📜 Certificate Chain Viewer

View the complete SSL certificate chain for any domain, including issuer details, validity dates, and certificate hierarchy.

💡 Tip: Enter a domain and click "View Certificate Chain" to see all certificates.
Enter a domain and click "View Certificate Chain" to view results.

What the chain is, and what the count means

Our server opens a live TLS connection to the domain you type and reports the certificates that site actually sent. A chain runs from your certificate up to a root the client already trusts:

leaf         CN=example.com          signed by
intermediate CN=R11, O=Let's Encrypt   signed by
root         CN=ISRG Root X1           in the client's trust store

Two certificates is the normal count: a leaf and one intermediate. The root is not meant to be sent - the client has its own copy, and shipping it only adds bytes to every handshake. A count of one usually means the intermediate is missing from your bundle.

What to look at

You see what the public internet sees. If the domain is behind a CDN or load balancer, that is its certificate - not the one on your origin server.

Frequently asked questions

Why does my certificate work in Chrome but fail with curl?

Almost always a missing intermediate. Browsers follow the authority information access pointer in the leaf and download the issuer, while most command-line and library clients do not, so they cannot build a path to a trusted root.

Do I need to install the root certificate on my server?

No. Roots come from the client's own trust store. Serving one is harmless but pointless, and it will show as an extra certificate in the chain here.

What order do certificates go in the bundle file?

Leaf first, then each issuer in turn, ending with the last intermediate. Nginx wants them concatenated into the single file named by ssl_certificate; Apache takes the same order in SSLCertificateChainFile or appended to the certificate file.