Click a certificate card to validate its chain up to the root.
Idle Signature valid Signature invalid Self-signed, untrusted
⚠ Couldn't load the 3D engineThree.js failed to load from the CDN. Check your connection and reload.

Digital Certificates: Chain of Trust Simulator

Public Key Infrastructure (PKI) secures the web by chaining certificates from a trusted Root CA down through Intermediate CAs to the certificate your browser actually sees. This simulator renders that chain in 3D — click any certificate to animate the signature check hop by hop, forge a certificate to watch validation fail at the exact broken link, and toggle self-signed mode to see why a mathematically valid signature still isn't enough without a trusted anchor.