An SSL certificate chain is the path your browser follows to verify that a website is legitimate

When you visit a website with a padlock icon in your address bar, your browser is checking a chain of certificates — not just one. The website presents a certificate with its name on it, but your browser doesn't automatically trust that certificate. Instead, it looks at who signed that certificate, then checks who signed that certificate, and so on, until it reaches a certificate it already knows and trusts. That chain of signatures is the SSL certificate chain.

Think of it like a notary public. If a stranger hands you a document and says "this is real," you don't believe them. But if they show you a document signed by a notary, and you recognize the notary's seal, you trust it. The notary's seal is the trusted root. The certificate chain is the series of signatures that connects the stranger's document back to that seal.

Without a certificate chain, every website would need its own root certificate installed on your computer — millions of them. Instead, a small number of root certificates (about 100 across all browsers) are built in, and they sign intermediate certificates, which sign website certificates. Your browser walks up that chain until it finds a root it recognizes.

Key Takeaways

  • An SSL certificate chain connects a website's certificate back to a trusted root certificate through one or more intermediate certificates.
  • Your browser trusts the chain only if every link is valid and unbroken — a missing or expired intermediate certificate breaks the chain.
  • The root certificate is built into your browser; intermediate certificates are provided by the website's hosting company or certificate authority.
  • A broken chain shows as a security warning in your browser, even if the website's own certificate is valid.
  • Website owners are responsible for configuring their server to send the complete chain, not just their own certificate.

How the chain works: from website to root

When your browser connects to a website, the server sends three things: the website's certificate, one or more intermediate certificates, and a request that you trust them. Your browser then performs a chain verification. It starts at the website's certificate and asks: "Who signed this?" The answer is an intermediate certificate. It then asks: "Who signed the intermediate?" The answer is another intermediate, or a root certificate. When it reaches a root certificate that is already installed in your browser, the chain is complete and verified.

Each certificate in the chain contains a digital signature — a mathematical proof that the previous certificate was signed by the current one. If even one signature is invalid or missing, the chain breaks and your browser shows a security error. The chain is only as strong as its weakest link.

Most chains have two or three links. A typical chain looks like this: website certificate (signed by) → intermediate certificate (signed by) → root certificate (trusted by your browser). Some larger organizations use longer chains with multiple intermediates, but the principle is the same.

Why intermediate certificates exist

Root certificates are kept offline in secure vaults — they almost never sign website certificates directly. Instead, certificate authorities create intermediate certificates and use those to sign website certificates. This separation protects the root. If an intermediate certificate is compromised, the authority can revoke it without affecting the root. If the root were compromised, every certificate it ever signed would become untrustworthy.

Intermediate certificates also allow certificate authorities to delegate signing authority. A large authority might create multiple intermediates, each one signing certificates for different purposes or regions. This spreads the load and adds a layer of security.

When you buy an SSL certificate from a provider like GoDaddy, Namecheap, or Let's Encrypt, you are actually receiving a website certificate and the intermediate certificates needed to complete the chain. Your web server must be configured to send all of them.

What happens when the chain is broken

A broken chain produces a security warning in your browser — usually a message like "This site's security certificate is not trusted" or "NET::ERR_CERT_AUTHORITY_INVALID" in Chrome. This warning appears even if the website's own certificate is valid and not expired. The problem is not the website certificate; it is the chain.

The most common cause is a missing intermediate certificate. The website owner configured their server to send only the website certificate, not the intermediates. The browser can verify the website certificate's signature, but it cannot find the intermediate that signed it, so the chain stops short of the root.

Another cause is an expired intermediate certificate. If an intermediate in the chain has expired, the chain is broken even if the website certificate is still valid. The website owner must update their server configuration to use a new intermediate before the old one expires.

A third cause is a revoked certificate. If a certificate authority revokes an intermediate (usually because it was compromised), browsers will reject any chain that includes it. The website owner must switch to a different intermediate immediately.

How to check your website's certificate chain

If you own a website and want to verify that your certificate chain is complete, you can use an online SSL checker. Visit a site like SSL Labs (ssllabs.com/ssltest), enter your domain name, and run the test. The report will show your certificate chain, list each certificate in order, and flag any problems like missing intermediates or expiration dates.

You can also check the chain in your browser. Click the padlock icon in the address bar, then click "Certificate" or "Connection is secure." Most browsers show a simplified view, but you can usually click through to see the full chain. In Chrome, click "Certificate is valid" to open the certificate viewer. In Firefox, click the arrow next to "Verified by" to see the chain.

If your chain is broken, contact your hosting provider or certificate authority. They can tell you which intermediate certificates your server should be sending and help you configure it correctly. Most hosting control panels (like cPanel or Plesk) have a section for uploading the intermediate certificate bundle.

The difference between chain and certificate validation

Certificate validation and chain validation are related but separate checks. Your browser validates the certificate itself by checking that it matches the domain you are visiting, that it has not expired, and that it was not revoked. It validates the chain by checking that each signature in the chain is mathematically correct and that each certificate in the chain is still valid.

A certificate can be valid but the chain can be broken. For example, a website certificate might be valid and not expired, but if the intermediate that signed it has expired, the chain is broken and the browser will reject it. Conversely, a chain can be complete but the certificate can be invalid — for instance, if the certificate is for example.com but you are visiting example.org, the browser will reject it even if the chain is perfect.

Self-signed certificates and why they break the chain

A self-signed certificate is one that is signed by itself rather than by a certificate authority. It has no chain — it is the root. Browsers do not have self-signed certificates built in, so they cannot verify self-signed certificates. Your browser will show a security warning for any self-signed certificate, no matter how valid it is.

Self-signed certificates are useful for testing and internal networks where you control all the computers. You can manually tell your browser to trust a self-signed certificate. But for public websites, a self-signed certificate is not practical because visitors will see a security warning.

Some people try to fix this by creating a self-signed root certificate and installing it on their computer, then using that root to sign their website certificate. This works on their own computer but not for visitors, who do not have the self-signed root installed. The chain still breaks for them.

Frequently Asked Questions

Can a website have more than one certificate chain?

Yes. A website can have multiple certificates, each with its own chain. A server might have one certificate signed by Let's Encrypt and another signed by DigiCert, for example. The server sends whichever chain the browser requests, based on the browser's supported algorithms and root certificates. Most websites use only one certificate, but larger organizations sometimes maintain multiple chains for redundancy or to support older browsers.

What is a certificate bundle?

A certificate bundle is a file containing the website certificate and all the intermediate certificates needed to complete the chain. When you purchase an SSL certificate, the provider usually sends you a bundle file (often named something like "bundle.crt" or "ca-bundle.crt"). Your web server reads this file and sends the entire chain to browsers. If you upload only the website certificate without the bundle, the chain will be broken.

Do I need to do anything to maintain my certificate chain?

You need to monitor your certificate's expiration date and renew it before it expires. Most certificate providers send reminder emails 30 days before expiration. When you renew, you will receive a new certificate and a new bundle. Upload both to your server before the old certificate expires. If you use a service like Let's Encrypt or your hosting provider's built-in SSL, renewal is usually automatic.

Why does my browser trust some roots but not others?

Each browser maintains its own list of trusted root certificates. Chrome uses the list from your operating system (Windows, Mac, or Linux). Firefox maintains its own list. Safari uses the system list on Mac and iOS. A certificate authority's root might be trusted in Chrome but not in Firefox if Firefox has not added it to its list. This is rare for major certificate authorities but can happen with newer or regional authorities.

Can a website owner see their certificate chain?

Yes. If you have access to your web server, you can view the certificate files directly. On Linux, you can use the command openssl x509 -in certificate.crt -text -noout to view a certificate's details. You can also use an online SSL checker or your hosting provider's control panel. Most hosting companies show the certificate chain in the SSL/TLS section of their dashboard.