Let&#8217;s Encrypt free certificates are very useful for Microsoft web servers, MS Dynamics Nav web client access, Exchange and Lync/Skype for business external accesses and so on (better to use it with windows ACME clients for auto prolongation of certificate) But if you have problems with publishing 80/443 port of your web server (conflict with router admin port, or maybe even server is not in public Internet access and so on, maybe you should configure manually Let&#8217;s encrypt SSL for your testing environment) 1. go  <span><a href="https://www.itforce.mn/index.php/2017/11/16/how-manually-enable-lets-encrypt-ssl-for-windows-iis-server/" class="readmore">Continue reading &rarr;</a></span>{"id":974,"date":"2017-11-16T20:01:33","date_gmt":"2017-11-16T12:01:33","guid":{"rendered":"https:\/\/www.itforce.mn\/?p=974"},"modified":"2017-11-19T14:04:36","modified_gmt":"2017-11-19T06:04:36","slug":"how-manually-enable-lets-encrypt-ssl-for-windows-iis-server","status":"publish","type":"post","link":"https:\/\/www.itforce.mn\/index.php\/2017\/11\/16\/how-manually-enable-lets-encrypt-ssl-for-windows-iis-server\/","title":{"rendered":"How manually enable Let&#8217;s encrypt SSL for Windows IIS server."},"content":{"rendered":"<p>Let&#8217;s Encrypt free certificates are very useful for Microsoft web servers, MS Dynamics Nav web client access, Exchange and Lync\/Skype for business external accesses and so on (better to use it with windows ACME clients for auto prolongation of certificate)<\/p>\n<p>But if you have problems with publishing 80\/443 port of your web server (conflict with router admin port, or maybe even server is not in public Internet access and so on, maybe you should configure manually Let&#8217;s encrypt SSL for your testing environment)<\/p>\n<p>1. go to https:\/\/zerossl.com<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-987\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl1.jpg\" alt=\"\" width=\"1008\" height=\"751\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl1.jpg 1008w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl1-300x224.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl1-768x572.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl1-624x465.jpg 624w\" sizes=\"auto, (max-width: 1008px) 100vw, 1008px\" \/><\/p>\n<p>2.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-988\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl2.jpg\" alt=\"\" width=\"995\" height=\"769\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl2.jpg 995w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl2-300x232.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl2-768x594.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl2-624x482.jpg 624w\" sizes=\"auto, (max-width: 995px) 100vw, 995px\" \/><\/p>\n<p>3.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-989\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl3.jpg\" alt=\"\" width=\"1208\" height=\"872\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl3.jpg 1208w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl3-300x217.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl3-768x554.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl3-1024x739.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl3-624x450.jpg 624w\" sizes=\"auto, (max-width: 1208px) 100vw, 1208px\" \/><\/p>\n<p>Certbot\/ACME clients use &#8220;HTTP verification&#8221;. We will in this post use standard DNS verification (DV certificate).<\/p>\n<p>4. Enter your domain name. If you like you can create CSR by openssl, or from IIS Manager and so on, but here we will create from a scratch &#8211; so just click next:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-990\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl4.jpg\" alt=\"\" width=\"1199\" height=\"839\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl4.jpg 1199w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl4-300x210.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl4-768x537.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl4-1024x717.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl4-624x437.jpg 624w\" sizes=\"auto, (max-width: 1199px) 100vw, 1199px\" \/><\/p>\n<p>5. The result you see below:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-991\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl5.jpg\" alt=\"\" width=\"1280\" height=\"907\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl5.jpg 1280w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl5-300x213.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl5-768x544.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl5-1024x726.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl5-624x442.jpg 624w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/p>\n<p>6. Now we generate account key (used later to prolong certificate, like your password for future), again click next:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-992\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl6.jpg\" alt=\"\" width=\"1204\" height=\"816\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl6.jpg 1204w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl6-300x203.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl6-768x521.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl6-1024x694.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl6-624x423.jpg 624w\" sizes=\"auto, (max-width: 1204px) 100vw, 1204px\" \/><\/p>\n<p>7. The result:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-993\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl7.jpg\" alt=\"\" width=\"1210\" height=\"788\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl7.jpg 1210w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl7-300x195.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl7-768x500.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl7-1024x667.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl7-624x406.jpg 624w\" sizes=\"auto, (max-width: 1210px) 100vw, 1210px\" \/><\/p>\n<p>8. download and save in safe place both files. Again click next:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-994\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl8.jpg\" alt=\"\" width=\"1209\" height=\"787\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl8.jpg 1209w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl8-300x195.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl8-768x500.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl8-1024x667.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl8-624x406.jpg 624w\" sizes=\"auto, (max-width: 1209px) 100vw, 1209px\" \/><\/p>\n<p>9. Now you should prove that you are owner of the domain creating on your DNS requested TXT records (for Mongolians i am showing on our Datacom registrar):<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-995\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl9.jpg\" alt=\"\" width=\"1166\" height=\"852\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl9.jpg 1166w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl9-300x219.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl9-768x561.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl9-1024x748.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl9-624x456.jpg 624w\" sizes=\"auto, (max-width: 1166px) 100vw, 1166px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-996\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl10.jpg\" alt=\"\" width=\"814\" height=\"660\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl10.jpg 814w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl10-300x243.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl10-768x623.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl10-624x506.jpg 624w\" sizes=\"auto, (max-width: 814px) 100vw, 814px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-997\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl11.jpg\" alt=\"\" width=\"1280\" height=\"601\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl11.jpg 1280w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl11-300x141.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl11-768x361.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl11-1024x481.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl11-624x293.jpg 624w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/p>\n<p>10. if you chosen to include www prefix, repeat above steps to create second TXT record:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-998\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl12.jpg\" alt=\"\" width=\"1280\" height=\"643\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl12.jpg 1280w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl12-300x151.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl12-768x386.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl12-1024x514.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl12-624x313.jpg 624w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/p>\n<p>11. Now don&#8217;t hasten, wait 15-30 minutes before clicking on next button.<\/p>\n<p>12. Next:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1000\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl13.jpg\" alt=\"\" width=\"1262\" height=\"1667\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl13.jpg 1262w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl13-227x300.jpg 227w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl13-768x1014.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl13-775x1024.jpg 775w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl13-624x824.jpg 624w\" sizes=\"auto, (max-width: 1262px) 100vw, 1262px\" \/><\/p>\n<p>14. download your key and certificate.<\/p>\n<p>15. now we need to install certificate on Microsoft IIS. For this open your IIS Manager and for your web server open &#8220;Server Certificates&#8221;, &#8220;Complete Certificate Request&#8221;<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1001\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl14.jpg\" alt=\"\" width=\"1280\" height=\"569\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl14.jpg 1280w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl14-300x133.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl14-768x341.jpg 768w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl14-1024x455.jpg 1024w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl14-624x277.jpg 624w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/> <img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1002\" src=\"http:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl15.jpg\" alt=\"\" width=\"688\" height=\"522\" srcset=\"https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl15.jpg 688w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl15-300x228.jpg 300w, https:\/\/www.itforce.mn\/wp-content\/uploads\/2017\/11\/zerossl15-624x473.jpg 624w\" sizes=\"auto, (max-width: 688px) 100vw, 688px\" \/><\/p>\n<p>16. choose saved on step 14 file, enter friendly name (i prefer the same as cert subject name)<\/p>\n<p>17. now just bind this certificate to your web server.<\/p>\n","protected":false},"excerpt":{"rendered":null,"protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-974","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/posts\/974","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/comments?post=974"}],"version-history":[{"count":6,"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/posts\/974\/revisions"}],"predecessor-version":[{"id":1083,"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/posts\/974\/revisions\/1083"}],"wp:attachment":[{"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/media?parent=974"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/categories?post=974"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.itforce.mn\/index.php\/wp-json\/wp\/v2\/tags?post=974"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}