📜 Certificate Chain Viewer
View the complete SSL certificate chain for any domain, including issuer details, validity dates, and certificate hierarchy.
What the chain is, and what the count means
Our server opens a live TLS connection to the domain you type and reports the certificates that site actually sent. A chain runs from your certificate up to a root the client already trusts:
leaf CN=example.com signed by
intermediate CN=R11, O=Let's Encrypt signed by
root CN=ISRG Root X1 in the client's trust store
Two certificates is the normal count: a leaf and one intermediate. The root is not meant to be sent - the client has its own copy, and shipping it only adds bytes to every handshake. A count of one usually means the intermediate is missing from your bundle.
What to look at
- The leaf's expiry. That is the date that matters. An intermediate or root expiring in 2035 tells you nothing about renewal.
- The names on the leaf. Browsers match the hostname against the subject alternative names only; a certificate whose common name is right but whose SAN list omits the host is rejected.
- A missing intermediate. Chrome and Firefox paper over it by
fetching the issuer themselves, so the site looks fine while
curl, Java clients and older mobile apps fail outright.
Frequently asked questions
Why does my certificate work in Chrome but fail with curl?
Almost always a missing intermediate. Browsers follow the authority information access pointer in the leaf and download the issuer, while most command-line and library clients do not, so they cannot build a path to a trusted root.
Do I need to install the root certificate on my server?
No. Roots come from the client's own trust store. Serving one is harmless but pointless, and it will show as an extra certificate in the chain here.
What order do certificates go in the bundle file?
Leaf first, then each issuer in turn, ending with the last intermediate.
Nginx wants them concatenated into the single file named by
ssl_certificate; Apache takes the same order in
SSLCertificateChainFile or appended to the certificate file.