You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

提取tbsCertificate后无法用OpenSSL解析为X509格式的原因及内容查看方法

Why You Can't Parse Extracted tbsCertificate with openssl x509 & How to View It

Let's break down why your attempt failed first, then walk through the correct ways to inspect the tbsCertificate content.

Why the openssl x509 Command Fails

The openssl x509 tool is built to parse full X.509 certificates, which follow a strict ASN.1 structure containing three core components:

  • The tbsCertificate (the signed body of the certificate)
  • The signature algorithm identifier
  • The signature value itself

Your extracted bd.cer.tbsCertificate is only the first component—its ASN.1 type is X509_CINF, which matches the "Type=X509_CINF" in your error. When you run openssl x509 on this file, the tool expects the complete certificate wrapper, so it throws an ASN.1 parsing error because the structure doesn't align with what it's designed to process.

Correct Ways to View tbsCertificate Content

Method 1: Directly Parse tbsCertificate Without Extracting It

This is the simplest and most reliable approach—use openssl asn1parse with the -strparse flag to jump straight to the tbsCertificate offset:
From your earlier asn1parse output, the tbsCertificate starts at offset 4 (the number before d=1). Run this command:

openssl asn1parse -inform der -in bd.cer -strparse 4 -text

The -text flag decodes the ASN.1 fields into human-readable format, so you'll see all key details in the tbsCertificate: issuer, subject, validity period, public key information, extensions, and more.

Method 2: Parse Your Extracted tbsCertificate File

If you want to work with the bd.cer.tbsCertificate file you created, avoid openssl x509—use openssl asn1parse instead, as it handles raw ASN.1 structures:

openssl asn1parse -inform der -in bd.cer.tbsCertificate -text

This will correctly decode the X509_CINF structure into readable text.

Quick Note on Your dd Command

Your dd command is actually correct:

dd if=bd.cer of=bd.cer.tbsCertificate skip=4 bs=1 count=2330

Since hl=4 (header length) + l=2326 (content length) = 2330, you're capturing the full tbsCertificate ASN.1 sequence. The only issue was using the wrong OpenSSL tool to parse it afterward.

内容的提问来源于stack exchange,提问作者Swa1n Suen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 21:42:53