I was trying to see what's the content of a tbsCerticate.
This is what I have done:
- Download a certificate from website (baidu.com) in der binary format.
- Use
openssl x509 -in bd.cer -inform cer -text -noout >> bd.cer.noout.txtto translate into text. Now I can see what's in the certificate
openssl asn1parse -inform der -in bd.cer > bd.cer.asn1parse the certificate. According to rfc5280, second line is tbsCertificate content, which is4:d=1 hl=4 l=2326 cons: SEQUENCE.dd if=bd.cer of=bd.cer.tbsCertificate skip=4 bs=1 count=2330to dump the bytes.openssl x509 -in bd.cer.tbsCertificate -inform der -text -noout >> bd.cer.tbs.txtNow I want to parse it bd.cer.tbsCertificate to x509 format to see it, but it failed.
unable to load certificate
140421447947392:error:0D0680A8:asn1 encoding routines:asn1_check_tlen:wrong tag:../crypto/asn1/tasn_dec.c:1149:
140421447947392:error:0D07803A:asn1 encoding routines:asn1_item_embed_d2i:nested asn1 error:../crypto/asn1/tasn_dec.c:309:Type=X509_CINF
140421447947392:error:0D08303A:asn1 encoding routines:asn1_template_noexp_d2i:nested asn1 error:../crypto/asn1/tasn_dec.c:646:Field=cert_info, Type=X509
I want to know why I can't translate the bd.cer.tbsCertificate into x509 just like bd.cer. Do I miss something? From the error, it seems that the structure is not right.
What should I do if I want to see tbsCertificate in txt to know what exactly are encrypted. Thank you for your help!