SSL Chain Analyzer

Verify a PEM certificate chain order and find broken or missing links

Certificate bundle (PEM)

Paste leaf + intermediates (+ optional root)

Parsing is local. Certificate data never leaves your browser.

Chain analysis

Paste a certificate bundle on the left to analyze its chain.

Examples

A complete leaf → intermediate → root chain

Input
Three PEM blocks: example.com (leaf), Example Intermediate CA, Example Root CA
Output
Chain complete — order reconstructed as leaf → intermediate → root.

Click Load sample to try a real throwaway chain. The analyzer reassembles the order even if you paste the blocks shuffled.

A broken chain (missing intermediate)

Input
Only the leaf certificate, issued by 'Example Intermediate CA'
Output
Chain broken — 'issued by "Example Intermediate CA", which is not present in the bundle'.

When a cert's issuer is absent, the analyzer names the missing intermediate you must add to the bundle.

About this tool

TLS handshakes fail with errors like 'unable to get local issuer certificate' when a certificate bundle is out of order, missing an intermediate, or contains an expired entry. Eyeballing a PEM bundle to find the broken link is tedious and error-prone.

Paste your full chain (leaf + intermediates, and optionally the root) as PEM. The analyzer parses every certificate — subject, issuer, validity window, and CA flag — then reconstructs the intended order and reports whether it links from leaf to a self-signed root. It flags missing intermediates that break the chain, expired or not-yet-valid certificates, duplicate entries, and bundles with unrelated chains. Parsing is purely client-side.

How to use

  1. Paste the bundle

    Include the leaf certificate first, then each intermediate, optionally the root, as PEM blocks.

  2. Read the status

    A green 'Chain complete' means each cert's issuer matches the next cert's subject up to a root.

  3. Investigate breaks

    A red 'Chain broken' names the missing issuer you need to add as an intermediate.

  4. Check validity

    Expired or not-yet-valid certificates are flagged so you can renew in time.

Common mistakes

Mistake:Serving only the leaf certificate.

Fix:Most clients need the leaf plus the intermediates. Bundle them in the correct order.

Mistake:Putting the root first.

Fix:Order matters: leaf first, then intermediates, root last. The analyzer reconstructs order, but correct input avoids confusion.

Frequently asked questions

References & standards