- Mission: Configure Centralized Certificate Store in IIS to better manage certificates
- Symptoms
- Manage certificates when they expire is a nightmare
- OR
- Every time a wildcard or SAN certificate expires you need to go site by site reconfiguring their bindings
- Manage certificates when they expire is a nightmare
- Prerequisites
- Have IIS already installed with your own environment custom settings
- A network share where certificates will be stored
- Info
- This procedure will follow the GUI (Graphic User Interface) method.
Step 1: Add Centralized Certificate Support feature to IIS server
data:image/s3,"s3://crabby-images/97042/97042e94443bda405a1e5c3ca03b8b73e793efba" alt=""
data:image/s3,"s3://crabby-images/4f4ea/4f4eafa064a768bca946f79f83dabd72fe0ca156" alt=""
data:image/s3,"s3://crabby-images/03c53/03c532cadf61fb7bc1edd4fa05e6344437b38d6d" alt=""
data:image/s3,"s3://crabby-images/6f721/6f7215d909dfd3ba1250a33f780a362a8d61aad1" alt=""
data:image/s3,"s3://crabby-images/7b621/7b621e836d7ba803029523747f233746e0e7f7df" alt=""
data:image/s3,"s3://crabby-images/f05ca/f05caf23a299d6d25b83211dd944db5e1178bff5" alt=""
data:image/s3,"s3://crabby-images/373cc/373cca618df2b2a4baa097f9f208270cffc5d5ff" alt=""
data:image/s3,"s3://crabby-images/532da/532da1d7b36ec59c4ba894af8711ff2343366ae3" alt=""
data:image/s3,"s3://crabby-images/b607d/b607d191b364573ad429209529ecaf63d9ccc84b" alt=""
This process does not require a reboot.
Step 2: Configure Centralized Certificates in IIS
data:image/s3,"s3://crabby-images/5c2eb/5c2ebee9c7617cb8c837643777ade03cb421eee8" alt=""
data:image/s3,"s3://crabby-images/30104/30104be8b81c5f2c357e40d19265636f63c52b20" alt=""
- Click Edit Feature Settings.
- Select the checkbox Enable Centralized Certificates.
- Enter the physical path where the certificates are stored. This can be a local folder on the server or a network share.
- Enter the username and password of an account with read/write privileges to the folder where the certificates are stored. I recommend to have a service account with access only to this folder.
- Enter the password for the pfx certificate file, if needed.
- Click OK to finish the configuration.
Step 3: Bind your sites to the certificate store
For every site you need to bind the certificate to the centralized store
data:image/s3,"s3://crabby-images/ecdc1/ecdc1ac4e68ea979c1e567adb175599c3e4ef3a6" alt=""
data:image/s3,"s3://crabby-images/6df93/6df935570e37e67bcf991f5ea34a671f719590cb" alt=""
data:image/s3,"s3://crabby-images/7bc01/7bc0125e34bed007c47a0be7d08f2e75a603250a" alt=""