提取tbsCertificate后无法用OpenSSL解析为X509格式的原因及内容查看方法
openssl x509 & How to View It Let's break down why your attempt failed first, then walk through the correct ways to inspect the tbsCertificate content.
Why the openssl x509 Command Fails
The openssl x509 tool is built to parse full X.509 certificates, which follow a strict ASN.1 structure containing three core components:
- The
tbsCertificate(the signed body of the certificate) - The signature algorithm identifier
- The signature value itself
Your extracted bd.cer.tbsCertificate is only the first component—its ASN.1 type is X509_CINF, which matches the "Type=X509_CINF" in your error. When you run openssl x509 on this file, the tool expects the complete certificate wrapper, so it throws an ASN.1 parsing error because the structure doesn't align with what it's designed to process.
Correct Ways to View tbsCertificate Content
Method 1: Directly Parse tbsCertificate Without Extracting It
This is the simplest and most reliable approach—use openssl asn1parse with the -strparse flag to jump straight to the tbsCertificate offset:
From your earlier asn1parse output, the tbsCertificate starts at offset 4 (the number before d=1). Run this command:
openssl asn1parse -inform der -in bd.cer -strparse 4 -text
The -text flag decodes the ASN.1 fields into human-readable format, so you'll see all key details in the tbsCertificate: issuer, subject, validity period, public key information, extensions, and more.
Method 2: Parse Your Extracted tbsCertificate File
If you want to work with the bd.cer.tbsCertificate file you created, avoid openssl x509—use openssl asn1parse instead, as it handles raw ASN.1 structures:
openssl asn1parse -inform der -in bd.cer.tbsCertificate -text
This will correctly decode the X509_CINF structure into readable text.
Quick Note on Your dd Command
Your dd command is actually correct:
dd if=bd.cer of=bd.cer.tbsCertificate skip=4 bs=1 count=2330
Since hl=4 (header length) + l=2326 (content length) = 2330, you're capturing the full tbsCertificate ASN.1 sequence. The only issue was using the wrong OpenSSL tool to parse it afterward.
内容的提问来源于stack exchange,提问作者Swa1n Suen

