Chrome caches intermediate certificates proactively. Most other TLS clients don't — they rely entirely on the server sending the complete chain. If intermediates are missing, curl and API clients reject the connection even though Chrome works fine.
Verify your full certificate chain — leaf, intermediates, and root — detect missing intermediates (the #1 cause of SSL errors on mobile and curl), check expiry of every cert, and identify chain ordering issues.
Enter any domain and optional port (default 443).
Our server connects to yours and captures the full certificate chain as presented.
Every certificate is inspected — expiry, key type, issuer chain, ordering.
Problems are listed clearly with explanations and next steps.
The most common SSL issue — server sends the leaf cert but not the intermediates needed to build trust to the root CA. Chrome works (it caches them), curl and mobile apps fail.
Certificates must be sent leaf-first, root-last. Some servers send them in reverse order, which causes failures in strict TLS clients.
Not just the leaf — intermediate CAs expire too (Let's Encrypt's ISRG Root X1 and R3 transitions affected millions of sites in 2021).
RSA keys under 2048 bits and SHA-1 signatures are deprecated and rejected by modern browsers and TLS clients.
Chrome caches intermediate certificates proactively. Most other TLS clients don't — they rely entirely on the server sending the complete chain. If intermediates are missing, curl and API clients reject the connection even though Chrome works fine.
Download the intermediate bundle from your CA, then configure Apache (SSLCertificateChainFile) or Nginx (ssl_certificate with concatenated bundle) to serve it alongside your leaf certificate.
No. Root CAs are pre-installed in trust stores. The correct server chain is leaf + intermediates only. Including the root wastes bandwidth and is ignored by clients.