Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Automatic HTTP Certificates with Let's Encrypt

From Tech-Wiki


Automate ACME certificates for Windows and IIS using a supported ACME client without embedding reusable secrets in scripts.

ⓘ
Validation status
Reviewed against current win-acme and Posh-ACME v4 documentation on 27 September 2026.
!
Do not hard-code DNS API tokens or PFX passwords
The legacy script contained a Cloudflare credential and a plaintext PFX password pattern. Use restricted API tokens, SecureString/credential storage, and the renewal mechanisms provided by the chosen ACME client.

IIS: win-acme

For a normal IIS deployment, win-acme can discover IIS bindings, perform ACME validation, install the certificate, update IIS bindings, and create a scheduled renewal task.

Typical workflow:

  1. Install win-acme in a persistent application folder.
  2. Run wacs.exe as administrator.
  3. Select the IIS site/bindings.
  4. Select an approved HTTP or DNS validation method.
  5. Allow win-acme to create its renewal task.
  6. Verify certificate renewal and IIS binding replacement.

Posh-ACME with Cloudflare DNS

Posh-ACME supports Cloudflare DNS validation with a scoped API token.

>_Install Posh-ACME
Install-Module Posh-ACME -Scope AllUsers
Import-Module Posh-ACME

Create the token interactively:

$pArgs = @{
    CFToken = (Read-Host 'Cloudflare API Token' -AsSecureString)
}

Request a certificate:

>_Request an ACME certificate
New-PACertificate 'example.com','www.example.com' -Plugin Cloudflare -PluginArgs $pArgs -AcceptTOS

Renew the current order when it reaches the renewal window:

>_Renew an existing order
Submit-Renewal

Operational checks

  • Test automation against the ACME staging service before production.
  • Scope DNS tokens to only the required zones and permissions.
  • Monitor the renewal job.
  • Alert on certificate expiry so failed automation is detected before an outage.
  • Confirm IIS bindings reference the renewed certificate.

Official references