This is a very basic TBSCertificate which would be valid except the version number is v4 (3). $ openssl asn1parse -i < [TBS CERTIFICATE] 0:d=0 hl=2 l= 60 cons: SEQUENCE 2:d=1 hl=2 l= 3 cons: cont [ 0 ] 4:d=2 hl=2 l= 1 prim: INTEGER :03 7:d=1 hl=2 l= 1 prim: INTEGER :01 10:d=1 hl=2 l= 3 cons: SEQUENCE 12:d=2 hl=2 l= 1 prim: OCTET STRING [HEX DUMP]:01 15:d=1 hl=2 l= 3 cons: SEQUENCE 17:d=2 hl=2 l= 1 prim: OCTET STRING [HEX DUMP]:05 20:d=1 hl=2 l= 30 cons: SEQUENCE 22:d=2 hl=2 l= 13 prim: UTCTIME :121018031200Z 37:d=2 hl=2 l= 13 prim: UTCTIME :131018145959Z 52:d=1 hl=2 l= 3 cons: SEQUENCE 54:d=2 hl=2 l= 1 prim: OCTET STRING [HEX DUMP]:83 57:d=1 hl=2 l= 3 cons: SEQUENCE 59:d=2 hl=2 l= 1 prim: OCTET STRING [HEX DUMP]:F3 -----BEGIN TBS CERTIFICATE----- MDygAwIBAwIBATADBAEBMAMEAQUwHhcNMTIxMDE4MDMxMjAwWhcNMTMxMDE4MTQ1OTU5WjADBAG DMAMEAfM= -----END TBS CERTIFICATE----- ERROR: Failed parsing version -----BEGIN ERRORS----- RVJST1I6IEZhaWxlZCBwYXJzaW5nIHZlcnNpb24K -----END ERRORS-----