Procedure

IIS: renew and replace an HTTPS certificate

Renew and replace an IIS HTTPS certificate without downtime by importing the certificate and chain correctly, checking SNI and bindings, switching the thumbprint deliberately, validating HTTP.sys behavior, testing externally, and keeping rollback ready.

Objective

Renew and replace an IIS HTTPS certificate without downtime by importing the certificate and chain correctly, checking SNI and bindings, switching the thumbprint deliberately, validating HTTP.sys behavior, testing externally, and keeping rollback ready.

Prerequisites

  • The required names/SANs, certificate purpose, trust chain and private-key location.
  • A rollback method for the previous binding, policy or boot state.
  • Administrative access appropriate to the system being changed or diagnosed.
  • A clearly identified scope: affected users, systems, addresses, services and the time of the observed problem.
  • A maintenance or test window when the procedure can affect production traffic or availability.
  • A copy of the current configuration or other recovery material before any irreversible action.

Step-by-step procedure

1

Establish the baseline and scope

Before changing anything, reproduce the issue or document the requested change on a representative system. Record the affected users or services, exact time, current configuration, recent changes and a known-good comparison point. This baseline is the reference used to decide whether each later step improves the situation.

Expected result
  • The scope and current state are documented well enough to reproduce or verify the procedure.
2

Importing the certificate

Work through this operational element in a controlled sequence: importing the certificate. Record the current state, verify dependencies, perform the smallest necessary action, and validate its effect before continuing. If the result differs from the expected state, stop and reassess rather than stacking additional changes.

Expected result
  • Evidence for this area is explicit, reproducible and consistent with the intended design.
3

Chain correctly

Work through this operational element in a controlled sequence: chain correctly. Record the current state, verify dependencies, perform the smallest necessary action, and validate its effect before continuing. If the result differs from the expected state, stop and reassess rather than stacking additional changes.

Expected result
  • Evidence for this area is explicit, reproducible and consistent with the intended design.
4

SNI

Work through this operational element in a controlled sequence: SNI. Record the current state, verify dependencies, perform the smallest necessary action, and validate its effect before continuing. If the result differs from the expected state, stop and reassess rather than stacking additional changes.

Expected result
  • Evidence for this area is explicit, reproducible and consistent with the intended design.
5

Bindings

Work through this operational element in a controlled sequence: bindings. Record the current state, verify dependencies, perform the smallest necessary action, and validate its effect before continuing. If the result differs from the expected state, stop and reassess rather than stacking additional changes.

Expected result
  • Evidence for this area is explicit, reproducible and consistent with the intended design.
6

Switching the thumbprint deliberately

Work through this operational element in a controlled sequence: switching the thumbprint deliberately. Record the current state, verify dependencies, perform the smallest necessary action, and validate its effect before continuing. If the result differs from the expected state, stop and reassess rather than stacking additional changes.

Expected result
  • Evidence for this area is explicit, reproducible and consistent with the intended design.
7

HTTP.sys behavior

Work through this operational element in a controlled sequence: HTTP.sys behavior. Record the current state, verify dependencies, perform the smallest necessary action, and validate its effect before continuing. If the result differs from the expected state, stop and reassess rather than stacking additional changes.

Expected result
  • Evidence for this area is explicit, reproducible and consistent with the intended design.
8

Externally

Work through this operational element in a controlled sequence: externally. Record the current state, verify dependencies, perform the smallest necessary action, and validate its effect before continuing. If the result differs from the expected state, stop and reassess rather than stacking additional changes.

Expected result
  • Evidence for this area is explicit, reproducible and consistent with the intended design.
9

Rollback ready

Work through this operational element in a controlled sequence: rollback ready. Record the current state, verify dependencies, perform the smallest necessary action, and validate its effect before continuing. If the result differs from the expected state, stop and reassess rather than stacking additional changes.

Expected result
  • Evidence for this area is explicit, reproducible and consistent with the intended design.
10

Validate the complete service

Repeat the original user, system or application workflow from the real source and verify the complete result, not only one command or one local check. Confirm that logs and monitoring show the expected behavior and that no temporary debug, bypass, test account, rule or maintenance setting remains enabled.

Expected result
  • The end-to-end service works or the remaining failure is isolated to a clearly identified component.

Technical commands from the original procedure

These technical blocks are preserved byte-for-byte from the historical procedure and kept in their original order. Review names, addresses, paths and parameters before use.

Technical block 1
Import-Module WebAdministration
Technical block 2
Get-Website | Select Name,State,PhysicalPath
Technical block 3
Get-WebBinding -Protocol https | Select protocol,bindingInformation,sslFlags
Technical block 4
Get-ChildItem Cert:LocalMachineMy | Select Subject,Thumbprint,NotAfter,HasPrivateKey
Technical block 5
$pwd = Read-Host 'Mot de passe PFX' -AsSecureString
Technical block 6
Import-PfxCertificate -FilePath 'C:Tempnewcert.pfx' -CertStoreLocation Cert:LocalMachineMy -Password $pwd
Technical block 7
Get-ChildItem Cert:LocalMachineMy<THUMBPRINT> | Format-List Subject,DnsNameList,Issuer,NotBefore,NotAfter,Thumbprint,HasPrivateKey
Technical block 8
%windir%system32inetsrvappcmd add backup BOAI-before-cert-renewal
Technical block 9
%windir%system32inetsrvappcmd list backup
Technical block 10
netsh http show sslcert
Technical block 11
curl.exe -Iv https://example.tld/
Technical block 12
openssl s_client -connect example.tld:443 -servername example.tld </dev/null 2>NUL | openssl x509 -noout -subject -issuer -dates -fingerprint -sha256

Validation

The procedure is validated when:

  • The original symptom or change request has been tested end to end.
  • The effective configuration matches the intended design and no unexplained error remains in the relevant logs.
  • Temporary troubleshooting controls have been removed and monitoring remains normal.
  • The result, evidence and any follow-up action are documented.

Rollback

  • Restore the configuration, policy, binding, route, credential assignment or service state recorded in the baseline when the change does not meet its success criteria.
  • Remove temporary rules, test objects and diagnostic settings that were introduced only for the procedure.
  • After rollback, repeat the minimum health checks to confirm that the previous service level has been restored.

Troubleshooting / common errors

  • A certificate can be valid but bound to the wrong service, SNI name, key or trust chain.
  • For fleet security changes, separate firmware/UEFI readiness from operating-system policy readiness.
  • If the result changes between tests, compare source, destination, identity, time and policy context before changing additional settings.
  • If a command succeeds but the application still fails, continue at the next protocol or application layer instead of widening access.
  • If the expected evidence is missing, verify that logging, auditing and the test path actually cover the failing component.
  • If the change does not improve the measured symptom, restore the previous state and reassess the working hypothesis.

Official and vendor references preserved from the original procedure

♡ 0