Fix an incomplete certificate chain
Why a certificate that works in your browser fails elsewhere, and how to install the intermediate certificates the server is missing.
By the Domain Health Hub team · Updated
- A server must send its own certificate plus the intermediate certificates that link it to a trusted root.
- Desktop browsers often hide a missing intermediate; phones, apps, payment providers and scripts don't.
- Install the full chain file from the certificate provider, or switch to your host's automated certificates.
What this means
Browsers trust a small set of root certificates. Your certificate is signed by an intermediate certificate, which is signed by a root. The server has to send its own certificate and the intermediates, so the client can build the chain back to a root it trusts. We connected to the site and couldn't build a valid chain: usually an intermediate is missing, out of date or in the wrong order.
Why it matters
This fault hides well. Desktop browsers may already hold the intermediate from another site, or fetch it themselves from the address in the certificate, so the person who set up the site sees a padlock. Older phones, apps, other servers, payment providers sending callbacks and command-line tools don't, and they refuse to connect. The result is intermittent failures that are hard to reproduce.
How to confirm it
Test the site with a tool that doesn't fill gaps itself. From a terminal, openssl s_client -connect example.com:443 -servername example.com lists the certificates the server sent; a working chain shows more than one.
How to fix it
Certificate providers supply the intermediates as a “CA bundle” or a “full chain” file. The server must send your certificate first, then the intermediates.
- cPanel
- In SSL/TLS, Manage SSL sites, paste the CA bundle into the Certificate Authority Bundle box, or let AutoSSL replace the certificate.
- Nginx
- Point ssl_certificate at the full chain file (for Certbot, fullchain.pem, not cert.pem) and reload.
- Apache 2.4.8+
- Point SSLCertificateFile at the full chain file and reload. Older versions use SSLCertificateChainFile for the intermediates.
- Cloudflare
- Proxied visitors get Cloudflare's own complete chain. If the fault shows on a DNS-only name, fix the origin server.
-----BEGIN CERTIFICATE----- (your certificate) -----END CERTIFICATE----- -----BEGIN CERTIFICATE----- (intermediate) -----END CERTIFICATE-----
If the certificate was bought years ago, the simplest fix is often to switch to the host's free automated certificates, which install the chain correctly and renew themselves. Domain Health Hub checks the chain daily, so a renewal that installs the wrong file is caught the next day.
Questions
It works in my browser. Is this a real problem?
Yes. Some browsers fetch or remember missing intermediates, so they hide the fault. Other clients, including many apps, payment callbacks and monitoring tools, reject the connection.
Should I include the root certificate in the chain?
There's no need. Clients already hold the trusted roots. Sending your certificate followed by the intermediates is enough.
Hear about it the day it breaks.
Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.