If you have a current Firefox that first diagram may not be correct for you. Let's tell a brief story about why. Servers, as Scott explains, are supposed to present a "chain" of certificates, in practice it's one leaf and then just anything else that might be useful for clients to assemble a trust path. If you do this everything works. But lots of servers are misconfigured and present only the leaf certificate, not l…
I've certainly expirenced the missing "missing intermediate cert" problem before. It is a bit of a nightmare to debug.
1. Had issue, raise support ticket: TLS not working
2. Ticket closed as can't reproduce
3. Try myself again locally, also can't reproduce. Hmpf!
4. 2 months goes by..
5. Experience same issue. Debug more carefully locally, use openssl go get proof of missing intermediate
6. Raise support ticket with platform team, then try to convince them that just because most people are not affected, it still needs to be fixed!