SSL & Security

Certificate Chain Checker

Chain Order

Check a Certificate Chain

Paste your certificate bundle, or enter a hostname to fetch and verify the chain a live server presents.
https://
:

Builds the certificate path from the leaf up through each intermediate to a trusted root — verifying issuer links, validity dates and signature strength at every level.

Certificates are public — nothing is stored, and private keys are never used

Tool features

Verify, reorder and repair SSL certificate chains
4 checks

Live host or pasted bundle

Fetch the chain a server actually presents on any port, or paste a PEM bundle before you deploy it.

Order detection

Arranges certificates leaf → intermediate → root and flags anything sent out of order.

Missing-intermediate check

Spots gaps in the chain that break Android, Java, curl and API clients even when Chrome looks fine.

Corrected bundle

Copy or download a correctly-ordered bundle with the self-signed root left out, ready to install.

What is a certificate chain & how it works

How clients build trust from your certificate to a root

An SSL certificate chain links your domain's certificate to a root certificate that browsers and operating systems already trust. Your server has to send the leaf certificate plus every intermediate in between, so a client can walk the signatures up to a root it recognises.

If an intermediate is missing or the certificates arrive in the wrong order, strict clients reject the connection even though the certificate itself is valid. This tool reads the chain, checks each issuer/subject link and expiry, and rebuilds a bundle in the order servers expect.

Leaf
The end-entity certificate issued for your domain; always first in the bundle.
Intermediate
CA certificates that bridge the leaf to the root; the server must send them.
Root
The self-signed trust anchor built into clients; normally left out of the bundle.

How to use this tool

Diagnose and fix chain issues in four steps
1
Provide the chain
Paste your full PEM bundle (leaf + intermediates), or enter a hostname to fetch the chain a live server presents.
2
Check the order
The tool arranges certificates leaf → intermediate → root and flags anything out of order.
3
Fix the gaps
Missing-intermediate, expired, and unrelated-certificate problems are called out with how to fix them.
4
Deploy the bundle
Copy or download the corrected, correctly-ordered bundle and install it on your server.

Frequently asked questions

Common questions about SSL certificate chains
5 Q&A

Chrome and some browsers cache intermediate certificates they've seen before, so they can complete a chain your server doesn't send. Android, Java, curl, and many API clients do not — they fail if the intermediate is missing. That's why a chain can look fine in one place and broken in another. Always send the full chain (leaf + intermediates).

Leaf (your domain) first, then each intermediate, ending just before the root. Most servers (Nginx, Apache, HAProxy) require this exact order in the bundle. The root certificate should normally be omitted — clients already trust it.

No. Clients ship with trusted root certificates, so sending the root just adds bytes to the handshake. Send the leaf and intermediates only. This tool's corrected bundle excludes a self-signed root automatically.

The leaf (or end-entity) certificate is issued for your domain. Intermediates are issued by the root to the leaf, forming a chain of trust. The root is the self-signed certificate at the top that clients trust directly. Verification walks leaf → intermediate → root.

No. Pasted certificates are analyzed in server memory and discarded immediately. Host checks open a standard TLS connection to read the presented chain and nothing is logged or retained. Certificates are public information; private keys are never involved.