+254725682556 +254725052660 info@ziprof.co.ke
Client Area

SSL

How to Fix an Incomplete SSL Certificate Chain (Missing Intermediate Certificate)

If your website's SSL certificate shows as "installed" in your control panel, but an SSL checker tool flags it as "incomplete chain" or some visitors (especially on older phones or certain browsers) still get a security warning, the most common cause is a missing intermediate certificate. Your domain's certificate on its own isn't enough: browsers also need the intermediate certificate (sometimes called the "CA bundle") that links your certificate back to a trusted root. Without it, some devices can't verify your certificate properly.

What Causes an Incomplete Certificate Chain

This almost always happens with a paid SSL certificate that was installed manually, where the Certificate Authority Bundle (also called the intermediate certificate or CA bundle) was skipped or pasted incorrectly during installation. Free certificates issued automatically through AutoSSL rarely have this problem, since the chain is built and renewed for you.

Most modern desktop browsers are good at fetching a missing intermediate certificate on their own, which is why the padlock can look fine to you while other visitors, older phones, or automated tools (like payment gateways or API clients) still fail. Don't assume the certificate is fine just because it looks fine in your own browser.

How to Check If Your Chain Is Incomplete

Run your domain through any online SSL checker tool (search "SSL checker" and use one you trust). Look for a line that says something like "chain incomplete," "chain issues," or "incomplete certificate chain." If it says the chain is complete and trusted, the problem you're seeing is likely something else, such as the certificate not matching the domain name or not being installed on the right subdomain.

How to Fix an Incomplete Certificate Chain

In cPanel

  1. Log in to cPanel and open SSL/TLS.
  2. Click Manage SSL Sites.
  3. Find your domain in the list and locate the Certificate Authority Bundle (CABUNDLE) field.
  4. Open the intermediate certificate file your certificate provider sent you (often named something like ca-bundle.crt or included in the same email as your certificate), and paste its full contents into the Certificate Authority Bundle (CABUNDLE) box. Leave the Certificate (CRT) and Private Key (KEY) fields as they already are.
  5. Click Install Certificate (or Save).

If you no longer have the intermediate certificate file, check the original email from whoever issued the certificate, or ask them to resend the CA bundle for your certificate type.

In DirectAdmin

  1. Log in to DirectAdmin and open SSL Certificates (under the Advanced Features or Account Manager section, depending on your theme).
  2. Choose the option to paste a pre-generated certificate and key.
  3. In the certificate text box, paste your domain certificate first, then paste the full intermediate/CA bundle certificate directly underneath it in the same box (no extra blank lines between them), followed by your private key below that.
  4. Click Save.

DirectAdmin expects the certificate, intermediate chain, and key together in one block in that order, so pasting only the domain certificate (and leaving out the intermediate) is the usual reason the chain comes back incomplete.

After You Fix It

  1. Wait a few minutes, then run the SSL checker tool again to confirm it now reports the chain as complete.
  2. Clear your browser cache or test in a private/incognito window, since browsers can cache the old certificate chain for a while.

If you installed your certificate through installing a paid SSL certificate and are still unsure which file is the CA bundle, check that article first; the intermediate certificate is usually a separate file from your main certificate and private key.