And now try to load the same website over HTTPS
There are other ways you can try to optimise the certificate chain, though. For instance, you can pick a CA that uses ECC rather than RSA to make use of the much shorter key sizes. Entrust has one, I believe. Even if the root CA has an RSA key, they may still have ECC intermediates you can use.
But yes, ensure that you're serving the entire chain, but keep the chain as short as possible.
> Also HTTPS requires two additional round trips before it can do the first one — which gets us up to 1836ms!
0-RTT works after the first handshake, but enabling it allows for some forms of replay attacks so that may not be something you want to use for anything hosting an API unless you've designed your API around it.