>_devtools

Certificate Chain Viewer & Verifier

Paste several PEM certificates to order them leaf to root and verify each issuer link and signature locally. Spots missing intermediates, expired certificates, and forged links.

What this does

TLS servers send a chain: the leaf certificate for your domain, then the intermediate CA certificate(s) that issued it, usually ending just before a root that clients already trust. When a chain is incomplete or out of order, some clients fail with errors like "unable to get local issuer certificate". Paste a fullchain.pem, a bundle, or certificates copied one at a time, and this tool sorts them leaf-first and checks every link.

How each link is checked

  • The issuer name of one certificate must equal the subject name of the next, and the authority key identifier must match the subject key identifier when both are present.
  • The signature on each certificate is verified with the next certificate's public key (RSA PKCS#1 v1.5, RSA-PSS, ECDSA, and Ed25519).
  • The issuer must be marked as a CA in its basic constraints and, if it has key usage, allow Certificate Sign. A path length limit is enforced.
  • Each certificate's validity dates are compared with your clock.
  • The last certificate is flagged as a root if it is self-signed with a valid signature, or reported as incomplete when its issuer is missing.

What it does not do

There is no trust store here: a chain that ends in a valid self-signed certificate is internally consistent, but that does not mean any public CA vouches for it. Revocation status (CRL, OCSP) is not queried, hostnames are not matched, and the tool never fetches missing intermediates from the CA-issuer URL. Use it to find structural problems, then add the missing certificate yourself. Certificates that do not belong to the chain are listed separately. Up to 50 certificates are accepted.

Fixing a chain

If the order differs, copy the ordered chain with the Copy button and use it as your server's certificate file. If an intermediate is missing, download it from the "CA issuer" URL shown in thecertificate decoder and append it.

Privacy

Certificates are processed in your browser and are not uploaded or stored.