The chain of trust
Browsers only trust a small list of root certificates. Certificate authorities do not sign your certificate with the root directly. They sign it with an intermediate certificate, and the intermediate is signed by the root. Your certificate, the intermediate, and the root form a chain:
Root (in the browser) → Intermediate (CA bundle) → Your certificate (yourdomain.crt)
The CA bundle is the intermediate part. When you install only your certificate, the browser cannot find the link to the root and shows an error such as "certificate is not trusted" or "incomplete chain".
Why it works on your laptop but not on phones
Desktop Chrome and Firefox can download a missing intermediate automatically. Android WebView, older iPhones, mail apps, curl and API clients cannot. That is why an incomplete chain looks fine to you and broken to your customers.
Where to install it
- cPanel: paste in the Certificate Authority Bundle (CABUNDLE) box.
- Nginx: combine your certificate and the bundle into one file:
cat yourdomain.crt ca-bundle.crt > fullchain.pem, then use it inssl_certificate. - Apache 2.4: use
SSLCertificateFilefor the full chain file, orSSLCertificateChainFilefor the bundle on older versions. - IIS: import a PFX file that already contains the chain. Make one with the SSL converter.
Lost the bundle?
See the CA bundle download page for the official intermediate certificates of Sectigo, DigiCert, GeoTrust, RapidSSL and Thawte, or ask us on WhatsApp and we resend it.
Written by the SSLWalay team, Karachi. Last reviewed October 2026. Prices quoted are SSLWalay PKR prices at the time of review and can change; the product pages always show the live price.