Certificate trust · Practical guide

SSL certificate chain errors: what to investigate

A certificate chain connects a site’s certificate to an authority a client trusts. An incomplete chain is one possible cause of failed verification, but an expiry, name mismatch or trust-store difference can produce a similar symptom. Use the available evidence to narrow the problem before replacing files.

Understand the parts of the chain

The leaf certificate identifies the site. Intermediate certificates link that certificate to a root trusted by the client. Let’s Encrypt publishes its certificate hierarchies and available chains; the relevant chain depends on the certificate you were issued.

A server normally supplies the leaf and required intermediate certificates. A trusted root need not appear among the certificates the server sends. Counting the received certificates therefore cannot establish whether a connection is trusted.

Reference: Let’s Encrypt: Chains of Trust

Separate evidence from a diagnosis

CheckSSL reports whether verification succeeded and lists received certificates when available. If verification fails, it may collect diagnostic details. Those details are useful for investigation, but they do not make the chain or hostname trusted.

The tool does not isolate every chain error. An unknown chain finding should not be rewritten as a confirmed missing intermediate. First inspect the date and hostname findings, then compare the observed certificate with the configuration you intended to deploy.

Review the certificate bundle at the public endpoint

Use the chain supplied for your certificate by your certificate authority or managed hosting provider. Check the format expected by the TLS listener, including whether it expects a full-chain file or separately configured intermediates. Avoid assembling a bundle from unrelated downloaded certificates.

If the result differs between endpoints, review where TLS terminates and which configuration each endpoint uses. The scan reflects the address and trust environment reached during that check. It does not prove identical behavior across every browser, region or backend.

Confirm the fix with verification enabled

Disabling certificate verification can expose diagnostic information, but it does not resolve a trust problem. Use a successfully verified connection as the completion criterion.

  1. Record the hostname, verification outcome and received certificate details.
  2. Rule out obvious expiry and hostname problems before assuming a missing intermediate.
  3. Check the bundle and certificate assignment against your hosting provider’s instructions.
  4. Retest the public endpoint and confirm that trust and hostname verification pass.

Keep reading

Related guides