Definition · TLS & Certificates

What is Certificate Chain?

A certificate chain (or chain of trust) is the sequence of certificates a client follows to decide whether it trusts a server’s TLS certificate. Each certificate in the chain is signed by the one above it, ending at a root certificate the client already trusts.

Anatomy of a chain

  1. Leaf (end-entity) certificate — issued to the server’s hostname; the certificate presented for example.com
  2. Intermediate certificate(s) — issued by the root CA to an intermediate CA, which in turn signs leaf certificates; roots sign leaves indirectly so their own keys can stay offline
  3. Root certificate — self-signed, distributed in operating system and browser trust stores rather than sent by the server

During the TLS handshake, the server sends the leaf and the intermediates; the client validates each signature up the chain until it reaches a root in its trust store.

Common chain problems

  • Missing intermediates — the most frequent misconfiguration; some browsers recover via cached or fetched intermediates, but many API clients and older devices fail with trust errors
  • Wrong order or duplicate certificates — tolerated by some clients, rejected by others
  • Expired intermediates or roots — a chain is only valid while every certificate in it is valid, as the 2021 expiry of a widely used root demonstrated

Why chains matter for external exposure

An incomplete chain often goes unnoticed because mainstream browsers paper over it, while customer integrations and mobile apps fail intermittently. SurfaceLoop validates the full chain served by each HTTPS endpoint as part of its TLS and certificate checks.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.