: Provision to Microsoft IIS
Focus
Focus

Provision to Microsoft IIS

Table of Contents

Provision to Microsoft IIS

Use this procedure to provision a certificate from Next-Gen Trust Security to a Microsoft IIS machine.
Tip: Before you begin, verify that the Microsoft IIS machine is already created in Next-Gen Trust Security and that prerequisite configuration is complete. See Create a new Microsoft IIS machine.
  1. Sign in to Next-Gen Trust Security.
  2. Click Insights > Machines.
  3. Select the Microsoft IIS machine you want to provision a certificate to.
  4. Click Provision a certificate.
  5. From Choose a certificate from the inventory, search for and select the certificate you want to provision.
    Verify that you selected the correct certificate by reviewing the Subject DN, Validity, and Fingerprint.
  6. From CAPI Store, select the certificate store where the certificate will be installed.
    Note: The Web Hosting store is recommended for certificates used by IIS.
  7. Enter a Friendly Name. This name is how the certificate appears in IIS.
  8. (Optional) To bind the certificate to an IIS website, enable Bind certificate to IIS website.
    1. In IIS Web Site Name, enter the name of the website.
    2. (Optional) Enable Create binding if not found.
      Note: If a matching binding does not exist and this option is disabled, the certificate is installed in the CAPI store but provisioning fails.
    3. (Optional) In Binding IP Address, enter a specific IP address.
      • Leave this field empty to bind the certificate to all IP addresses.
    4. Enter the Binding Port.
    5. (Optional) In Binding Hostname, enter a hostname to enable SNI.
    6. (Optional) Enable Restart the IIS Web Site to automatically restart the site after provisioning.
  9. (Optional) To prevent the certificate from being pushed immediately, set Push upon saving to No.
  10. Click Save.
After saving, Next-Gen Trust Security installs the certificate on the IIS machine and creates an installation record on the Installations tab.