1This is an otherwise valid TBSCertificate, however it lacks a version (making 2it v1). As such extensions are not allowed. 3 4 5$ openssl asn1parse -i < [TBS CERTIFICATE] 6 0:d=0 hl=2 l= 62 cons: SEQUENCE 7 2:d=1 hl=2 l= 1 prim: INTEGER :01 8 5:d=1 hl=2 l= 3 cons: SEQUENCE 9 7:d=2 hl=2 l= 1 prim: OCTET STRING [HEX DUMP]:01 10 10:d=1 hl=2 l= 3 cons: SEQUENCE 11 12:d=2 hl=2 l= 1 prim: OCTET STRING [HEX DUMP]:05 12 15:d=1 hl=2 l= 30 cons: SEQUENCE 13 17:d=2 hl=2 l= 13 prim: UTCTIME :121018031200Z 14 32:d=2 hl=2 l= 13 prim: UTCTIME :131018145959Z 15 47:d=1 hl=2 l= 3 cons: SEQUENCE 16 49:d=2 hl=2 l= 1 prim: OCTET STRING [HEX DUMP]:83 17 52:d=1 hl=2 l= 3 cons: SEQUENCE 18 54:d=2 hl=2 l= 1 prim: OCTET STRING [HEX DUMP]:F3 19 57:d=1 hl=2 l= 5 cons: cont [ 3 ] 20 59:d=2 hl=2 l= 3 cons: SEQUENCE 21 61:d=3 hl=2 l= 1 prim: OCTET STRING [HEX DUMP]:DD 22-----BEGIN TBS CERTIFICATE----- 23MD4CAQEwAwQBATADBAEFMB4XDTEyMTAxODAzMTIwMFoXDTEzMTAxODE0NTk1OVowAwQBgzADBAH 24zowUwAwQB3Q== 25-----END TBS CERTIFICATE----- 26 27ERROR: Unexpected extensions (must be V3 certificate) 28 29-----BEGIN ERRORS----- 30RVJST1I6IFVuZXhwZWN0ZWQgZXh0ZW5zaW9ucyAobXVzdCBiZSBWMyBjZXJ0aWZpY2F0ZSkK 31-----END ERRORS-----