Incomplete Certificate Chain: The Missing Intermediate Fix
· CSR.plus Team

- •A chain error almost always means the server sends the leaf certificate without the intermediate that browsers need to verify it.
- •The fix is a single concatenated file: leaf + intermediate(s) in the correct order.
- •Verify with ssls labs-style checks and the same openssl command your visitors will trigger.
Why the chain breaks
Browsers trust a certificate because they trust its root. Your leaf certificate is signed by an intermediate that is not in the browser’s trust store, so the server must send it during the handshake. If the server config only points to the leaf, or the concatenated file has the wrong order, clients that do not cache the intermediate fail with "incomplete chain", "unable to get local issuer certificate" or NET::ERR_CERT_AUTHORITY_INVALID.
How to fix it on Nginx and Apache
Download the full chain bundle from your CA (or from the intermediate endpoint in the certificate’s Authority Information Access extension). Concatenate: cat yourdomain.com.crt intermediate.crt root.crt > fullchain.crt — leaf first, then intermediates in order, root last. In Nginx point ssl_certificate to the fullchain file; in Apache set SSLCertificateChainFile (or include the chain in SSLCertificateFile). Then reload.
Verify the fix
Run openssl s_client -connect yourdomain.com:443 -servername yourdomain.com -showcerts 2>&1 | grep -A1 "Certificate chain". You should see the leaf followed by the intermediate. openssl verify -CAfile root.pem fullchain.crt should print "fullchain.crt: OK". Retest from a clean browser profile and with an external chain checker.
FAQ
Why does it work in some browsers and not others?
Clients that recently fetched the intermediate from a CT log or cache can verify the chain without it; others cannot. The fix is the same: send the full chain.
Does a CDN hide this problem?
No — a CDN terminates TLS with its own certificate. If you upload only the leaf to the CDN, it forwards the same broken chain to visitors.
UptimeRobot
Monitor your SSL & uptime for free
UptimeRobot watches your certificates and endpoints 24/7 — 50 monitors on the free plan.
Affiliate link — we may earn a commission at no extra cost to you.
Free SSL/TLS tools
Verify and inspect your certificates in seconds.