TLS Certificate Chain

A knowledge base article about TLS Certificate Chain provided by the UC Berkeley IT Service Hub - Knowledge Portal

Table of Contents

Background

As of July 17, 2026, the TLS Certificate Service issues all TLS certificates using Sectigo public intermediate certificate authorities (CAs) instead of InCommon intermediates. These new intermediate CAs are cross-signed by both legacy USERTrust roots and modern Sectigo Public Server (R46/E46) roots to ensure broad compatibility.

Important: Modern browsers like Chrome and Firefox are removing USERTrust from their trusted root programs. Certificates relying solely on the USERTrust chain will eventually fail in these browsers.

What this means for you:


RSA Certificate Chain (New)

For RSA certificates issued after July 17, 2026, include all three of the following in your configuration to ensure maximum backward compatibility:

your_server_leaf_certificate
Sectigo Public Server Authentication CA OV R36 (intermediate)
Sectigo Public Server Authentication Root R46 (cross-signed root acting as intermediate)

Download RSA Intermediates:

ECC Certificate Chain (New)

ECC certificates follow the same logic using the E46 intermediates:

your_server_leaf_certificate
Sectigo Public Server Authentication CA OV E36 (intermediate)
Sectigo Public Server Authentication Root E46 (cross-signed root acting as intermediate)

Download ECC Intermediates:


About Cross-Signing

Using cross-signed intermediates provides two verification paths during the transition away from USERTrust.

Attribute Cross-signed Version Self-signed Version
Subject Sectigo Public Server Auth Root R46/E46 Sectigo Public Server Auth Root R46/E46
Issuer USERTrust RSA/ECC Certification Authority Sectigo Public Server Auth Root R46/E46
Public Key Same Same
Role Intermediate Root CA Certificate

Because the R46 root has the same Subject DN and Public Key in both variants, a client that trusts the self-signed R46 root will recognize the cross-signed certificate in your chain and anchor to it directly, bypassing the need for USERTrust.


Administrative Policies & Compliance

Ensure your deployment complies with the following campus standards:


Frequently Asked Questions

Why are "Root" certificates being sent as intermediates?

These are cross-signed versions of the R46/E46 roots. They are signed by the legacy USERTrust root to provide maximum compatibility for older clients that do not yet have the R46 root in their trust store.

Why is the USERTrust root being distrusted?

Browser vendors (Google, Mozilla) are moving toward modern root hierarchies. For more information, see the Sectigo Resource Library.

How do I see what CA issued my certificate?

You can use an online certificate decoder or use the following command:

openssl x509 -noout -in /path/to/your/server/certificate -issuer
Where do I download the new roots for custom trust stores?