Trusted path
Intermediate certificates create a bridge between your website certificate and the trusted root CA.
Paste your SSL certificate in PEM format to find and compose the missing intermediate certificate chain. This tool helps generate a complete fullchain.pem file for web servers, CDN platforms, load balancers, reverse proxies, and SSL/TLS troubleshooting.
Only paste your public certificate. Do not paste your private key. The private key is not required for certificate chain generation.
Paste the public server certificate. The backend reads Authority Information Access and tries to fetch missing intermediate certificates.
Generated fullchain.pem will appear here.
If your SSL certificate is missing intermediate certificates, browsers and SSL checkers may show warnings such as certificate not trusted, incomplete certificate chain, or unable to verify the first certificate. This Certificate Chain Composer helps you paste your public certificate, detect issuer information, fetch the required intermediate certificates, and prepare a complete certificate chain.
To use the tool, copy the contents of your .crt or .pem certificate file and paste it into the input box above. The certificate should start with -----BEGIN CERTIFICATE----- and end with -----END CERTIFICATE-----. After processing, the tool will show decoded certificate details and the complete chain that you can use on your web server, CDN, reverse proxy, load balancer, or firewall SSL inspection device.
A certificate chain is the trust path used by browsers and clients to verify that a website certificate was issued by a trusted Certificate Authority. A normal TLS chain contains the server certificate, one or more intermediate certificates, and a trusted root certificate.
The server certificate is issued for your domain, such as example.com or www.example.com. The intermediate certificate is issued by the root Certificate Authority and is used to sign your server certificate. The root certificate is already trusted by major browsers and operating systems through their trusted root stores.
In most web server installations, you need to install the server certificate and intermediate certificates together. The root certificate usually does not need to be installed on your server because clients already keep trusted root certificates locally.
Intermediate certificates create a bridge between your website certificate and the trusted root CA.
A website can have a valid SSL certificate but still fail if the server sends an incomplete chain during the TLS handshake.
Use the Certificate Checker when you want to inspect a pasted certificate or full chain before installation.
fullchain.pem usually means a combined certificate file that contains your server certificate followed by the required intermediate certificates. It is commonly used with Nginx, Apache, reverse proxies, CDN providers, automation tools, load balancers, and SSL offload devices.
The usual order is server certificate first, then intermediate certificate, then any additional intermediate certificate if required. The private key is never part of fullchain.pem. Your private key should remain stored separately and securely on your server.
Full chain files are commonly required when you upload SSL certificates to reverse proxies, ingress controllers, CDN platforms, WAF services, application gateways, and hardware or virtual load balancers. These systems often expect the public server certificate and the intermediate CA bundle together so clients can validate the trust path without downloading missing certificates themselves.
A complete chain is especially important for API clients, older mobile devices, embedded systems, Java runtimes, and strict TLS libraries. Some desktop browsers can recover from missing intermediates using cached certificates or AIA fetching, but many automated clients will fail immediately when the server does not present the required chain.
For Nginx, the ssl_certificate directive should usually point to the full chain file, not only the server certificate.
ssl_certificate /etc/ssl/certs/fullchain.pem; ssl_certificate_key /etc/ssl/private/private.key;
For Apache, modern configurations commonly use SSLCertificateFile with a full chain file.
SSLCertificateFile /etc/ssl/certs/fullchain.pem SSLCertificateKeyFile /etc/ssl/private/private.key
Missing chain files can cause invalid CA bundle, browser SSL warning, CDN upload failure, load balancer import error, and mobile app TLS handshake failure.
This tool only needs your public certificate. Never paste your private key into any online tool. A private key is sensitive and must remain protected on your server. If a private key is exposed, the certificate should be replaced immediately.
The chain composer downloads intermediate certificates only from CA Issuers URLs found inside the public certificate. The backend blocks local, private, link-local, multicast, and reserved IP ranges to reduce SSRF risk.
No. It does not generate a new SSL certificate. It fetches or composes the missing intermediate certificate chain from issuer information already present in your certificate.
Most servers do not need to send the root certificate because clients already keep trusted roots locally. The server and intermediate certificates are usually enough.
The tool can still decode the certificate, but it may not be able to fetch intermediates automatically. In that case, download the CA bundle from your certificate authority.
This page includes a working interactive tool or quiz. Use the input, buttons, or quiz controls above to run the check, conversion, lookup, decoder, composer, or practice test directly in the browser.
This tool is designed for fast networking practice and troubleshooting. It gives you a practical starting point, then the supporting notes below explain what to enter, what result to expect, and how to avoid common mistakes.
Example input: enter a valid value for the tool, paste supported certificate text, type a public IP or hostname, convert an epoch timestamp, or answer the displayed quiz question.
Example output: the page returns decoded details, converted time, lookup information, generated chain text, or a quiz result that can be used for study and troubleshooting.
Yes. The working tool or quiz is available in the main section of the page.
Yes. Use it for quick checks, then confirm important findings with device commands, logs, or authoritative records.
No. It is a fast helper or practice page. Use the related tools and labs for complete validation.