What Is the SSL Trust Chain and How Does It Work?

· SSL Basics

The SSL trust chain (Chain of Trust) is the hierarchy that determines whether a browser trusts a website's certificate. Understanding it prevents installation errors and helps diagnose trust issues.

Three Layers

1. End-Entity Certificate: The certificate you purchase and install on your server. Contains the domain, validity period, and public key.

2. Intermediate CA: Root CAs don't directly sign end-entity certificates for security reasons. Intermediate CAs handle this, acting as a trusted intermediary.

3. Root CA: Operating systems and browsers ship with a pre-built list of trusted Root CAs ("Trusted Root Certification Authorities" store). If the chain's Root CA is on this list, all certificates in the chain are trusted.

Validation Process

The browser receives the end-entity cert, identifies the signing CA, follows the chain up through Intermediate → Root CA, checks the Root CA against its trusted list, and verifies all signatures and validity dates.

Missing Intermediate Certificate

The most common installation mistake. Chrome sometimes completes the chain from cache; Firefox and older Android are strict and will reject an incomplete chain.

Fix: Install the full chain file (fullchain.pem or ca-bundle.crt) provided by your CA. SSL Labs (ssllabs.com/ssltest) clearly reports chain completeness — aim for "Chain Issues: None."

Visit the PekiSSL product page to find the right certificate for your needs.

All blog posts