How to Install an SSL Certificate on IIS / Windows Server?

· Guide

IIS (Internet Information Services) doesn't have a one-click "install SSL" button like cPanel or Plesk — but if you're using PekiSSL, the process is much shorter than it looks: you never generate a CSR, "complete" a certificate request, or install a separate intermediate certificate. PekiSSL handles all of that for you, packaged into a single .pfx file. Here's the full process:

1. Order and Complete Validation

Enter your domain in the PekiSSL dashboard and complete the domain validation (DCV) step. You never generate the private key or CSR yourself — PekiSSL creates them automatically at order time and submits them to the certificate authority.

2. Download the PFX File

Once your certificate is ready, go to its detail page and find the "Certificate Files" panel — under the "Windows / IIS" heading you'll see a "Download as PFX (.pfx)" button. Clicking it prompts you to set a password (minimum 4 characters), which you'll use shortly when importing into IIS. PekiSSL packages your certificate, private key, and intermediate chain into this single .pfx file — there's no manual file-combining step.

3. Import the PFX into IIS

Open IIS Manager, click your server name in the left panel, then double-click "Server Certificates" in the middle pane. Click "Import..." in the right-hand Actions panel, select the .pfx file you downloaded, and enter the password you set in step 2. The certificate — along with its intermediate chain — is added to your certificate store in one step.

4. Bind the Certificate to Your Site

In IIS Manager, select your site, click "Bindings" in the Actions panel, and click "Add" to create a new binding: choose https as the Type, port 443, and select the certificate you just imported from the SSL certificate dropdown. If you're hosting multiple HTTPS sites on the same IP, check "Require Server Name Indication" (SNI).

5. Add an HTTPS Redirect

IIS has no built-in "Force HTTPS" toggle like cPanel/Plesk. You'll need to install the URL Rewrite module and add a redirect rule to your web.config file, or use the "Add Rule(s) > Canonical" template in IIS Manager's URL Rewrite interface.

6. Verify

After installation, test with ssllabs.com/ssltest. Since the PFX already includes the intermediate chain, you're very unlikely to see the "Chain issues" error that's the most common problem in the traditional CSR-based workflow.

Visit the PekiSSL product page to find the right certificate for your needs.

All blog posts