Your provider gave you a single .crt
Some providers only offer the server certificate, or put the intermediates in a separate ca_bundle file. Configure just the .crt in Nginx and the site opens on a computer but fails in some clients. Paste the certificate here and the tool fetches the intermediates from the CA and builds a full chain you can deploy.
Works on desktop, fails on phones or APIs
Desktop browsers cache or fetch missing intermediates, so a broken chain still loads. Android, WeChat mini programs, Java, Python and curl don't, and report an untrusted certificate or "unable to get local issuer certificate". Paste the certificate file from your server to see whether intermediates are missing.
Several files and no idea how to combine them
The download contains certificate.crt, ca_bundle.crt, root.crt and more, and it's unclear which to use or in what order. Upload them all: the tool identifies each certificate's role, drops roots and unrelated certificates, and outputs the chain in the right order.
- Is my certificate uploaded? What about my private key?
- Certificate details are decoded in your browser. Completing the chain means downloading intermediates from the CA, which a browser can't do, so the certificate is sent to the LapseZero server for processing and isn't stored. Certificates are public anyway: every visitor to your site receives them. Private keys are never uploaded; if you paste one, it's discarded in your browser.
- Why are intermediate certificates needed?
- CAs don't sign site certificates with their roots directly. The root signs an intermediate, and the intermediate signs your certificate. Clients only ship with roots, so your server must send the intermediates to connect your certificate to a root. That's why the server should be configured with a full chain: server certificate plus intermediates.
- How does the tool complete the chain?
- Most certificates carry an Authority Information Access (AIA) extension with the download URL of the intermediate that signed them. The tool follows these URLs level by level and verifies each signature until it reaches a trusted root. Without an AIA URL the chain can't be completed automatically; get the intermediates from your provider's download page.
- Should the full chain include the root certificate?
- No. Clients only trust their built-in roots and ignore a root sent by the server, which just adds a certificate to every handshake. The generated files therefore contain only the server certificate and intermediates.
- How do I tell DV, OV and EV certificates apart?
- The CA declares the validation type in the Certificate Policies extension: DV only proves domain control, OV also verifies the organization, and EV applies stricter organization vetting. Encryption strength is the same for all three. The tool reads the policy identifiers defined by the CA/Browser Forum; certificates with only CA-specific identifiers show as "Not declared".
- What are the equivalent OpenSSL commands?
- Show certificate details: openssl x509 -in cert.pem -noout -text
List every certificate in a chain: openssl crl2pkcs7 -nocrl -certfile fullchain.pem | openssl pkcs7 -print_certs -noout
Build a full chain: cat cert.pem intermediate.pem > fullchain.pem
Verify a chain: openssl verify -untrusted intermediate.pem cert.pem
After deploying, use the SSL Certificate Checker to confirm the live chain is complete.