SSL Certificate Installation, Configuration & Troubleshooting Guide – Windows Server IIS 10

Windows September 30, 2026 18 Views 6 min read
SSL Certificate Installation, Configuration & Troubleshooting Guide – Windows Server IIS 10

SSL Certificate Installation Guide

Microsoft IIS 10 + GoDaddy SSL Certificate

Complete step-by-step procedure with screenshots

 

Purpose

This guide explains how to create a Certificate Signing Request (CSR) in Microsoft IIS, submit the CSR to GoDaddy, download the issued SSL certificate, install it on the IIS server, bind it to the website, verify the certificate, and resolve an intermediate-certificate chain issue when required.

Prerequisites

  • Windows Server with IIS 10 installed and the target website already configured.
  • Administrative access to the Windows server.
  • Access to the GoDaddy SSL certificate management page.
  • The domain name for which the SSL certificate will be issued.
  • The certificate files downloaded from GoDaddy after issuance.

Note: The screenshots in this document are based on the original SSL installation document. Names and domain details in the screenshots may be redacted.

Part 1 – Generate the CSR in IIS

Step 1: Open IIS Manager and Server Certificates

• Open Internet Information Services (IIS) Manager on the Windows server.

• Select the server from the Connections panel on the left.

• Open Server Certificates from the IIS feature view.

IIS Manager – Server Certificates

Step 2: Start a new Certificate Request

• In the Actions panel on the right, select Create Certificate Request…

• This starts the IIS wizard used to generate the CSR for the domain.

IIS Server Certificates – Create Certificate Request

Step 3: Enter Distinguished Name Properties

• Enter the Common name as the domain name that will use the certificate.

• Enter the Organization, Organizational unit, City/locality, State/province, and Country/region as required.

• Click Next after confirming the information.

Certificate Request – Distinguished Name Properties

Step 4: Select the Cryptographic Service Provider

• Select the Microsoft RSA SChannel Cryptographic Provider shown in the screenshot.

• Use the key length shown in the wizard (2048 in the supplied screenshot).

• Click Next.

Certificate Request – Cryptographic Service Provider Properties

Step 5: Choose the CSR file name

• Specify the path and file name where IIS should save the certificate request.

• Use a clear file name such as domain-name.txt or domain-name.csr.

• Click Finish to generate the request file.

Certificate Request – File Name

Step 6: Confirm that the CSR was created

• After the wizard finishes, verify that the CSR file has been created at the selected location.

• Keep this CSR file available because its contents will be submitted to the certificate provider.

CSR generation completed in IIS

Step 7: Open and copy the CSR

• Open the generated CSR file in a text editor such as Notepad.

• Copy the complete CSR, including the BEGIN CERTIFICATE REQUEST and END CERTIFICATE REQUEST lines.

• Do not modify the CSR text while copying it.

Generated CSR file opened in Notepad

Step 8: Submit the CSR to GoDaddy

• Open the GoDaddy SSL setup page for the certificate.

• Paste the complete CSR into the Enter your CSR field.

• Accept the Subscriber Agreement if required and continue the certificate request process.

GoDaddy – Enter your CSR

Step 9: Download the issued SSL certificate

• After GoDaddy issues the certificate, select the server type shown in the screenshot: Microsoft IIS 10.

• Use Download Zip File to download the certificate package.

• Save the ZIP file in a secure location on the server or an administrator workstation.

GoDaddy – Download the IIS certificate ZIP

Step 10: Extract the certificate package

• Extract the downloaded ZIP file.

• Keep the certificate files together and note the certificate file that will be used to complete the pending IIS certificate request.

• Do not rename certificate files unless there is a specific operational reason.

Downloaded certificate ZIP and extracted files

Part 2 – Complete the Certificate Installation in IIS

Step 11: Verify the issued certificate is available

• Return to IIS Manager and open Server Certificates.

• Confirm that the server certificate list is visible before completing the pending certificate request.

IIS Server Certificates list

Step 12: Complete the Certificate Request

• In the Actions panel, select Complete Certificate Request…

• Browse to the certificate file supplied by GoDaddy.

• Enter a friendly name for the certificate so it can be identified easily later.

• Keep the certificate store as Personal, as shown in the screenshot, and complete the wizard.

Complete Certificate Request – Specify Certificate Authority Response

Step 13: Open the website bindings

• Select the website in IIS that should use HTTPS.

• Open Bindings… from the Actions panel.

• The HTTP/HTTPS bindings for the selected site will be displayed.

IIS website bindings

Step 14: Add or edit the HTTPS binding

• Add an HTTPS binding if one does not already exist, or edit the existing HTTPS binding.

• Select HTTPS and use port 443.

• Enter the host name when host-name-based HTTPS is being used.

• Select the SSL certificate installed in the previous step.

IIS HTTPS binding configuration

Step 15: Verify the selected SSL certificate

• Open the certificate selection/details view from the HTTPS binding.

• Confirm that the selected certificate matches the intended domain.

• Check the issuer and validity dates before saving the binding.

Certificate details and IIS binding

Step 16: Test the certificate and identify chain issues

• Open the website over HTTPS and use an SSL certificate checking tool if required.

• The supplied screenshot shows the certificate and hostname checks succeeding while the chain/trust warning remains.

• If the chain is trusted correctly on your server and clients, no additional intermediate-certificate installation is required. If the chain warning appears, continue with Part 3.

SSL checker result showing an intermediate/chain issue

Part 3 – Fix the Intermediate Certificate Chain Issue

Note: Use this section when the SSL checker reports that the certificate chain is not trusted or shows an intermediate-certificate problem. The original document specifically uses the file domain-intermediate.pem for this step.

Step 17: Open the Microsoft Management Console

• Open the Windows Run dialog.

• Type mmc and press Enter.

• If Windows asks for administrative permission, allow the console to open with the required privileges.

Windows Run – mmc

Step 18: Add the Certificates snap-in

• In MMC, select File → Add/Remove Snap-in.

• Select Certificates and click Add.

• Choose Computer account.

• Select Local computer and click Finish.

• Click OK to return to the MMC console.

MMC – Certificates snap-in for Local Computer

Step 19: Import the intermediate certificate

• Navigate to Certificates → Intermediate Certification Authorities → Certificates.

• Right-click Certificates and choose All Tasks → Import.

• Start the Certificate Import Wizard.

• Import the domain-intermediate.pem file supplied for the certificate chain.

• Complete the wizard and confirm that the intermediate certificate is installed in the Intermediate Certification Authorities store.

Certificate Import Wizard – Intermediate Certification Authorities

Final Verification Checklist

  • The website opens successfully using https://.
  • The certificate subject/domain matches the website hostname.
  • The certificate is within its validity period.
  • The HTTPS binding uses port 443 and the correct certificate.
  • The certificate chain is trusted and the intermediate certificate warning is resolved, if one was previously reported.
  • Test the site from a client machine/browser after installation.

Important File / Certificate Store Notes

The original procedure places the issued server certificate in the Personal certificate store through IIS and places the intermediate certificate in Intermediate Certification Authorities through the Local Computer certificate store. Keep the private key associated with the CSR protected and do not share it with unauthorized users.

Discussion (0)