Free tool · Check

CA Bundle and Intermediate Certificates

Your certificate is only trusted when the browser can follow the chain from your certificate to a trusted root. The CA bundle (intermediate certificates) makes that link. If you lost the bundle that came with your certificate, use the official sources below.

Official sources

Intermediate certificates by brand

Always download intermediates from the certificate authority itself. The bundle that came with your SSLWalay certificate email is the correct one for your exact product; these links are for when it is lost.

Sectigo (PositiveSSL, EssentialSSL, InstantSSL, EnterpriseSSL)

Root: USERTrust RSA Certification Authority. Intermediates: Sectigo RSA Domain Validation Secure Server CA (DV), Sectigo RSA Organization Validation Secure Server CA (OV), Sectigo RSA Extended Validation Secure Server CA (EV). Your bundle is the OV, DV or EV intermediate plus the USERTrust cross-signed root.

DigiCert (Secure Site, Basic)

Root: DigiCert Global Root G2. Intermediates: DigiCert Global G2 TLS RSA SHA256 2020 CA1 for most products; DigiCert TLS RSA SHA256 2020 CA1 for older orders; DigiCert EV RSA CA G2 for EV. CertCentral shows the exact chain for your order.

GeoTrust (QuickSSL, TrueBusinessID)

Issued from the DigiCert hierarchy. Root: DigiCert Global Root G2. Intermediates: GeoTrust TLS RSA CA G1 (DV and OV) and GeoTrust EV RSA CA G2.

Khalid Group branded certificates

Issued through our CA partner. The CA bundle is always attached to your issuance email and available in the client area under the certificate. Ask support on WhatsApp for a resend.

Order matters

How to combine the files

A full chain file is your certificate first, then the intermediates from the one closest to you down to the one closest to the root. Never include the root itself; browsers already have it.

-----BEGIN CERTIFICATE-----
(your certificate: yourdomain.crt)
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
(intermediate 1, for example Sectigo RSA DV Secure Server CA)
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
(intermediate 2, for example USERTrust cross-signed, if provided)
-----END CERTIFICATE-----
Where it goes

Per server

  • cPanel

    Paste intermediates in the "Certificate Authority Bundle (CABUNDLE)" box. Your certificate goes in the CRT box on its own.

  • Nginx

    ssl_certificate points to the combined full chain file. ssl_certificate_key points to your private key.

  • Apache

    SSLCertificateFile = your certificate (or the full chain on 2.4.8+), SSLCertificateChainFile = intermediates on older versions.

  • IIS

    Import a PFX that already contains the chain. Build it with the SSL converter.

Verify with the SSL checker. It reports how many chain certificates the server sends.

FAQ

About this tool

Short answers. More in the guides.

Read the guides
Do I really need the CA bundle?
Yes. Desktop Chrome sometimes fills in the gap automatically, but many phones, older browsers and API clients do not. Without the bundle they show a trust error.

Need a certificate to go with this tool?

Every SSL with a PKR price, the requirements listed, and a quotation in one click.

Bank transferJazzCashEasyPaisaDebit or credit card
WhatsApp, reply in minutes