Automatic HTTP Certificates with Let's Encrypt
From Tech-Wiki
More actions
Automate ACME certificates for Windows and IIS using a supported ACME client without embedding reusable secrets in scripts.
Validation status
Reviewed against current win-acme and Posh-ACME v4 documentation on 27 September 2026.
Do not hard-code DNS API tokens or PFX passwords
The legacy script contained a Cloudflare credential and a plaintext PFX password pattern. Use restricted API tokens, SecureString/credential storage, and the renewal mechanisms provided by the chosen ACME client.
IIS: win-acme
For a normal IIS deployment, win-acme can discover IIS bindings, perform ACME validation, install the certificate, update IIS bindings, and create a scheduled renewal task.
Typical workflow:
- Install win-acme in a persistent application folder.
- Run
wacs.exeas administrator. - Select the IIS site/bindings.
- Select an approved HTTP or DNS validation method.
- Allow win-acme to create its renewal task.
- Verify certificate renewal and IIS binding replacement.
Posh-ACME with Cloudflare DNS
Posh-ACME supports Cloudflare DNS validation with a scoped API token.
Install Posh-ACME
Install-Module Posh-ACME -Scope AllUsers Import-Module Posh-ACME
Create the token interactively:
$pArgs = @{
CFToken = (Read-Host 'Cloudflare API Token' -AsSecureString)
}
Request a certificate:
Request an ACME certificate
New-PACertificate 'example.com','www.example.com' -Plugin Cloudflare -PluginArgs $pArgs -AcceptTOS
Renew the current order when it reaches the renewal window:
Renew an existing order
Submit-Renewal
Operational checks
- Test automation against the ACME staging service before production.
- Scope DNS tokens to only the required zones and permissions.
- Monitor the renewal job.
- Alert on certificate expiry so failed automation is detected before an outage.
- Confirm IIS bindings reference the renewed certificate.