If you have a current Firefox that first diagram may not be correct for you. Let's tell a brief story about why. Servers, as Scott explains, are supposed to present a "chain" of certificates, in practice it's one leaf and then just anything else that might be useful for clients to assemble a trust path. If you do this everything works. But lots of servers are misconfigured and present only the leaf certificate, not l…
Interesting note about Firefox there. I've certainly expirenced the missing "missing intermediate cert" problem before. It is a bit of a nightmare to debug. 1. Had issue, raise support ticket: TLS not working 2. Ticket closed as can't reproduce 3. Try myself again locally, also can't reproduce. Hmpf! 4. 2 months goes by.. 5. Experience same issue. Debug more carefully locally, use openssl go get proof of missing inte…
https://www.ssllabs.com/ssltest/
Also this lets you out-source the decisions about what's important versus what really doesn't matter to somebody else, and unless you've got (or can hire someone who has got) hours per week to read and digest work in this area that's likely going to mean better security in practice.