Certificate Chain Builder
Order leaf, intermediate, and root certificates, validate their links, and generate fullchain.pem and chain.pem without uploading certificates.
Certificate input
Paste certificates in any order, or upload multiple PEM, CRT, or CER files.
Certificate path building
Build the certificate chain in the correct order
A valid certificate chain links the leaf certificate to one or more intermediate certificate authorities and, optionally, to a trusted root certificate.
What the builder checks
The tool compares certificate subjects and issuers, validates cryptographic signatures where supported, identifies the leaf, intermediate, and root certificates, and orders the chain.
What the generated files contain
A typical fullchain.pem contains the leaf certificate followed by the intermediate certificates. A chain.pem normally contains only the intermediate certificates required by the server.
Guide
About Certificate Chain Builder
TLS servers often require certificates in a precise order: leaf certificate first, followed by one or more intermediate certificates.
This tool analyzes a set of X.509 certificates, identifies issuer relationships, and builds common PEM chain outputs.
Chain construction is not the same as trust validation; client trust still depends on an appropriate root store and validation policy.
What the chain builder does
The builder compares subjects and issuers, checks certificate relationships, and orders certificates from leaf toward root.
- Identify leaf certificates
- Find intermediate issuers
- Detect self-signed roots
- Generate fullchain.pem and chain.pem
Typical server files
A typical fullchain.pem contains the leaf certificate followed by intermediates. chain.pem normally contains only intermediate certificates.
Why chains fail
Servers can fail TLS validation when an intermediate is missing, certificates are out of order, the wrong issuer is included, or signatures do not link correctly.
Trust limitations
A structurally valid chain may still be expired, revoked, untrusted, or unsuitable for the requested hostname.
FAQ
Frequently asked questions
Should the root certificate be included in fullchain.pem?
Usually no. Servers normally send the leaf and intermediate certificates, while clients already maintain trusted root stores.
What is the difference between fullchain.pem and chain.pem?
fullchain.pem normally includes the leaf plus intermediates; chain.pem usually includes intermediates only.
Why is certificate order important?
Clients need a clear issuer path from the leaf certificate toward a trusted root.
Can this prove the chain is publicly trusted?
No. Public trust depends on the client's trust store and full validation policy.
Can a chain contain multiple intermediates?
Yes. Some PKI hierarchies use more than one intermediate CA.
Are certificates uploaded?
The chain analysis is intended to run locally in your browser.
Continue exploring
Related tools
Useful tools for the next step in the same workflow.
X.509 Certificate Decoder
Decode certificate identity, validity, algorithms, key details, and fingerprints locally.
PKI & Certificates
Certificate Lint
Check X.509 certificates for common RFC 5280, CA/B Forum, and security best-practice issues.
PKI & Certificates
Certificate & Private Key Match Checker
Verify whether an X.509 certificate and RSA private key contain the same public key.
PKI & Certificates
SSL/TLS Checker
Inspect a live server's TLS protocol, cipher, certificate chain, expiration, and trust status.
Website Security
CSR Decoder
Decode PKCS#10 certificate signing requests and review requested identities, keys, and extensions.
PKI & Certificates
Public & Private Key Analyzer
Identify PEM and OpenSSH key algorithms, formats, sizes, curves, and fingerprints locally.
PKI & Certificates