Create certificate for web server - use https for web viewer

To be able to connect to a Signifikant Web viewer using https (encrypted connection), a certificate shall be created on the server and bindings updated where the certificate is linked to port 443 for the web site that runs WebViewer. With the Windows program WinAcme you can create a free certificate (certified by Let’s Encrypt) that is automatically renewed every three months.

  1. Ensure that the domain name you want to use is linked to the IP address of the server through a A record in the DNS register. It can take a few hours for the DNS record to be propagated to the web server.

  2. Download the Windows version of Win-Acme here: win-acme.com

  3. Transfer the zip file to the web server and unzip the file

  4. Run wacs.exe in an command windows that runs in Administrator mode

  5. Choose M in the dialogue (“Create certificate (full options”)

  6. Choose Manual input when asked how to determine the domain name

  7. Enter the domain name you have linked to the IP address when asked for the host names

  8. Choose any friendly name, or just press enter

  9. Choose default answers for all remaining questions (given you have a standard setup with just one web site on the IIS server)

  10. During the process, the program will do a check to see if the domain name does point to the IP address. If validation goes well, it will create a certificate, add it to the IIS server and bind it to port 443 of the default web site.

  11. The program will also setup a scheduled task that automatically will renew the certificate every three months (the scheduled task will check every day if a renewal is needed).

Public analyse tools can be use to verify certificates on the server, as well as other security aspects. Example below for Ålö public web server.

https://www.ssllabs.com/ssltest/analyze.html?d=parts.quicke.nu