XiaTools

How to Fix SSL Certificate Chain Errors on Apache and Nginx

Updated 09 Oct 2026

SSL certificate chain errors happen when a web browser cannot verify the complete path of trust from your website's SSL certificate up to a trusted root Certificate Authority (CA). When visitors hit your site, browsers like Chrome or Firefox will throw security warnings such as ERR_CERT_AUTHORITY_INVALID or NET::ERR_CERT_COMMON_NAME_INVALID because intermediate certificates are missing from your web server configuration. Fixing this requires bundling your leaf certificate with the correct intermediate certificates in the proper order and serving them correctly.

Understanding the SSL Certificate Chain

An SSL/TLS certificate chain consists of three distinct layers designed to provide security and administrative flexibility:

  1. Root Certificate: Owned and heavily secured by trusted CAs (like DigiCert, Let's Encrypt, or Sectigo). This certificate is pre-loaded into the operating system and browser trust stores.
  2. Intermediate Certificate(s): Issued by the root CA to sign end-user certificates. These act as a buffer so the root key can stay safely offline.
  3. Leaf/End-Entity Certificate: The specific SSL certificate issued for your domain, such as example.com.

Browsers do not blindly trust your leaf certificate. They look for the intermediate certificates to bridge the gap back to the root. If your web server only serves the leaf certificate, clients fail to establish the chain of trust and display an error.

Before making any server configuration changes, you should verify your current deployment using the SSL Checker to instantly diagnose missing intermediates, expired certificates, and incorrect trust paths.

How to Verify Your Certificate Chain

Command-line tools are invaluable for inspecting what your web server is actually presenting to the outside world. Here is how to use OpenSSL and other utilities to audit your certificate chain.

Using OpenSSL Client

Run the following command in your terminal to connect to your secure port and print the certificate chain:

openssl s_client -connect example.com:443 -servername example.com

Examine the output for lines starting with Certificate chain. A healthy chain will show multiple certificates:

Certificate chain
 0 s:CN = example.com
   i:C = US, O = Let's Encrypt, CN = R3
 1 s:C = US, O = Let's Encrypt, CN = R3
   i:C = US, O = Internet Security Research Group, CN = ISRG Root X1

If you only see certificate index 0, your server is misconfigured and failing to serve the intermediate certificate.

Using cURL for Quick Verification

You can also use curl to check if the TLS handshake completes successfully against your domain using documentation IPs (such as 192.0.2.1 via local host file mapping) or public endpoints:

curl -Iv https://example.com

If the chain is broken, curl will return an error such as SSL certificate problem: unable to get local issuer certificate.

Fixing SSL Chain Errors on Nginx

Nginx requires the intermediate certificate(s) to be explicitly appended to your domain's certificate file. Serving only the primary certificate file will break the chain.

Step 1: Prepare the Combined Certificate File

Locate your primary certificate (often named yourdomain.crt or cert.pem) and your intermediate certificate (often named intermediate.crt or chain.pem). Combine them into a single file using the terminal:

cat yourdomain.crt intermediate.crt > bundled.crt

Crucial Ordering Rule: The leaf/domain certificate must come before the intermediate certificate in this file. If you invert them, Nginx will throw a configuration or handshake error.

Step 2: Update Nginx Configuration

Open your Nginx server block configuration file (typically located in /etc/nginx/sites-available/ or /etc/nginx/conf.d/) and update the ssl_certificate directive to point to your new combined file:

server {
    listen 443 ssl;
    server_name example.com www.example.com;

    ssl_certificate /etc/ssl/certs/bundled.crt;
    ssl_certificate_key /etc/ssl/private/example.key;

    # Modern SSL configuration parameters
    ssl_protocols TLSv1.2 TLSv1.3;
    ssl_ciphers HIGH:!aNULL:!MD5;

    location / {
        root /var/www/html;
        index index.html index.htm;
    }
}

Step 3: Test and Reload Nginx

Validate your syntax to prevent downtime, then reload the service:

sudo nginx -t
sudo systemctl reload nginx

Fixing SSL Chain Errors on Apache

Apache handles certificate chains using distinct directives for the certificate, private key, and intermediate chain file.

Step 1: Place Certificate Files on Server

Upload your files to your Apache security directory (commonly /etc/ssl/certs/ and /etc/ssl/private/). Make sure your file permissions are locked down (e.g., chmod 600 for private keys).

Step 2: Update Apache Virtual Host Configuration

Open your SSL virtual host configuration file (frequently found in /etc/apache2/sites-available/default-ssl.conf or inside /etc/httpd/conf.d/). Configure the directives based on your Apache version.

For Apache 2.4.8 and newer:

<VirtualHost *:443>
    ServerName example.com
    ServerAlias www.example.com

    SSLEngine on
    SSLCertificateFile /etc/ssl/certs/example.crt
    SSLCertificateKeyFile /etc/ssl/private/example.key
    SSLCertificateChainFile /etc/ssl/certs/intermediate.crt
</VirtualHost>

Note for older Apache versions: Versions prior to 2.4.8 used SSLCertificateChainFile. In modern Apache builds, you can alternatively append the intermediate certificate directly to the bottom of SSLCertificateFile and omit the chain directive entirely.

Step 3: Test and Restart Apache

Check for syntax errors and restart the Apache daemon:

sudo apachectl configtest
sudo systemctl restart apache2

Comparison: Apache vs Nginx Certificate Handling

Feature Apache HTTP Server Nginx Web Server
Primary Cert Directive SSLCertificateFile ssl_certificate
Intermediate Handling Separate SSLCertificateChainFile or appended Must be appended into a single bundle file
Reload Command systemctl restart apache2 systemctl reload nginx
Config Test Command apachectl configtest nginx -t

Common Mistakes and How to Fix Them

Even experienced engineers occasionally make configuration errors when deploying TLS. Avoid these frequent pitfalls:

  • Reversed Certificate Order in Bundles: Putting the intermediate certificate above the leaf certificate in Nginx will cause browsers to reject the handshake. Always place the domain certificate first.
  • Using the Wrong Intermediate: Certificate Authorities frequently update their root and intermediate keys. If you renewed your certificate and reused an old intermediate bundle, validation will fail.
  • Incomplete Chain File: Some CAs require both a primary intermediate and a secondary root-cross-signed intermediate. Ensure you download and include all provided intermediate files.
  • Permissions Errors: Web server user accounts (like www-data or nginx) must have read permissions on certificate files, while private keys must be strictly restricted to root.

Quick Troubleshooting Checklist

Use this rapid checklist to ensure your certificate chain is correct:

  1. Download all certificate files (.crt, .ca-bundle) directly from your CA portal.
  2. Confirm file order if bundling (Leaf certificate first, Intermediate(s) following below).
  3. Update the respective Nginx or Apache configuration directives.
  4. Run the local syntax check (nginx -t or apachectl configtest).
  5. Restart or reload your web server software.
  6. Run an external validation check to confirm zero errors are reported.

Frequently asked questions

What is the difference between a root certificate and an intermediate certificate?

A root certificate is self-signed by a Certificate Authority and pre-installed in browser trust stores. Intermediate certificates are issued by the root CA to sign end-user domain certificates, providing an extra layer of security so the root private key can remain offline.

Why do some browsers load my site fine while others show an SSL error?

Certain modern browsers or operating systems cache intermediate certificates from previous visits to other sites. If a browser has cached the required intermediate, it may successfully build the chain even if your server is misconfigured, whereas a fresh browser instance on another device will immediately fail.

How do I know if I need to include multiple intermediate certificates?

You should check the zip file or bundle provided by your Certificate Authority upon certificate issuance. Many modern CAs provide both a primary intermediate and a secondary cross-signed intermediate to support older legacy mobile devices and operating systems.

Can I use wildcard certificates with a multi-level certificate chain?

Yes. Wildcard certificates follow the exact same structural rules for certificate chains as standard single-domain certificates. You must still include the intermediate certificate bundle alongside your wildcard leaf certificate.

What command can I run locally to test my SSL chain without external tools?

You can run 'openssl s_client -connect yourdomain.com:443 -servername yourdomain.com' in your terminal. Look through the output to ensure that more than one certificate is returned in the certificate chain section.

Related articles

Free tools