Definition · TLS & Certificates
What is Certificate Chain?
A certificate chain (or chain of trust) is the sequence of certificates a client follows to decide whether it trusts a server’s TLS certificate. Each certificate in the chain is signed by the one above it, ending at a root certificate the client already trusts.
Anatomy of a chain
- Leaf (end-entity) certificate — issued to the server’s hostname; the certificate presented for
example.com - Intermediate certificate(s) — issued by the root CA to an intermediate CA, which in turn signs leaf certificates; roots sign leaves indirectly so their own keys can stay offline
- Root certificate — self-signed, distributed in operating system and browser trust stores rather than sent by the server
During the TLS handshake, the server sends the leaf and the intermediates; the client validates each signature up the chain until it reaches a root in its trust store.
Common chain problems
- Missing intermediates — the most frequent misconfiguration; some browsers recover via cached or fetched intermediates, but many API clients and older devices fail with trust errors
- Wrong order or duplicate certificates — tolerated by some clients, rejected by others
- Expired intermediates or roots — a chain is only valid while every certificate in it is valid, as the 2021 expiry of a widely used root demonstrated
Why chains matter for external exposure
An incomplete chain often goes unnoticed because mainstream browsers paper over it, while customer integrations and mobile apps fail intermittently. SurfaceLoop validates the full chain served by each HTTPS endpoint as part of its TLS and certificate checks.