Free SSL Tool

SSL/TLS Certificate Chain Checker

Verify your full certificate chain — leaf, intermediates, and root — detect missing intermediates (the #1 cause of SSL errors on mobile and curl), check expiry of every cert, and identify chain ordering issues.

  • ✔ Full chain verification
  • ✔ Missing intermediate detection
  • ✔ Per-cert expiry & key info
  • ✔ Chain ordering check
  • ✔ SHA1/weak key detection
  • ✔ Custom port support
Leaf Certificate example.com · expires 90d ↓ Intermediate CA Let's Encrypt R11 · 2027 ↓ Root CA ISRG Root X1 · 2035 ✔ Chain valid ✘ Missing inter.

Why Chain Checking Matters


A TLS certificate doesn't work alone — browsers trust it because it links back to a root CA they already trust, via one or more intermediate certificates. When a server doesn't send those intermediates, the browser can still work (Chrome caches them), but curl, API clients, mobile apps, and many server-to-server requests fail with an SSL verification error, even though your certificate is perfectly valid.
This tool checks the actual chain your server presents during a real TLS handshake — not just whether a certificate exists — so you can spot missing intermediates, ordering issues, expiring certs in the chain, and weak key types before they cause production outages.

How It Works

1. Enter a Domain

Enter any domain and optional port (default 443).

2. Real TLS Handshake

Our server connects to yours and captures the full certificate chain as presented.

3. Full Analysis

Every certificate is inspected — expiry, key type, issuer chain, ordering.

4. Issues Listed

Problems are listed clearly with explanations and next steps.

Port defaults to 443. Change for non-standard HTTPS ports (e.g. 8443).
Common Issues

What This Checker Looks For

Missing Intermediates

The most common SSL issue — server sends the leaf cert but not the intermediates needed to build trust to the root CA. Chrome works (it caches them), curl and mobile apps fail.

Wrong Chain Order

Certificates must be sent leaf-first, root-last. Some servers send them in reverse order, which causes failures in strict TLS clients.

Expiring Certificates

Not just the leaf — intermediate CAs expire too (Let's Encrypt's ISRG Root X1 and R3 transitions affected millions of sites in 2021).

Weak Keys & Algorithms

RSA keys under 2048 bits and SHA-1 signatures are deprecated and rejected by modern browsers and TLS clients.

FAQsSSL/TLS Certificate Chain Checker

Why does my SSL work in Chrome but fail in curl or on mobile?

Chrome caches intermediate certificates proactively. Most other TLS clients don't — they rely entirely on the server sending the complete chain. If intermediates are missing, curl and API clients reject the connection even though Chrome works fine.

How do I fix a missing intermediate certificate?

Download the intermediate bundle from your CA, then configure Apache (SSLCertificateChainFile) or Nginx (ssl_certificate with concatenated bundle) to serve it alongside your leaf certificate.

Should the root CA be included in my server's chain?

No. Root CAs are pre-installed in trust stores. The correct server chain is leaf + intermediates only. Including the root wastes bandwidth and is ignored by clients.

24/7 Support Available:

Our support team is here to assist you around the clock. Get Expert Help, Anytime.