Help Center> Cloud Certificate Manager> FAQs> Others> Troubleshooting> How Do I Fix an Incomplete SSL Certificate Chain?
Updated on 2023-01-19 GMT+08:00

How Do I Fix an Incomplete SSL Certificate Chain?

If the certificate provided by the certificate authority is not found in the built-in trust store on your platform and the certificate chain does not have a certificate authority, the certificate is incomplete. If you use the incomplete certificate to access the website corresponding to the protected domain name, the access will fail.

You can manually create a complete certificate chain to solve this problem. The latest Google Chrome version supports automatic verification of the trust chain. The following describes how to manually create a complete certificate chain (using a HUAWEI CLOUD certificate as an example):

  1. Viewing the certificate. Click the padlock in the address bar to view the certificate status (see Figure 1).

    Figure 1 Viewing the certificate

  2. Check the certificate chain. Click Certificate. Select the Certificate Path tab and then click the certificate name to view the certificate status.

    Figure 2 Viewing the certificate chain

  3. Save the certificates to the local PC one by one.

    1. Select the certificate name and click the Details tab.
      Figure 3 Details
    2. Click Copy to File, and then click Next as prompted.
    3. Select Base-64 encoded X.509 (.CER) and click Next. Figure 4 shows an example.
      Figure 4 Certificate export wizard

  4. Rebuild the certificate. After all certificates are exported to the local PC, open the certificate file in Notepad and rebuild the certificate according to the sequence shown in Figure 5.

    Figure 5 Certificate rebuilding

  5. Upload the certificate again.

Troubleshooting FAQs

more