A knowledge base article about TLS Certificate Chain provided by the UC Berkeley IT Service Hub - Knowledge Portal
Table of Contents
As of July 17, 2026, the TLS Certificate Service issues all TLS certificates using Sectigo public intermediate certificate authorities (CAs) instead of InCommon intermediates. These new intermediate CAs are cross-signed by both legacy USERTrust roots and modern Sectigo Public Server (R46/E46) roots to ensure broad compatibility.
Important: Modern browsers like Chrome and Firefox are removing USERTrust from their trusted root programs. Certificates relying solely on the USERTrust chain will eventually fail in these browsers.
For RSA certificates issued after July 17, 2026, include all three of the following in your configuration to ensure maximum backward compatibility:
your_server_leaf_certificate
Sectigo Public Server Authentication CA OV R36 (intermediate)
Sectigo Public Server Authentication Root R46 (cross-signed root acting as intermediate)
Download RSA Intermediates:
ECC certificates follow the same logic using the E46 intermediates:
your_server_leaf_certificate
Sectigo Public Server Authentication CA OV E36 (intermediate)
Sectigo Public Server Authentication Root E46 (cross-signed root acting as intermediate)
Download ECC Intermediates:
Using cross-signed intermediates provides two verification paths during the transition away from USERTrust.
| Attribute | Cross-signed Version | Self-signed Version |
|---|---|---|
| Subject | Sectigo Public Server Auth Root R46/E46 | Sectigo Public Server Auth Root R46/E46 |
| Issuer | USERTrust RSA/ECC Certification Authority | Sectigo Public Server Auth Root R46/E46 |
| Public Key | Same | Same |
| Role | Intermediate | Root CA Certificate |
Because the R46 root has the same Subject DN and Public Key in both variants, a client that trusts the self-signed R46 root will recognize the cross-signed certificate in your chain and anchor to it directly, bypassing the need for USERTrust.
Ensure your deployment complies with the following campus standards:
These are cross-signed versions of the R46/E46 roots. They are signed by the legacy USERTrust root to provide maximum compatibility for older clients that do not yet have the R46 root in their trust store.
Browser vendors (Google, Mozilla) are moving toward modern root hierarchies. For more information, see the Sectigo Resource Library.
You can use an online certificate decoder or use the following command:
openssl x509 -noout -in /path/to/your/server/certificate -issuer