🌐
The SSL Store
thesslstore.com › blog › root-certificates-intermediate
The Difference Between Root Certificates and Intermediate Certificates
May 25, 2023 - Rather than revoke the root certificate and literally every certificate that it signed by extension, you just revoke the intermediate, which only causes the group of certificates issued off that intermediate to get distrusted. Here’s a practical example, Google and the other browsers recently distrusted Symantec CA brand SSL certificates.
🌐
GoDaddy
godaddy.com › help › what-is-an-intermediate-certificate-868
What is an intermediate certificate? | SSL Certificates - GoDaddy Help US
We use intermediate certificates as a proxy because we must keep our root certificate behind numerous layers of security, ensuring its keys are absolutely inaccessible.
🌐
SSLTrust
ssltrust.com › home › guides and tutorials › setup and how-to guides › ssl intermediate certifiates
A Guide to Intermediate Certifiates | SSLTrust
Intermediate certificates are often a topic of confusion. It’s understandable. We pay a lot of attention to root certificates as they require a lot of active management on the client. Leaf certificates on the endpoint are the star of the show – they’re what we’re trying to validate ...
🌐
SecureW2
securew2.com › home › blog › overview: root and intermediate certificates
Overview: Root And Intermediate Certificates
September 17, 2025 - Certificates establish online trust, with client certificates verifying users and server certificates authenticating websites. Root CAs provide the ultimate source of trust, while intermediate CAs extend trust securely by issuing certificates under root authority.
🌐
SSLInsights
sslinsights.com › ssl certificate › what is an intermediate certificate: the ultimate beginners guide
What is an Intermediate Certificate: The Ultimate Beginners Guide
July 18, 2024 - Some organizations classify intermediates based on certificate policies using unique OID identifiers in the certificate. For example, “Policy 1 Intermediate CA” or “Smartcard Logon Intermediate CA”.
🌐
Encryption Consulting
encryptionconsulting.com › root-vs-intermediate-certificates
Root Certificates - Root vs Intermediate Certificates
March 10, 2021 - The certificate at the bottom, named *.encryptionconsulting.com is this website’s certificate. The certificate named R3 is the Intermediate certificate, and the certificate named DST Root CA X3 is the Root certificate.
🌐
Readthedocs
openssl-ca.readthedocs.io › en › latest › create-the-intermediate-pair.html
Create the intermediate pair — OpenSSL CA documentation
V 250408122707Z 1000 unknown ... /CN=Alice Ltd Intermediate CA · As we did for the root certificate, check that the details of the intermediate certificate are correct.
🌐
SSL Dragon
ssldragon.com › home › blog › ssl basics › root and intermediate certificates: key differences explained
Root and Intermediate Certificates: Key Differences Explained
September 8, 2025 - In practice, both root and intermediate certificates are widely used to secure online transactions, websites, and communications. For example, a root certificate might be trusted by all browsers, while an intermediate certificate is used to issue an SSL certificate for a website, authenticating its identity and enabling secure communication.
🌐
DNSimple
support.dnsimple.com › articles › what-is-ssl-certificate-chain
What is the SSL Certificate Chain? - DNSimple Help
Intermediate Awesome CA Gamma utilizes a certificate issued by The King of Awesomeness. The King of Awesomeness is a Root CA. Its certificate is directly embedded in your web browser, therefore it can be explicitly trusted. In our example, the SSL certificate chain is represented by 6 certificates:
Find elsewhere
🌐
Keyfactor
keyfactor.com › home › the difference in root certificates vs intermediate certificates
The Difference in Root Certificates vs Intermediate Certificates | Keyfactor
1 week ago - When you store the certificate of a new website you are trying to connect to, you can view the certificate for more details and get the certificate hierarchy. The first certificate you possess will be the root certificate, followed by intermediate CAs, and then the final certificate should point to a valid CA.
🌐
Cheap SSL Security
cheapsslsecurity.com › home › what are root certificates and intermediate certificates
What Are Root Certificates and Intermediate Certificates
July 20, 2022 - Trusted certificate authorities like DigiCert, Comodo, GeoTrust, RapidSSL, etc., deliver root certificates, also known as a trusted root. This digital certificate uses the X.509 format and is used to issue intermediate certificates and other certificates.
🌐
SSL2BUY
ssl2buy.com › home › wiki › root certificates vs. intermediate certificates: everything you need to know
Root Certificates vs. Intermediate Certificates: Core Differences
January 22, 2025 - These certificates are mediators between the secured root certificates and the server (endpoint) certificates. It is compulsory to have a single intermediate certificate in the chain, though there can be multiple ones too.
🌐
IBM
ibm.com › docs › en › blockchain-platform › 2.5.2
Creating an intermediate Certificate Authority (CA)
For customers who prefer to include intermediate CAs in their network, the IBM® Blockchain Platform offers this configuration option when you deploy a CA. This tutorial describes the process for creating an intermediate CA.
🌐
About SSL
aboutssl.org › root-certificates-vs-intermediate-certificates
Root Certificate vs Intermediate Certificates - AboutSSL.org
JavaScript is disabled in your browser · Please enable JavaScript to proceed · A required part of this site couldn’t load. This may be due to a browser extension, network issues, or browser settings. Please check your connection, disable any ad blockers, or try using a different browser
🌐
Aruba Networking
arubanetworking.hpe.com › techdocs › AOS-CX › 10.13 › HTML › security_6200-6300-6400 › Content › Chp_PKI › exa-inc-use-int-cer-10.htm
Example including the use of an intermediate certificate
================================================================================ Install root CA as a TA profile ================================================================================ switch(config)# crypto pki ta-profile root switch(config-ta-root)# ta-certificate import terminal Paste the certificate in PEM format below, then hit enter and ctrl-D: switch(config-ta-cert)# -----BEGIN CERTIFICATE----- switch(config-ta-cert)# MIIGATCCA+mgAwIBAgIJAL/JIZfJ0GpcMA0GCSqGSIUAMIGOMQswCQYD switch(config-ta-cert)# VQQGEwJVUzETMBEGA1UECAwKQ2FsaWZvcm5pYTESBwwJUm9zZXZpbGxl switch(config-ta-cert)#
🌐
Reddit
reddit.com › r/computersecurity › why do we really need intermediate certificates and the chain of trust?
r/ComputerSecurity on Reddit: Why do we really need intermediate certificates and the chain of trust?
June 15, 2023 -

in SSL, I get that we need a chain of trust and root certificate is self-signed. But I still can't grasp why do we REALLY need it? Because aren't intermediate certificates are also issued by the same CA as root? Thus, does it make a difference if root just signs the SSL certs?

Top answer
1 of 3
8
Root certificates are a much larger problem if they are leaked. It's usually a good idea to create multiple intermediate certificates from the root, then lock the root away in an inaccessible location. The intermediate certificates can then be used for daily activities. This way, you always have a certificate available to generate the public certificates, but if an intermediate certificate gets leaked then it's less of a nightmare to deal with. You can revoke an intermediate certificate and re-issue public certificates much more easily than you can a root certificate. Also, there are management use cases that are much improved by intermediate certificates. Say, for example, you need publicly signed certificates for multiple in-house servers (remote access servers, email servers, etc.). You could purchase an individual certificate for each server, but if you have a lot of servers, that gets expensive and difficult to manage. You could get a wildcard certificate, but they have compatibility issues. Or you could purchase an intermediate certificate from a public CA, install it on your own internal CA, then generate all the certificates you need in a much more manageable fashion.
2 of 3
2
There are many reasons! Offline root. You create the private key and cert, make it last for many years, issue a subordinate, then lock up that root key in an offline, air gapped environment. Only take it out to issue a new subordinate or CRL. Subordinate revocation. You can use the CA to issue a CSR revoking the intermediate if it were ever compromised. Subordinate rollover. Similar to 2, you can create a new subordinate and start issuing from that subordinate and everyone will trust it because they trust your root. Imagine you are a major certificate authority and your root CA private key were stolen. Your business value just dropped to 0 instantly because your root cert is useless. Even if you issued another - why would anyone trust YOU, the CA that lost its root.
🌐
Trustico
blog.trustico.com › resources › resource-articles › intermediate-certificate-explained.php
What Is An Intermediate Certificate?
Browsers and operating systems save SSL Certificate information to speed up secure connections, but this cached data can become outdated or corrupted, causing connection problems even when your SSL Certificate...
🌐
Dell
dell.com › home › support home › knowledge base article
How to manually separate the server, intermediate, and root certificates from a single signed certificate | Dell US
July 19, 2023 - The first will be the server s signed certificate, the last will be the root certificate, anything in between are intermediate certificates. In the example below, I ve replaced the encrypted content to describe each certificate in the chain according to the order they appear in the file: ---- BEGIN CERTIFICATE---- Issued To: webserver01.emc.com; Issued By: IntermediateCA-1 ----END CERTIFICATE---- ---- BEGIN CERTIFICATE---- Issued To: IntermediateCA-1; Issued By: IntermediateCA-2 ----END CERTIFICATE---- ---- BEGIN CERTIFICATE---- Issued To: IntermediateCA-2; Issued By: Root-CA ----END CERTIFICA