This is a v2 certificate which contains extensions. This is invalid since v2 does not have extensions defined. $ openssl asn1parse -i < [TBS CERTIFICATE] 0:d=0 hl=2 l= 67 cons: SEQUENCE 2:d=1 hl=2 l= 3 cons: cont [ 0 ] 4:d=2 hl=2 l= 1 prim: INTEGER :01 7:d=1 hl=2 l= 1 prim: INTEGER :01 10:d=1 hl=2 l= 3 cons: SEQUENCE 12:d=2 hl=2 l= 1 prim: OCTET STRING [HEX DUMP]:01 15:d=1 hl=2 l= 3 cons: SEQUENCE 17:d=2 hl=2 l= 1 prim: OCTET STRING [HEX DUMP]:05 20:d=1 hl=2 l= 30 cons: SEQUENCE 22:d=2 hl=2 l= 13 prim: UTCTIME :121018031200Z 37:d=2 hl=2 l= 13 prim: UTCTIME :131018145959Z 52:d=1 hl=2 l= 3 cons: SEQUENCE 54:d=2 hl=2 l= 1 prim: OCTET STRING [HEX DUMP]:83 57:d=1 hl=2 l= 3 cons: SEQUENCE 59:d=2 hl=2 l= 1 prim: OCTET STRING [HEX DUMP]:F3 62:d=1 hl=2 l= 5 cons: cont [ 3 ] 64:d=2 hl=2 l= 3 cons: SEQUENCE 66:d=3 hl=2 l= 1 prim: OCTET STRING [HEX DUMP]:DD -----BEGIN TBS CERTIFICATE----- MEOgAwIBAQIBATADBAEBMAMEAQUwHhcNMTIxMDE4MDMxMjAwWhcNMTMxMDE4MTQ1OTU5WjADBAG DMAMEAfOjBTADBAHd -----END TBS CERTIFICATE-----