{"id":304,"date":"2019-07-19T14:14:35","date_gmt":"2019-07-19T14:14:35","guid":{"rendered":"https:\/\/www.rapidsslonline.com\/ssl\/?p=304"},"modified":"2019-08-09T14:11:39","modified_gmt":"2019-08-09T14:11:39","slug":"what-is-ssl-certificate-chain","status":"publish","type":"post","link":"https:\/\/www.rapidsslonline.com\/ssl\/what-is-ssl-certificate-chain\/","title":{"rendered":"What is the SSL Certificate Chain? Explained by a Certificate Authority"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">A look at the SSL certificate chain order and the role it plays in the\ntrust model<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">There are tons of different kinds of chains: gold chains, bike chains, evolutionary chains, chain wallets\u2026 Today we\u2019re going to discuss the least interesting of those chains: the SSL certificate chain. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/www.thesslstore.com\/blog\/wide-world-pki\/\" target=\"_blank\">Public key infrastructure<\/a> (PKI) is a hierarchy of trust that uses digital certificates to authenticate entities. There are myriad uses for PKI \u2014 everything from digital signatures to encrypted internet connections. One thing all of them share in common is they use a certificate chain to establish identity. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to Get an SSL Certificate Chain<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When you arrive at a website, the serving hosting sends a\ncopy of its SSL certificate to your browser as part of what\u2019s known as a \u201chandshake.\u201d\nThe handshake process is where authentication occurs and the parameters of a\nsecure, encrypted HTTPS connection are negotiated. To authenticate the server,\nyour browser will perform a series of checks on the certificate its presented.\nIt will check certificate transparency (CT) logs, online certificate status\nprotocol (OCSP) servers, revocation lists, and the digital signature on the\ncertificate itself.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This last part, verifying the digital signature, is where\nthe certificate chain comes in.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Starting at the Bottom \u2013 With the Roots<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.rapidsslonline.com\/blog\/little-guide-to-help-you-choose-a-ssl-certificate-authority\/\">Certificate\nauthorities<\/a> (CAs) are the organizations responsible for issuing trusted\ndigital certificates. They\u2019re strictly monitored and must comply with stringent\nstandards to ensure they maintain their trusted status. The return for this is\nthat their issuing root certificates get included in the major root stores run\nby the various OSs and browsers. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How to Validate the SSL Certificate Chain<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When a certificate is issued, the CA performs a validation\nof the entity requesting the certificate. Once that\u2019s satisfied, it issues a\ncertificate that includes the validated information and signs it with the\nissuing certificate\u2019s private key.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This digital signature can be verified using the same\ncertificate\u2019s public key.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It all starts with the root certificate. These are\nincredibly powerful, long-lived digital certificates that can be used to issue\nother trusted certificates. This is all done with digital signatures. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But CAs don\u2019t issue directly off their root certificates.\nThat would be too dangerous and also raises a laundry list of technical issues.\nInstead, to protect the root certificates, the CAs spin up and sign <a href=\"https:\/\/www.rapidsslonline.com\/blog\/ssl-encryption-guide-on-intermediate-ssl-certificates\/\">intermediate\nroots<\/a>. Whereas the root certificates themselves reside in root stores and\nphysically live on the devices that use those root stores, the intermediate\nroots do not. This is why it\u2019s oftentimes necessary to install an intermediate\nalongside your end user or leaf SSL certificate.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The SSL Certificate Chain Order<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This will all make more sense when we put it together.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>A CA undergoes the requisite vetting to be\ntrusted and have its issuing roots included in the various root programs.<\/li><li>The CA uses its root certificates to issue and\nsign intermediate root certificates.<\/li><li>The CA uses those intermediates to issue\nend-user\/leaf (server) SSL certificates.<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s an SSL certificate chain example from RapidSSLonline.com:\n<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" width=\"405\" height=\"510\" data-src=\"https:\/\/www.rapidsslonline.com\/ssl\/wp-content\/uploads\/2019\/07\/SSLCertificateChain.png\" alt=\"Graphic: ssl certificate chain example\" class=\"wp-image-305 lazyload\" data-srcset=\"https:\/\/www.rapidsslonline.com\/ssl\/wp-content\/uploads\/2019\/07\/SSLCertificateChain.png 405w, https:\/\/www.rapidsslonline.com\/ssl\/wp-content\/uploads\/2019\/07\/SSLCertificateChain-238x300.png 238w\" data-sizes=\"(max-width: 405px) 100vw, 405px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 405px; --smush-placeholder-aspect-ratio: 405\/510;\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Following the SSL Certificate Chain<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Now, let\u2019s talk about the actual trust model that leverages\nthe SSL certificate chain. Remember earlier when we talked about how the\nbrowser receives the server\u2019s SSL certificate during the handshake? Well, in\naddition to the leaf certificate, it also receives any associated intermediates.\nThese intermediates are needed to complete the chain. Oftentimes, modern\nbrowsers will cache intermediates in case the server doesn\u2019t have all the right\ncertificates installed, but if you\u2019re a site owner, it\u2019s always best to ensure\nyou have the completed certificate chain at your users\u2019 disposal.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When the user receives the certificate, it checks the\ndigital signature. So, in the case of the leaf certificate, it checks the\nsignature that was left by the intermediate root that issued it. That intermediate\nshould also be installed, and its public key comes included, so the browser\nuses its public key to verify the signature on the leaf certificate. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Provided that checks out, it moves to the digital certificate that was affixed to the intermediate by whatever certificate issued it. This could be one of the roots in its trust store, or another intermediate. Regardless, it takes the signing certificate\u2019s public key and verifies the signature on the previous certificate. It continues to do this until it reaches one of the roots in its root store.<\/p>\n\n\n\n<div class=\"graysection\"><h2>Save Up to 80% on DV SSL Certificates<\/h2>\n<p>Protect a website in a few minutes with DV SSL or Domain Validated SSL Certificate.<\/p>\n<p><a class=\"more-link floatnone\" style=\"text-decoration: none;\" href=\"https:\/\/www.rapidsslonline.com\/ssl-types\/domain-validation-ssl-certificates.aspx\">Get a DV SSL certificate, starting at $12.42\/year<\/a><\/p>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Wrapping This Up<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you can chain the signatures back to the root, it means\nthat the end user certificate is descendant of that root. That root is trusted,\nso anything it signs is trusted. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Long story short \u2014 as long as a certificate can be chained\nback to one of the roots in a device\u2019s root store, that device will trust it. If\nit can\u2019t be chained back to the root, your browser will <a href=\"https:\/\/www.rapidsslonline.com\/blog\/solve-certificate-not-trusted-error\/\">issue\na warning<\/a> about the certificate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Which more than you can say for anybody with a chain wallet.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A look at the SSL certificate chain order and the role it plays in the trust model There are tons of different kinds of chains: gold chains, bike chains, evolutionary<\/p>\n<div class=\"article-wpr-button\"><a href=\"https:\/\/www.rapidsslonline.com\/ssl\/what-is-ssl-certificate-chain\/\" class=\"btn btn-green\">Read More<\/a><\/p>\n<div>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13],"tags":[19],"class_list":["post-304","post","type-post","status-publish","format-standard","category-ssl-advanced","tag-ssl-certificate-chain"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>What is the SSL Certificate Chain? Explained by a Certificate Authority<\/title>\n<meta name=\"description\" content=\"Breaking down the SSL certificate chain. The chain establishes the identity of a website and authenticates it via a trusted certificate authority.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.rapidsslonline.com\/ssl\/what-is-ssl-certificate-chain\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What is the SSL Certificate Chain? Explained by a Certificate Authority\" \/>\n<meta property=\"og:description\" content=\"Breaking down the SSL certificate chain. The chain establishes the identity of a website and authenticates it via a trusted certificate authority.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.rapidsslonline.com\/ssl\/what-is-ssl-certificate-chain\/\" \/>\n<meta property=\"og:site_name\" content=\"SSL\/TLS Certificates\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/rsosslcertificates\/\" \/>\n<meta property=\"article:published_time\" content=\"2019-07-19T14:14:35+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2019-08-09T14:11:39+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.rapidsslonline.com\/ssl\/wp-content\/uploads\/2019\/07\/SSLCertificateChain.png\" \/>\n<meta name=\"author\" content=\"Casey Crane\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@RSOSSL\" \/>\n<meta name=\"twitter:site\" content=\"@RSOSSL\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Casey Crane\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What is the SSL Certificate Chain? Explained by a Certificate Authority","description":"Breaking down the SSL certificate chain. The chain establishes the identity of a website and authenticates it via a trusted certificate authority.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.rapidsslonline.com\/ssl\/what-is-ssl-certificate-chain\/","og_locale":"en_US","og_type":"article","og_title":"What is the SSL Certificate Chain? Explained by a Certificate Authority","og_description":"Breaking down the SSL certificate chain. The chain establishes the identity of a website and authenticates it via a trusted certificate authority.","og_url":"https:\/\/www.rapidsslonline.com\/ssl\/what-is-ssl-certificate-chain\/","og_site_name":"SSL\/TLS Certificates","article_publisher":"https:\/\/www.facebook.com\/rsosslcertificates\/","article_published_time":"2019-07-19T14:14:35+00:00","article_modified_time":"2019-08-09T14:11:39+00:00","og_image":[{"url":"https:\/\/www.rapidsslonline.com\/ssl\/wp-content\/uploads\/2019\/07\/SSLCertificateChain.png","type":"","width":"","height":""}],"author":"Casey Crane","twitter_card":"summary_large_image","twitter_creator":"@RSOSSL","twitter_site":"@RSOSSL","twitter_misc":{"Written by":"Casey Crane","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.rapidsslonline.com\/ssl\/what-is-ssl-certificate-chain\/#article","isPartOf":{"@id":"https:\/\/www.rapidsslonline.com\/ssl\/what-is-ssl-certificate-chain\/"},"author":{"name":"Casey Crane","@id":"https:\/\/www.rapidsslonline.com\/ssl\/#\/schema\/person\/24349032d0b90283d4682ad113e46d4d"},"headline":"What is the SSL Certificate Chain? Explained by a Certificate Authority","datePublished":"2019-07-19T14:14:35+00:00","dateModified":"2019-08-09T14:11:39+00:00","mainEntityOfPage":{"@id":"https:\/\/www.rapidsslonline.com\/ssl\/what-is-ssl-certificate-chain\/"},"wordCount":868,"commentCount":0,"publisher":{"@id":"https:\/\/www.rapidsslonline.com\/ssl\/#organization"},"image":{"@id":"https:\/\/www.rapidsslonline.com\/ssl\/what-is-ssl-certificate-chain\/#primaryimage"},"thumbnailUrl":"https:\/\/www.rapidsslonline.com\/ssl\/wp-content\/uploads\/2019\/07\/SSLCertificateChain.png","keywords":["SSL certificate chain"],"articleSection":["SSL Advanced"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.rapidsslonline.com\/ssl\/what-is-ssl-certificate-chain\/","url":"https:\/\/www.rapidsslonline.com\/ssl\/what-is-ssl-certificate-chain\/","name":"What is the SSL Certificate Chain? Explained by a Certificate Authority","isPartOf":{"@id":"https:\/\/www.rapidsslonline.com\/ssl\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.rapidsslonline.com\/ssl\/what-is-ssl-certificate-chain\/#primaryimage"},"image":{"@id":"https:\/\/www.rapidsslonline.com\/ssl\/what-is-ssl-certificate-chain\/#primaryimage"},"thumbnailUrl":"https:\/\/www.rapidsslonline.com\/ssl\/wp-content\/uploads\/2019\/07\/SSLCertificateChain.png","datePublished":"2019-07-19T14:14:35+00:00","dateModified":"2019-08-09T14:11:39+00:00","description":"Breaking down the SSL certificate chain. The chain establishes the identity of a website and authenticates it via a trusted certificate authority.","breadcrumb":{"@id":"https:\/\/www.rapidsslonline.com\/ssl\/what-is-ssl-certificate-chain\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.rapidsslonline.com\/ssl\/what-is-ssl-certificate-chain\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.rapidsslonline.com\/ssl\/what-is-ssl-certificate-chain\/#primaryimage","url":"https:\/\/www.rapidsslonline.com\/ssl\/wp-content\/uploads\/2019\/07\/SSLCertificateChain.png","contentUrl":"https:\/\/www.rapidsslonline.com\/ssl\/wp-content\/uploads\/2019\/07\/SSLCertificateChain.png","width":405,"height":510},{"@type":"BreadcrumbList","@id":"https:\/\/www.rapidsslonline.com\/ssl\/what-is-ssl-certificate-chain\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"SSL Resources","item":"https:\/\/www.rapidsslonline.com\/ssl\/"},{"@type":"ListItem","position":2,"name":"SSL Advanced","item":"https:\/\/www.rapidsslonline.com\/ssl\/ssl-advanced\/"},{"@type":"ListItem","position":3,"name":"What is the SSL Certificate Chain? Explained by a Certificate Authority"}]},{"@type":"WebSite","@id":"https:\/\/www.rapidsslonline.com\/ssl\/#website","url":"https:\/\/www.rapidsslonline.com\/ssl\/","name":"SSL\/TLS Certificates","description":"Secure a website in few minutes with Trusted SSL Certificate","publisher":{"@id":"https:\/\/www.rapidsslonline.com\/ssl\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.rapidsslonline.com\/ssl\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.rapidsslonline.com\/ssl\/#organization","name":"RapidSSLOnline","url":"https:\/\/www.rapidsslonline.com\/ssl\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.rapidsslonline.com\/ssl\/#\/schema\/logo\/image\/","url":"https:\/\/www.rapidsslonline.com\/ssl\/wp-content\/uploads\/2019\/10\/rapidsslonline-logo.png","contentUrl":"https:\/\/www.rapidsslonline.com\/ssl\/wp-content\/uploads\/2019\/10\/rapidsslonline-logo.png","width":266,"height":39,"caption":"RapidSSLOnline"},"image":{"@id":"https:\/\/www.rapidsslonline.com\/ssl\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/rsosslcertificates\/","https:\/\/x.com\/RSOSSL","https:\/\/in.linkedin.com\/company\/rapidsslonline-com"]},{"@type":"Person","@id":"https:\/\/www.rapidsslonline.com\/ssl\/#\/schema\/person\/24349032d0b90283d4682ad113e46d4d","name":"Casey Crane","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/c18d819d34a1995e91a4aa7518e9048df7856f336a1ede2262a572db7b1c2506?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/c18d819d34a1995e91a4aa7518e9048df7856f336a1ede2262a572db7b1c2506?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/c18d819d34a1995e91a4aa7518e9048df7856f336a1ede2262a572db7b1c2506?s=96&d=mm&r=g","caption":"Casey Crane"}}]}},"_links":{"self":[{"href":"https:\/\/www.rapidsslonline.com\/ssl\/wp-json\/wp\/v2\/posts\/304","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rapidsslonline.com\/ssl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.rapidsslonline.com\/ssl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.rapidsslonline.com\/ssl\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rapidsslonline.com\/ssl\/wp-json\/wp\/v2\/comments?post=304"}],"version-history":[{"count":0,"href":"https:\/\/www.rapidsslonline.com\/ssl\/wp-json\/wp\/v2\/posts\/304\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.rapidsslonline.com\/ssl\/wp-json\/wp\/v2\/media?parent=304"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.rapidsslonline.com\/ssl\/wp-json\/wp\/v2\/categories?post=304"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rapidsslonline.com\/ssl\/wp-json\/wp\/v2\/tags?post=304"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}