HomeOnline Tools › CA Chain Matcher
Free SSL tool

CA Chain Matcher

Enter a domain name to fetch and verify its live SSL certificate chain. A broken chain is one of the most common causes of browser SSL warnings even after a successful installation.

How to verify your SSL certificate chain

  1. Paste your certificate — Copy the full PEM-encoded certificate (including -----BEGIN CERTIFICATE----- and -----END CERTIFICATE-----) into the tool.
  2. Optionally paste intermediates — If you have intermediate (CA bundle) certificates, paste them in the second field to test the complete chain.
  3. Run the check — The tool verifies that the root, intermediates and leaf certificate are in the correct order and that each signature is valid.
  4. Fix any gaps — If the chain is broken, download the correct intermediate from your CA's website (usually listed in the AIA extension) and reinstall.

Frequently asked questions

What is a certificate chain?

An SSL certificate is not trusted on its own — browsers trust it by following a chain: your leaf certificate → one or more intermediate CAs → a root CA that is embedded in the browser or operating system. If any link is missing, browsers show a warning.

Why is my chain failing even though the certificate is valid?

The most common reason is a missing intermediate certificate. Many servers only serve the leaf certificate and omit the intermediate. You need to install the full chain file provided by your CA.

What is the difference between a root and an intermediate CA?

Root CAs are self-signed and embedded in browsers. Intermediates are signed by roots and used for day-to-day issuance. Using intermediates protects root keys — if an intermediate is compromised, it can be revoked without replacing the root.

Need a new certificate?

Browse all SSL certificate types and find the right one for your site.

Take the SSL wizard →