Windows IIS Server
Automate TLS certificate enrollment and renewal on Microsoft IIS with the Horizon Client.
The Horizon Client automates the full TLS certificate lifecycle on Windows IIS web servers. Certificates are enrolled via an automation policy and stored in the Windows machine certificate store — IIS reads them from there automatically.
Prerequisites
- Windows Server with IIS installed and running
- Horizon Client installed via the MSI installer (see Installation & Configuration)
- A PKI connector configured in Horizon. See Configure SwissSign MPKI.
- A certificate profile configured in Horizon. See Certificate Profiles.
- An automation policy configured in Horizon. See Automation Policies.
Setting up TLS on a new IIS site
Use init when the IIS site does not yet have an HTTPS binding:
horizon-cli.exe automate init --target=iis --automation-policy=<policy>To set up HTTPS on a non-standard port:
horizon-cli.exe automate init --target=iis --automation-policy=<policy> --port=<port>Taking control of an existing certificate
Use enroll when IIS is already serving HTTPS. The client detects the existing certificate from the IIS configuration, re-enrolls it under the automation policy, and updates the binding:
horizon-cli.exe automate enroll --target=iis --automation-policy=<policy>To preview what the client finds without making any changes:
horizon-cli.exe automate enroll --target=iis --automation-policy=<policy> --analyze-onlyScheduled renewal
Once enrolled, run routine to check for and perform renewals:
horizon-cli.exe automate routineCreate a Windows Scheduled Task to run this automatically:
horizon-cli.exe automate create-periodic-taskThe period can be any value between 1h and 24h. The default is 6h. To remove the scheduled task:
horizon-cli.exe automate remove-periodic-taskCertificate storage and backup
The enrolled certificate is stored in the Windows machine certificate store (Local Computer). On each renewal:
- The new certificate replaces the current one in the store.
- The previous certificate is retained as a backup. The original certificate from before Horizon took management is always preserved.
- Backup thumbprints are recorded in the
iisbackupsfile inside the Horizon Client data folder:C:\ProgramData\EverTrust\Horizon.
To see which certificates are currently managed and find their IDs:
horizon-cli.exe automate listIDs follow the format <target>-*:<port>, for example iis-*:443.
To remove a certificate from Horizon management and restore the original, pass the ID from automate list:
horizon-cli.exe automate remove <id> --restoreFor trigger-based workflows and other advanced automation configuration, refer to the Evertrust Horizon documentation.