IIS blocks ACME challenge path during automated SSL renewal

Sahil Soni 100 Reputation points
2026-10-08T07:27:43.28+00:00

Automated SSL certificate renewal fails with a 403 Forbidden error because IIS blocks requests to the .well-known/acme-challenge/ path. How can we configure IIS request filtering or URL authorization rules to allow ACME challenge requests while keeping the rest of the site secured?

Windows for business | Windows Server | Directory services | Certificates and public key infrastructure (PKI)
0 comments No comments

1 answer

Sort by: Newest
  1. Domic Vo 34,570 Reputation points Independent Advisor
    2026-10-08T08:00:17.8966667+00:00

    Hello,

    The 403 should be addressed by allowing anonymous access only to the ACME challenge path rather than weakening security for the entire site. Create /.well-known/acme-challenge/ and add a web.config there:

    <configuration>
      <system.webServer>
        <security>
          <authorization>
            <clear />
            <add accessType="Allow" users="*" />
          </authorization>
        </security>
      </system.webServer>
    </configuration>
    

    Also verify IIS Request Filtering has not blocked .well-known or acme-challenge as a hidden segment or URL sequence. Do not disable Request Filtering or authentication globally. Test http://yourdomain/.well-known/acme-challenge/<token> and confirm IIS returns 200.

    If it still returns 403, check the IIS log for sc-substatus and sc-win32-status; these will identify the specific authorization or IIS module causing the denial.

    I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!

    DV.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.