right-hand Actions pane, click **Bindings**.
11. Select the existing `https` binding and click **Edit**, or click **Add** to create a new one if it does not exist.
12. Ensure the Type is set to **https** and the port is **443**.
13. Check the **Require Server Name Indication (SNI)** box if you host multiple SSL certificates on this server.
14. Select your newly imported SSL certificate from the dropdown menu and click **OK** to apply the binding.

---

## Frequently Asked Questions (FAQ)

****Why did my SSL certificate disappear from the list after I clicked OK?****This is a common IIS error that occurs when the certificate does not match the private key on the server. This happens if you generated the CSR on a different machine or accidentally deleted the pending request. You must generate a new CSR from this server and have the certificate reissued.

****Do I need to bind the certificate to every version of my domain?****If you have multiple HTTPS bindings for the same site (such as `[www.yourdomain.com](https://www.yourdomain.com)` and `yourdomain.com`), you must edit each binding and select the new certificate from the dropdown list.
