Provision to Microsoft IIS
Table of Contents
Expand all | Collapse all
-
- Activate Next-Generation Trust Security
-
-
- Configure AWS connection
- Configure Azure Key Vault connection
-
- Workload Identity Federation authentication
- Workload Identity Federation - Azure Identity Provider authentication
- Next-Gen Trust Security Generated Key authentication
- User permissions
- Workload Identity Federation authentication
- Next-Gen Trust Security Generated Key authentication
- User permissions
- Supported OIDC claims
-
-
-
-
- Create an F5 BIG-IP LTM machine
- Create a Microsoft Azure Private Key Vault machine
- Create a Microsoft IIS machine
- Create a Microsoft Windows (PowerShell) machine
- Create a Microsoft SQL Server machine
- Create a Common KeyStore machine
- Create a Citrix ADC machine
- Create an Imperva WAF machine
- Create a VMware NSX Advanced Load Balancer (AVI) machine
- Create an A10 Thunder ADC machine
- Create a Cloudflare machine
- Create Kemp Virtual LoadMaster machine
- Create a Palo Alto Panorama machine
-
- Provision to an F5 BIG-IP LTM
- Provision to a Microsoft Azure Private Key Vault
- Provision to Microsoft IIS
- Provision to Microsoft Windows (PowerShell)
- Provision to Microsoft SQL Server
- Provision to a Common KeyStore
- Provision to a Citrix ADC
- Provision to an Imperva WAF
- Provision to VMware NSX Advanced Load Balancer (AVI)
- Provision to an A10 Thunder ADC
- Provision to Cloudflare
- Provision to a Kemp Virtual LoadMaster
- Provision to Palo Alto Panorama
-
-
- 47-Day Validity Readiness TLS Certificates dashboard
- About the Certificate Inventory
- Managing certificate lifecycle settings
- Reissuing certificates in Next-Gen Trust Security
- Downloading certificates, certificate chains, and keystores
- Retiring, recovering, and deleting certificates
- Finding certificates in the certificate inventory
- Importing certificates from a CA using EJBCA
- Notification Center overview
- Domain-based validation for external emails
- Managing user accounts
- Troubleshooting
Provision to Microsoft IIS
Use this procedure to provision a certificate from Next-Gen Trust Security to a Microsoft IIS machine.
Tip: Before you begin, verify that the Microsoft IIS machine is already created in Next-Gen Trust Security and that prerequisite configuration is complete. See Create a new Microsoft IIS machine.
- Sign in to Next-Gen Trust Security.
- Click Insights > Machines.
- Select the Microsoft IIS machine you want to provision a certificate to.
- Click Provision a certificate.
- From Choose a certificate from the inventory, search for and select the certificate you want to provision.Verify that you selected the correct certificate by reviewing the Subject DN, Validity, and Fingerprint.
- From CAPI Store, select the certificate store where the certificate will be installed.Note: The Web Hosting store is recommended for certificates used by IIS.
- Enter a Friendly Name. This name is how the certificate appears in IIS.
- (Optional) To bind the certificate to an IIS website, enable Bind certificate to IIS website.
- In IIS Web Site Name, enter the name of the website.
- (Optional) Enable Create binding if not found.Note: If a matching binding does not exist and this option is disabled, the certificate is installed in the CAPI store but provisioning fails.
- (Optional) In Binding IP Address, enter a specific IP address.
- Leave this field empty to bind the certificate to all IP addresses.
- Enter the Binding Port.
- (Optional) In Binding Hostname, enter a hostname to enable SNI.
- (Optional) Enable Restart the IIS Web Site to automatically restart the site after provisioning.
- (Optional) To prevent the certificate from being pushed immediately, set Push upon saving to No.
- Click Save.
After saving, Next-Gen Trust Security installs the certificate on the IIS machine and creates an installation record on the Installations tab.