What is SSL Certificate Chain?
SSL security is based on a chain of trust. Every SSL certificate becomes trusted with the signature of a higher authority:
Root CA Certificate → Intermediate Certificate(s) → Site Certificate
Browsers only trust built-in root CA certificates. Every link in the chain from the site certificate to the root must be verifiable. If any link is missing or broken, a certificate chain error occurs.
Common Certificate Chain Errors
1. Incomplete Chain
The most common chain error. Only the site certificate is installed on the server, intermediate certificate(s) are missing.
Symptoms
- It works in Chrome but gives an error in Firefox (Chrome can download the missing certificate with AIA support, Firefox cannot)
- It works on desktop but gives an error on mobile
- SSL Labs test shows "Chain issues: Incomplete"
Solution
# Download intermediate certificate and create fullchain
cat your_domain.crt intermediate.crt > fullchain.pem
#nginx
ssl_certificate /etc/ssl/fullchain.pem;
ssl_certificate_key /etc/ssl/private.key;
#Apache
SSLCertificateFile /etc/ssl/your_domain.crt
SSLCertificateChainFile /etc/ssl/intermediate.crt
2. Wrong Order
If the order of merging the certificate files is incorrect, problems may occur on some platforms.
Correct Order
- Site certificate (leaf / end-entity)
- Intermediate certificate 1 (signing the site certificate)
- Intermediate certificate 2 (if applicable — signer of intermediate certificate 1)
- Root certificate not added (browser built in)
# Check order
openssl s_client -connect domain.com:443 -showcerts 2>/dev/null | grep "s:" | head -10
# Sort in output:
# s:CN = yourdomain.com (site cert)
# s:CN = Sectigo RSA Domain Validation Secure Server CA (intermediate)
# ...must be in the correct order
3. Expired Intermediate (Expired Intermediate Certificate)
Even if your site certificate is valid, the intermediate certificate may have expired. In this case, the chain cannot be verified.
Solution
# Check intermediate certificate date
openssl x509 -in intermediate.crt -noout -dates
# Download updated intermediate certificate from your CA if expired
# Sectigo: https://support.sectigo.com/articles/Knowledge/Sectigo-Intermediate-Certificates
# DigiCert: https://www.digicert.com/kb/digicert-root-certificates.htm
4. Cross-Signed Chain Problems
Some CAs (especially Let's Encrypt) use cross-signed chains for legacy device compatibility. There may be incompatibilities during the transition to the new root.
Let's Encrypt Example
- Long chain: DST Root CA X3 → ISRG Root X1 → Intermediate → Site Cert (cross-sign for legacy Android support; this cross-signature expired in 2024 and is no longer used)
- Short chain: ISRG Root X1 → Intermediate → Site Cert (the chain in use today)
- Certbot selects the correct chain by default; if the CA offers more than one chain, a preference can be set with
--preferred-chain
Certificate Chain Testing Tools
| Tool | Feature | Access |
|---|---|---|
| SSL Labs | Comprehensive chain analysis, chain issues report | ssllabs.com/ssltest |
| DATASSL SSL Checker | Fast certificate chain check | datassl.com/ssl-checker |
| whatsmychaincert.com | Automatic detection of missing intermediate certificates and bundle creation | whatsmychaincert.com |
| OpenSSL CLI | Detailed certificate chain inspection | Command line |
Certificate Chain Verification Commands
# Show all certificates returned from the server
openssl s_client -connect domain.com:443 -showcerts
# Information for each certificate in the chain
openssl s_client -connect domain.com:443 -showcerts 2>/dev/null | \
awk '/BEGIN/{cert=""} {cert=cert$0"\n"} /END/{print cert | "openssl x509 -noout -subject -issuer -dates"}'
# Verify chain
openssl verify -CAfile ca-bundle.crt -untrusted intermediate.crt site.crt
Conclusion
Certificate chain errors are one of the most common sources of SSL problems. Installing the correct intermediate certificates in the correct order — such a simple step — solves the vast majority of problems. With whatsmychaincert.com, you can automatically detect missing certificates and verify your configuration with SSL Labs.