When Trustico® issues your SSL Certificate, it is signed by an Intermediate Certificate Authority (CA). Each Intermediate Certificate Authority (CA) is in turn signed by a trusted Root Certificate Authority (CA), which forms a complete chain of trust.
The Intermediate Certificate Authority (CA) that signs your SSL Certificate, sometimes called the Issuer Certificate Authority (CA), depends on the SSL Certificate type and the algorithm you ordered. Learn About Encryption Algorithms 🔗
If the Intermediate SSL Certificate is missing from your server, the chain is incomplete. Browsers cannot connect your SSL Certificate to a trusted root, so visitors may see an untrusted warning even though your SSL Certificate is valid.
For that reason we strongly recommend installing the correct Intermediate SSL Certificate on your server. This completes the chain of trust from the Root Certificate Authority (CA) through to your End Entity SSL Certificate and gives the widest browser and device compatibility. Learn About Installing Your SSL Certificate 🔗
We also recommend installing the matching Sectigo® cross-chain root. The cross-chain extends trust to older devices and browsers whose root stores may not yet include the newer roots, which maximizes browser ubiquity. Learn About Browser Ubiquity 🔗
Always match the intermediate to your SSL Certificate algorithm : an RSA intermediate for an RSA SSL Certificate, and an Elliptic Curve Cryptography (ECC) intermediate for an Elliptic Curve Cryptography (ECC) SSL Certificate. We usually include the Intermediate SSL Certificates during issuance, so if you are unsure, please refer to your fulfillment e-mail.
Tip : The correct Intermediate SSL Certificates for your order are always available within the tracking system, matched to the SSL Certificate that was last issued. It is the easy and convenient way to obtain them and takes the guesswork out of choosing which Intermediates to use.
The following Intermediates should be used for Trustico® branded SSL Certificates issued after 24 May 2025.
RSA Domain Validation (DV) Intermediates
RSA Domain Validation (DV) SSL Certificates are issued through their own Trustico® Intermediate SSL Certificate. Download Trustico RSA DV SSL CA 2 🔗
For the widest device coverage, also install the matching Sectigo® cross-chain root. Download Sectigo Public Server Authentication Root R46 (Cross Chain) 🔗
Elliptic Curve Cryptography (ECC) Domain Validation (DV) Intermediates
Elliptic Curve Cryptography (ECC) Domain Validation (DV) SSL Certificates use their own Trustico® Intermediate SSL Certificate. Download Trustico ECC DV SSL CA 2 🔗
Add the matching Sectigo® cross-chain root alongside it for maximum compatibility. Download Sectigo Public Server Authentication Root E46 (Cross Chain) 🔗
RSA Organization Validation (OV) Intermediates
RSA Organization Validation (OV) SSL Certificates are issued through their own Trustico® Intermediate SSL Certificate. Download Trustico RSA OV SSL CA 2 🔗
Install the matching Sectigo® cross-chain root with it for the broadest device support. Download Sectigo Public Server Authentication Root R46 (Cross Chain) 🔗
Elliptic Curve Cryptography (ECC) Organization Validation (OV) Intermediates
Elliptic Curve Cryptography (ECC) Organization Validation (OV) SSL Certificates use their own Trustico® Intermediate SSL Certificate. Download Trustico ECC OV SSL CA 2 🔗
Pair it with the matching Sectigo® cross-chain root for the widest reach. Download Sectigo Public Server Authentication Root E46 (Cross Chain) 🔗
RSA Extended Validation (EV) Intermediates
RSA Extended Validation (EV) SSL Certificates are issued through their own Trustico® Intermediate SSL Certificate. Download Trustico RSA EV SSL CA 2 🔗
Add the matching Sectigo® cross-chain root to reach the oldest supported devices. Download Sectigo Public Server Authentication Root R46 (Cross Chain) 🔗
Elliptic Curve Cryptography (ECC) Extended Validation (EV) Intermediates
Elliptic Curve Cryptography (ECC) Extended Validation (EV) SSL Certificates use their own Trustico® Intermediate SSL Certificate. Download Trustico ECC EV SSL CA 2 🔗
Complete the chain with the matching Sectigo® cross-chain root for maximum compatibility. Download Sectigo Public Server Authentication Root E46 (Cross Chain) 🔗
Windows Internet Information Services (IIS) Chain Building
If your chain does not build correctly on Internet Information Services (IIS), the cause is usually the way Windows selects a chain. As a client, Windows tends to build the shortest available chain.
That behavior suits a client machine but not a server, which should send the longest available chain, since the longest chain is usually the most ubiquitous. Learn About Windows Chain Building 🔗
Note : On older Android devices, legacy operating systems, or some Internet of Things (IoT) systems, a valid SSL Certificate can still show a security warning or connection error. This is not a fault with the SSL Certificate itself, but a chain configuration issue in how Windows Internet Information Services (IIS) selects the chain to present.
One solution is to remove the shorter, non cross-chain Sectigo Public Server Authentication Root R46 from the Root and Intermediate stores and add it to the Untrusted Certificates list. This forces the server to send the longer cross-chain root instead. Learn About Fixing Older Device Trust Errors 🔗
Full Intermediate SSL Certificate Reference
For a complete reference of every Trustico® Intermediate SSL Certificate, including serial numbers, validity periods, issuer details, key algorithms and SHA-256 fingerprints, please refer to our full reference document. It covers both our current generation Intermediates and all legacy Intermediates. Download Trustico® Intermediate SSL Certificate Reference 🔗
We recommend bookmarking this document if you manage SSL Certificates across multiple servers or appliances. Quick access to the correct serial numbers and SHA-256 fingerprints lets you verify that the Intermediate SSL Certificate installed on your server is genuine and current, which helps you avoid chain validation issues before they affect your visitors.