Our Intermediate Certificates

When Trustico® issues your SSL Certificate, it is signed by an Intermediate Certificate Authority (CA). Each Intermediate Certificate Authority (CA) is in turn signed by a trusted Root Certificate Authority (CA), which forms a complete chain of trust.

The Intermediate Certificate Authority (CA) that signs your SSL Certificate, sometimes called the Issuer Certificate Authority (CA), depends on the SSL Certificate type and the algorithm you ordered. Learn About Encryption Algorithms 🔗

If the Intermediate SSL Certificate is missing from your server, the chain is incomplete. Browsers cannot connect your SSL Certificate to a trusted root, so visitors may see an untrusted warning even though your SSL Certificate is valid.

For that reason we strongly recommend installing the correct Intermediate SSL Certificate on your server. This completes the chain of trust from the Root Certificate Authority (CA) through to your End Entity SSL Certificate and gives the widest browser and device compatibility. Learn About Installing Your SSL Certificate 🔗

We also recommend installing the matching Sectigo® cross-chain root. The cross-chain extends trust to older devices and browsers whose root stores may not yet include the newer roots, which maximizes browser ubiquity. Learn About Browser Ubiquity 🔗

Always match the intermediate to your SSL Certificate algorithm : an RSA intermediate for an RSA SSL Certificate, and an Elliptic Curve Cryptography (ECC) intermediate for an Elliptic Curve Cryptography (ECC) SSL Certificate. We usually include the Intermediate SSL Certificates during issuance, so if you are unsure, please refer to your fulfillment e-mail.

Tip : The correct Intermediate SSL Certificates for your order are always available within the tracking system, matched to the SSL Certificate that was last issued. It is the easy and convenient way to obtain them and takes the guesswork out of choosing which Intermediates to use.

The following Intermediates should be used for Trustico® branded SSL Certificates issued after 24 May 2025.

RSA Domain Validation (DV) Intermediates

RSA Domain Validation (DV) SSL Certificates are issued through their own Trustico® Intermediate SSL Certificate. Download Trustico RSA DV SSL CA 2 🔗

For the widest device coverage, also install the matching Sectigo® cross-chain root. Download Sectigo Public Server Authentication Root R46 (Cross Chain) 🔗

Elliptic Curve Cryptography (ECC) Domain Validation (DV) Intermediates

Elliptic Curve Cryptography (ECC) Domain Validation (DV) SSL Certificates use their own Trustico® Intermediate SSL Certificate. Download Trustico ECC DV SSL CA 2 🔗

Add the matching Sectigo® cross-chain root alongside it for maximum compatibility. Download Sectigo Public Server Authentication Root E46 (Cross Chain) 🔗

RSA Organization Validation (OV) Intermediates

RSA Organization Validation (OV) SSL Certificates are issued through their own Trustico® Intermediate SSL Certificate. Download Trustico RSA OV SSL CA 2 🔗

Install the matching Sectigo® cross-chain root with it for the broadest device support. Download Sectigo Public Server Authentication Root R46 (Cross Chain) 🔗

Elliptic Curve Cryptography (ECC) Organization Validation (OV) Intermediates

Elliptic Curve Cryptography (ECC) Organization Validation (OV) SSL Certificates use their own Trustico® Intermediate SSL Certificate. Download Trustico ECC OV SSL CA 2 🔗

Pair it with the matching Sectigo® cross-chain root for the widest reach. Download Sectigo Public Server Authentication Root E46 (Cross Chain) 🔗

RSA Extended Validation (EV) Intermediates

RSA Extended Validation (EV) SSL Certificates are issued through their own Trustico® Intermediate SSL Certificate. Download Trustico RSA EV SSL CA 2 🔗

Add the matching Sectigo® cross-chain root to reach the oldest supported devices. Download Sectigo Public Server Authentication Root R46 (Cross Chain) 🔗

Elliptic Curve Cryptography (ECC) Extended Validation (EV) Intermediates

Elliptic Curve Cryptography (ECC) Extended Validation (EV) SSL Certificates use their own Trustico® Intermediate SSL Certificate. Download Trustico ECC EV SSL CA 2 🔗

Complete the chain with the matching Sectigo® cross-chain root for maximum compatibility. Download Sectigo Public Server Authentication Root E46 (Cross Chain) 🔗

Windows Internet Information Services (IIS) Chain Building

If your chain does not build correctly on Internet Information Services (IIS), the cause is usually the way Windows selects a chain. As a client, Windows tends to build the shortest available chain.

That behavior suits a client machine but not a server, which should send the longest available chain, since the longest chain is usually the most ubiquitous. Learn About Windows Chain Building 🔗

Note : On older Android devices, legacy operating systems, or some Internet of Things (IoT) systems, a valid SSL Certificate can still show a security warning or connection error. This is not a fault with the SSL Certificate itself, but a chain configuration issue in how Windows Internet Information Services (IIS) selects the chain to present.

One solution is to remove the shorter, non cross-chain Sectigo Public Server Authentication Root R46 from the Root and Intermediate stores and add it to the Untrusted Certificates list. This forces the server to send the longer cross-chain root instead. Learn About Fixing Older Device Trust Errors 🔗

Full Intermediate SSL Certificate Reference

For a complete reference of every Trustico® Intermediate SSL Certificate, including serial numbers, validity periods, issuer details, key algorithms and SHA-256 fingerprints, please refer to our full reference document. It covers both our current generation Intermediates and all legacy Intermediates. Download Trustico® Intermediate SSL Certificate Reference 🔗

We recommend bookmarking this document if you manage SSL Certificates across multiple servers or appliances. Quick access to the correct serial numbers and SHA-256 fingerprints lets you verify that the Intermediate SSL Certificate installed on your server is genuine and current, which helps you avoid chain validation issues before they affect your visitors.

Most Popular Questions

Frequently asked questions covering Trustico® Intermediate SSL Certificates, including why installation matters, choosing the correct RSA or ECC intermediate, the cross-chain root, and fixing chain issues on Windows.

Reasons to Install the Intermediate SSL Certificate

Installing the Intermediate SSL Certificate on your server completes the chain of trust from the Root Certificate Authority (CA) through to your End Entity SSL Certificate. Without it the chain is incomplete, so browsers may show an untrusted warning even though your SSL Certificate is valid.

Identifying the Correct Intermediate SSL Certificate

Your Intermediate SSL Certificate must match both your validation type, which is Domain Validation (DV), Organization Validation (OV) or Extended Validation (EV), and your algorithm, which is RSA or Elliptic Curve Cryptography (ECC). Trustico® includes the correct Intermediate SSL Certificate during issuance, so check your fulfillment e-mail if you are unsure which one to install.

Differences Between RSA and ECC Intermediate SSL Certificates

RSA and Elliptic Curve Cryptography (ECC) are two different cryptographic algorithms. ECC provides comparable security to RSA using shorter key lengths, which means faster processing and lower overhead. You must use an RSA intermediate with an RSA SSL Certificate and an ECC intermediate with an ECC SSL Certificate.

Purpose of the Cross-Chain Intermediate SSL Certificate

The cross-chain Sectigo Public Server Authentication Root intermediates extend trust to older devices and browsers whose root stores may not yet include the newer roots. Installing the cross-chain root alongside your Trustico® intermediate gives the widest possible browser ubiquity.

Fixing SSL Certificate Chain Problems on Windows Internet Information Services (IIS)

Windows tends to build the shortest available chain, which can leave a server sending a less compatible chain. To force the longer and more ubiquitous chain, remove the shorter Sectigo Public Server Authentication Root R46 from the Root and Intermediate stores and add it to the Untrusted Certificates list.

Introduction Date of the Current Trustico® Intermediate SSL Certificates

The current Trustico® branded Intermediate SSL Certificates should be used for SSL Certificates issued after 24 May 2025. They include separate intermediates for Domain Validation (DV), Organization Validation (OV) and Extended Validation (EV) SSL Certificates in both RSA and Elliptic Curve Cryptography (ECC) formats.

Ask Trustico® Assistant

For Instant Answers - Start Here When You Have a Question or Need Help

Formatting Domain Name System (DNS) Records and the Trailing Dot

Formatting Domain Name System (DNS) Records and...

Why some DNS records need a trailing dot and others do not, and how to enter SSL Certificate validation records correctly in zone files and hosting panels.

Formatting Domain Name System (DNS) Records and...

Why some DNS records need a trailing dot and others do not, and how to enter SSL Certificate validation records correctly in zone files and hosting panels.

Merkle Tree Certificates Explained

Merkle Tree Certificates Explained

The move toward post-quantum cryptography solves one problem and creates another. It protects encrypted traffic against future quantum computers, but the new signature algorithms are far larger than the ones...

Merkle Tree Certificates Explained

The move toward post-quantum cryptography solves one problem and creates another. It protects encrypted traffic against future quantum computers, but the new signature algorithms are far larger than the ones...

SSL Certificates and Front-of-Site Services Like Cloudflare

SSL Certificates and Front-of-Site Services Lik...

Learn how front-of-site services like Cloudflare affect which SSL Certificate visitors see and how to apply your purchased SSL Certificate to them.

SSL Certificates and Front-of-Site Services Lik...

Learn how front-of-site services like Cloudflare affect which SSL Certificate visitors see and how to apply your purchased SSL Certificate to them.

Understanding X9 Certificates and the Public Trust Model

Understanding X9 Certificates and the Public Tr...

Learn what X9 Certificates are, how X9 PKI differs from public browser trust, and why they are not a substitute for a publicly trusted SSL Certificate.

Understanding X9 Certificates and the Public Tr...

Learn what X9 Certificates are, how X9 PKI differs from public browser trust, and why they are not a substitute for a publicly trusted SSL Certificate.

Why Your SSL Certificate Type and Brand Matter by Industry

Why Your SSL Certificate Type and Brand Matter ...

Why the type and brand of SSL Certificate matter across regulated industries, who examines your validation standing, and what is at stake when they do.

Why Your SSL Certificate Type and Brand Matter ...

Why the type and brand of SSL Certificate matter across regulated industries, who examines your validation standing, and what is at stake when they do.

Revocation Status Errors on a Valid SSL Certificate

Revocation Status Errors on a Valid SSL Certifi...

A revocation status error such as RevocationStatusUnknown can appear on a valid SSL Certificate. Learn how to confirm it is not revoked and what to do next.

Revocation Status Errors on a Valid SSL Certifi...

A revocation status error such as RevocationStatusUnknown can appear on a valid SSL Certificate. Learn how to confirm it is not revoked and what to do next.

1 / 6