Skip to main content
DigiCert, Sectigo and GeoTrust SSL certificates
+90 850 259 76 06 WhatsApp Support Become a Reseller
SSL Certificates
Brands
Code Signing LEI Code
Tools
Support Contact WhatsApp Cart
Language
Currency
Get an SSL Certificate
SSL Security

SSL Certificate Chain Errors: Incomplete Chain and Solution

SSL certificate chain errors: Detection and solution of Incomplete chain, wrong order, expired intermediate problems.

10 min read

What is SSL Certificate Chain?

SSL security is based on a chain of trust. Every SSL certificate becomes trusted with the signature of a higher authority:

Root CA Certificate → Intermediate Certificate(s) → Site Certificate

Browsers only trust built-in root CA certificates. Every link in the chain from the site certificate to the root must be verifiable. If any link is missing or broken, a certificate chain error occurs.

Common Certificate Chain Errors

1. Incomplete Chain

The most common chain error. Only the site certificate is installed on the server, intermediate certificate(s) are missing.

Symptoms

  • It works in Chrome but gives an error in Firefox (Chrome can download the missing certificate with AIA support, Firefox cannot)
  • It works on desktop but gives an error on mobile
  • SSL Labs test shows "Chain issues: Incomplete"

Solution

# Download intermediate certificate and create fullchain
cat your_domain.crt intermediate.crt > fullchain.pem

#nginx
ssl_certificate /etc/ssl/fullchain.pem;
ssl_certificate_key /etc/ssl/private.key;

#Apache
SSLCertificateFile /etc/ssl/your_domain.crt
SSLCertificateChainFile /etc/ssl/intermediate.crt

2. Wrong Order

If the order of merging the certificate files is incorrect, problems may occur on some platforms.

Correct Order

  1. Site certificate (leaf / end-entity)
  2. Intermediate certificate 1 (signing the site certificate)
  3. Intermediate certificate 2 (if applicable — signer of intermediate certificate 1)
  4. Root certificate not added (browser built in)
# Check order
openssl s_client -connect domain.com:443 -showcerts 2>/dev/null | grep "s:" | head -10

# Sort in output:
# s:CN = yourdomain.com (site cert)
# s:CN = Sectigo RSA Domain Validation Secure Server CA (intermediate)
# ...must be in the correct order

3. Expired Intermediate (Expired Intermediate Certificate)

Even if your site certificate is valid, the intermediate certificate may have expired. In this case, the chain cannot be verified.

Solution

# Check intermediate certificate date
openssl x509 -in intermediate.crt -noout -dates

# Download updated intermediate certificate from your CA if expired
# Sectigo: https://support.sectigo.com/articles/Knowledge/Sectigo-Intermediate-Certificates
# DigiCert: https://www.digicert.com/kb/digicert-root-certificates.htm

4. Cross-Signed Chain Problems

Some CAs (especially Let's Encrypt) use cross-signed chains for legacy device compatibility. There may be incompatibilities during the transition to the new root.

Let's Encrypt Example

  • Long chain: DST Root CA X3 → ISRG Root X1 → Intermediate → Site Cert (cross-sign for legacy Android support; this cross-signature expired in 2024 and is no longer used)
  • Short chain: ISRG Root X1 → Intermediate → Site Cert (the chain in use today)
  • Certbot selects the correct chain by default; if the CA offers more than one chain, a preference can be set with --preferred-chain

Certificate Chain Testing Tools

ToolFeatureAccess
SSL LabsComprehensive chain analysis, chain issues reportssllabs.com/ssltest
DATASSL SSL CheckerFast certificate chain checkdatassl.com/ssl-checker
whatsmychaincert.comAutomatic detection of missing intermediate certificates and bundle creationwhatsmychaincert.com
OpenSSL CLIDetailed certificate chain inspectionCommand line

Certificate Chain Verification Commands

# Show all certificates returned from the server
openssl s_client -connect domain.com:443 -showcerts

# Information for each certificate in the chain
openssl s_client -connect domain.com:443 -showcerts 2>/dev/null | \
  awk '/BEGIN/{cert=""} {cert=cert$0"\n"} /END/{print cert | "openssl x509 -noout -subject -issuer -dates"}'

# Verify chain
openssl verify -CAfile ca-bundle.crt -untrusted intermediate.crt site.crt

Conclusion

Certificate chain errors are one of the most common sources of SSL problems. Installing the correct intermediate certificates in the correct order — such a simple step — solves the vast majority of problems. With whatsmychaincert.com, you can automatically detect missing certificates and verify your configuration with SSL Labs.

Share this post
Ali Yiğit
Yazar

Ali Yiğit

Recommended SSL Certificates

All Products
EV DigiCert

DigiCert Basic EV SSL

Extended validation with DigiCert Basic EV SSL. The organization name appears in the certificate det

18,782.67 ₺ /yr
Details
EV DigiCert

DigiCert EV Multi-Domain

Protect multiple domains with extended validation using DigiCert EV Multi-Domain. 250 SANs, $1,500,0

37,726.70 ₺ /yr
Details
EV DigiCert

DigiCert Secure Site EV

Extended validation with DigiCert Secure Site EV. DigiCert Smart Seal, vulnerability assessment, mal

48,873.22 ₺ /yr
Details