Install an SSL Certificate on a Windows Core Managed Server
Introduction
Installing an SSL certificate encrypts the data transmitted between your Windows Core Managed Server and your visitors. This secures sensitive customer information, builds trust, and prevents modern browsers from flagging your website as unsafe. By importing the certificate into Internet Information Services (IIS) and binding it to your site, you ensure all traffic is securely routed over HTTPS.
Prerequisites
Before installing your certificate, ensure you have the following:
- Server Access: You must have administrative Remote Desktop Protocol (RDP) access to your Windows server.
- Certificate File: You need the
.ceror.crtcertificate file downloaded and saved locally on the server. - Matching Private Key: You must have generated the original Certificate Signing Request (CSR) from this exact server so the private key matches.
Step-by-step Instructions
- Connect to your Windows server via RDP and open Internet Information Services (IIS) Manager.
- In the left-hand Connections pane, click on your server name.
- In the center window, double-click the Server Certificates icon.
- In the right-hand Actions pane, click Complete Certificate Request. Fill out the requested information and select the Microsoft RSA Schannel Cryptographic Service Provider with at least 2048 bit length from the dropdown menu.
- Choose a file name and location for the CSR, generally the name of the domain.csr.txt, saved where you can find it easily, like the documents folder.
- Order an SSL Certificate for your domain using the CSR you generated.
- Click the … button, browse to the
.ceror.crtfile you saved on your server, and select it. - Enter a friendly name for the certificate (typically your domain name) and choose Personal as the certificate store. Click OK to import it.
- Return to the left-hand Connections pane, expand the Sites folder, and select the specific website you want to secure.
- In the right-hand Actions pane, click Bindings.
- Select the existing
httpsbinding and click Edit, or click Add to create a new one if it does not exist. - Ensure the Type is set to https and the port is 443.
- Check the Require Server Name Indication (SNI) box if you host multiple SSL certificates on this server.
- Select your newly imported SSL certificate from the dropdown menu and click OK to apply the binding.
Frequently Asked Questions (FAQ)
Why did my SSL certificate disappear from the list after I clicked OK?
This is a common IIS error that occurs when the certificate does not match the private key on the server. This happens if you generated the CSR on a different machine or accidentally deleted the pending request. You must generate a new CSR from this server and have the certificate reissued.
Do I need to bind the certificate to every version of my domain?
If you have multiple HTTPS bindings for the same site (such as [www.yourdomain.com](https://www.yourdomain.com) and yourdomain.com), you must edit each binding and select the new certificate from the dropdown list.