Let’s Encrypt IIS Fix: Keep HTTP-to-HTTPS Redirects Without Breaking SSL Renewals


If you’ve configured a global HTTP-to-HTTPS rewrite rule in your IIS web.config file, you might have noticed a frustrating side effect: your automated Let’s Encrypt (or Win-ACME) SSL certificate renewals suddenly start failing.

This happens because Let’s Encrypt uses an automated HTTP challenge (HTTP-01). It looks for a specific validation file inside a hidden directory called .well-known/acme-challenge/ over standard, unencrypted HTTP (Port 80). If your global redirect catches that request and forces it over to HTTPS before the certificate is renewed, the verification chain can break, leaving your site unsecured.

At UpTime, we don't believe in sacrificing security for configuration convenience. You can have both. Here is how to update your web.config file to automatically ignore the .well-known folder, allowing your SSL certificates to renew seamlessly while keeping your visitors forced onto safe HTTPS.

The Resolution: Update Your web.config

To stop your global HTTPS redirect rule from hijacking Let’s Encrypt validation requests, you need to add an exclusion condition directly into your <rewrite> rules.

Open the web.config file located in your website's root directory and locate your existing canonical HTTPS redirect rule. You need to insert an extra <add input="..." /> condition that explicitly tells IIS to stand down if the URL contains .well-known.

Copy and Paste This Rule:

 
<configuration>
  <system.webServer>
    <rewrite>
      <rules>
        <rule name="Force HTTPS - Ignore ACME Challenge" stopProcessing="true">
          <match url="(.*)" />
          <conditions>
            <add input="{HTTPS}" pattern="off" ignoreCase="true" />
            
            <add input="{REQUEST_URI}" pattern="^/\.well-known/acme-challenge/.*" negate="true" />
          </conditions>
          <action type="Redirect" url="https://{HTTP_HOST}/{R:1}" redirectType="Permanent" />
        </rule>
      </rules>
    </rewrite>
  </system.webServer>
</configuration>

How It Works

  • negate="true": This attribute is the magic switch. It tells IIS that the redirect rule should only trigger if the requested URL does not match the pattern specified.

  • pattern="^/\.well-known/acme-challenge/.*": This targets the exact, hardcoded directory path that Let’s Encrypt’s automated verification bots request.

  • The Result: Standard visitors trying to hit http://yourdomain.com are safely redirected to https://yourdomain.com. Meanwhile, the Let's Encrypt validation bot hitting http://yourdomain.com/.well-known/acme-challenge/ bypasses the redirect completely, successfully reads the challenge token, and issues your new SSL certificate automatically.

 


Was this answer helpful?

Still need help?

Our friendly support team are ready to offer assistance with any issues you may be encountering.
Click the button below to open a ticket:
Open Ticket

 WordPress Hosting

Fast hosting for WordPress
Experience the best in Australian WordPress hosting with lightning fast servers, built-in caching, and performance tools.

 Build Your Website

Sitejet Hosting
Build your site fast with a drag and drop editor with no coding required. 140+ quality, templates to get you started.

 Register Domains

It all starts with your domain name
Find the perfect domain and register now with our competitive pricing on all extensions.

 Web Hosting

Fast, local, secure hosting
Full featured hosting on cPanel with multiple server locations around the country.
« Back