If you’ve configured a global HTTP-to-HTTPS rewrite rule in your IIS web.config file, you might have noticed a frustrating side effect: your automated Let’s Encrypt (or Win-ACME) SSL certificate renewals suddenly start failing.
This happens because Let’s Encrypt uses an automated HTTP challenge (HTTP-01). It looks for a specific validation file inside a hidden directory called .well-known/acme-challenge/ over standard, unencrypted HTTP (Port 80). If your global redirect catches that request and forces it over to HTTPS before the certificate is renewed, the verification chain can break, leaving your site unsecured.
At UpTime, we don't believe in sacrificing security for configuration convenience. You can have both. Here is how to update your web.config file to automatically ignore the .well-known folder, allowing your SSL certificates to renew seamlessly while keeping your visitors forced onto safe HTTPS.
The Resolution: Update Your web.config
To stop your global HTTPS redirect rule from hijacking Let’s Encrypt validation requests, you need to add an exclusion condition directly into your <rewrite> rules.
Open the web.config file located in your website's root directory and locate your existing canonical HTTPS redirect rule. You need to insert an extra <add input="..." /> condition that explicitly tells IIS to stand down if the URL contains .well-known.
Copy and Paste This Rule:
<configuration>
<system.webServer>
<rewrite>
<rules>
<rule name="Force HTTPS - Ignore ACME Challenge" stopProcessing="true">
<match url="(.*)" />
<conditions>
<add input="{HTTPS}" pattern="off" ignoreCase="true" />
<add input="{REQUEST_URI}" pattern="^/\.well-known/acme-challenge/.*" negate="true" />
</conditions>
<action type="Redirect" url="https://{HTTP_HOST}/{R:1}" redirectType="Permanent" />
</rule>
</rules>
</rewrite>
</system.webServer>
</configuration>
How It Works
-
negate="true": This attribute is the magic switch. It tells IIS that the redirect rule should only trigger if the requested URL does not match the pattern specified. -
pattern="^/\.well-known/acme-challenge/.*": This targets the exact, hardcoded directory path that Let’s Encrypt’s automated verification bots request. -
The Result: Standard visitors trying to hit
http://yourdomain.comare safely redirected tohttps://yourdomain.com. Meanwhile, the Let's Encrypt validation bot hittinghttp://yourdomain.com/.well-known/acme-challenge/bypasses the redirect completely, successfully reads the challenge token, and issues your new SSL certificate automatically.