Because the "Certificate Chain" field for AWS always throws me when someone asks what the order of the certs are. Every. Single. Time.
(openssl x509 -inform PEM -in COMODORSADomainValidationSecureServerCA.crt; openssl x509 -inform PEM -in COMODORSAAddTrustCA.crt)
Where's the trust root? Don't need it; you'll get an contains anchor
issue when testing.