Guidance on obtaining certificate chain for Apache SSL setup

Asma Aljarai <[email protected]> Fri, 26 Dec 2025 11:51:25 +0200
Newsgroups gmane.comp.apache.user
Message-ID <[email protected]>
--Apple-Mail-48DDC705-2645-46BF-BC90-2797B29C0059
Content-Type: text/plain;
	charset=us-ascii
Content-Transfer-Encoding: quoted-printable

Hello Apache Community,

I have configured SSL on Apache HTTP Server running on CentOS 9.

Environment:
- Operating System: CentOS 9
- Apache Version: 2.4.62

Certificate setup:
- Private key generated on the server
- CSR generated on the server and signed by our internal CA (Key Manager Plu=
s)
- Server certificate (.crt) issued successfully

Issue:
I did not receive the certificate chain (intermediate certificates). Without=
 the chain, browsers may not fully trust the site, and I want to ensure the S=
SL configuration is complete and secure.

Questions:
1. What is the recommended way to obtain the certificate chain from an inter=
nal CA such as Key Manager Plus?
2. Is it acceptable to run Apache securely using only the server certificate=
 and private key if the chain is not available?
3. Could the missing chain be the reason the site appears as not fully secur=
e in browsers?

Any guidance or best practices would be greatly appreciated.

Thank you.

--Apple-Mail-48DDC705-2645-46BF-BC90-2797B29C0059
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html class=3D"apple-mail-supports-explicit-dark-mode"><head><meta http-equi=
v=3D"content-type" content=3D"text/html; charset=3Dutf-8"></head><body dir=3D=
"auto"><div style=3D"direction: rtl;"><div style=3D"direction: ltr;" dir=3D"=
ltr">Hello Apache Community,</div><div style=3D"direction: rtl;"><br></div><=
div style=3D"direction: rtl;">I have configured SSL on Apache HTTP Server ru=
nning on CentOS 9.</div><div style=3D"direction: rtl;"><br></div><div style=3D=
"direction: rtl;">Environment:</div><div style=3D"direction: rtl;">- Operati=
ng System: CentOS 9</div><div style=3D"direction: rtl;">- Apache Version: 2.=
4.62</div><div style=3D"direction: rtl;"><br></div><div style=3D"direction: r=
tl;">Certificate setup:</div><div style=3D"direction: rtl;">- Private key ge=
nerated on the server</div><div style=3D"direction: rtl;">- CSR generated on=
 the server and signed by our internal CA (Key Manager Plus)</div><div style=
=3D"direction: rtl;">- Server certificate (.crt) issued successfully</div><d=
iv style=3D"direction: rtl;"><br></div><div style=3D"direction: rtl;">Issue:=
</div><div style=3D"direction: rtl;">I did not receive the certificate chain=
 (intermediate certificates). Without the chain, browsers may not fully trus=
t the site, and I want to ensure the SSL configuration is complete and secur=
e.</div><div style=3D"direction: rtl;"><br></div><div style=3D"direction: rt=
l;">Questions:</div><div style=3D"direction: rtl;">1. What is the recommende=
d way to obtain the certificate chain from an internal CA such as Key Manage=
r Plus?</div><div style=3D"direction: rtl;">2. Is it acceptable to run Apach=
e securely using only the server certificate and private key if the chain is=
 not available?</div><div style=3D"direction: rtl;">3. Could the missing cha=
in be the reason the site appears as not fully secure in browsers?</div><div=
 style=3D"direction: rtl;"><br></div><div style=3D"direction: rtl;">Any guid=
ance or best practices would be greatly appreciated.</div><div style=3D"dire=
ction: rtl;"><br></div><div style=3D"direction: rtl;">Thank you.</div></div>=
<div dir=3D"ltr"></div></body></html>=

--Apple-Mail-48DDC705-2645-46BF-BC90-2797B29C0059--