SSL Certificate Decoder & Chain Builder

See everything inside a certificate, check whether its chain is complete, fetch missing intermediates automatically, and download a full chain file ready for Nginx and Apache.

What it checks

Certificate details

Domains, issuer, validity, DV/OV/EV type, key algorithm, fingerprints and extensions

Chain diagnosis

Missing intermediates, wrong order, extra roots, expired certificates and untrusted roots

Chain completion

Downloads missing intermediates from the issuing CA and builds a deployable full chain

When to decode a certificate and complete its chain

Your provider gave you a single .crt

Some providers only offer the server certificate, or put the intermediates in a separate ca_bundle file. Configure just the .crt in Nginx and the site opens on a computer but fails in some clients. Paste the certificate here and the tool fetches the intermediates from the CA and builds a full chain you can deploy.

Works on desktop, fails on phones or APIs

Desktop browsers cache or fetch missing intermediates, so a broken chain still loads. Android, WeChat mini programs, Java, Python and curl don't, and report an untrusted certificate or "unable to get local issuer certificate". Paste the certificate file from your server to see whether intermediates are missing.

Several files and no idea how to combine them

The download contains certificate.crt, ca_bundle.crt, root.crt and more, and it's unclear which to use or in what order. Upload them all: the tool identifies each certificate's role, drops roots and unrelated certificates, and outputs the chain in the right order.

FAQ

Is my certificate uploaded? What about my private key?
Certificate details are decoded in your browser. Completing the chain means downloading intermediates from the CA, which a browser can't do, so the certificate is sent to the LapseZero server for processing and isn't stored. Certificates are public anyway: every visitor to your site receives them. Private keys are never uploaded; if you paste one, it's discarded in your browser.
Why are intermediate certificates needed?
CAs don't sign site certificates with their roots directly. The root signs an intermediate, and the intermediate signs your certificate. Clients only ship with roots, so your server must send the intermediates to connect your certificate to a root. That's why the server should be configured with a full chain: server certificate plus intermediates.
How does the tool complete the chain?
Most certificates carry an Authority Information Access (AIA) extension with the download URL of the intermediate that signed them. The tool follows these URLs level by level and verifies each signature until it reaches a trusted root. Without an AIA URL the chain can't be completed automatically; get the intermediates from your provider's download page.
Should the full chain include the root certificate?
No. Clients only trust their built-in roots and ignore a root sent by the server, which just adds a certificate to every handshake. The generated files therefore contain only the server certificate and intermediates.
How do I tell DV, OV and EV certificates apart?
The CA declares the validation type in the Certificate Policies extension: DV only proves domain control, OV also verifies the organization, and EV applies stricter organization vetting. Encryption strength is the same for all three. The tool reads the policy identifiers defined by the CA/Browser Forum; certificates with only CA-specific identifiers show as "Not declared".
What are the equivalent OpenSSL commands?
Show certificate details: openssl x509 -in cert.pem -noout -text List every certificate in a chain: openssl crl2pkcs7 -nocrl -certfile fullchain.pem | openssl pkcs7 -print_certs -noout Build a full chain: cat cert.pem intermediate.pem > fullchain.pem Verify a chain: openssl verify -untrusted intermediate.pem cert.pem After deploying, use the SSL Certificate Checker to confirm the live chain is complete.

Rebuilding the chain on every renewal? Let LapseZero handle it

LapseZero renews certificates before they expire and deploys the full chain to your servers and cloud products automatically. No more downloading, combining and uploading. Start on the free plan.

Start for free