Home / Alt manpages / openssl-asn1parse(1ssl)

  • openssl-asn1parse(1ssl)
  • OpenSSL command
  • linux

Inspect DER and PEM Structures with openssl asn1parse

You will use openssl asn1parse to inspect an ASN.1 file, interpret its offsets and lengths, drill into a nested value, and generate a small DER fixture for testing. Allow about 15 minutes if the input file is ready. The commands are diagnostic: they decode structure, but they do not prove that a certificate, key or protocol message is trustworthy.

This guide follows the OpenSSL 3.6.1 command installed on this machine. The local openssl-asn1parse(1ssl) page carries a 3.0.13 header, so check openssl version on another host before relying on version-specific output.

1. Check the installed command

Start without elevated privileges. Parsing a readable file does not need sudo, and adding it can hide an ordinary file-permission problem.

$ command -v openssl
/home/linuxbrew/.linuxbrew/bin/openssl
$ openssl version
OpenSSL 3.6.1 27 Jan 2026
$ openssl asn1parse -help
Usage: asn1parse [options]

Your path and build date can differ. Check that the help lists the options you intend to use, especially -inform, -strparse, -genstr and -genconf.

Checkpoint

You have confirmed the binary and version, and you know the input is safe to inspect. Do not paste private keys or confidential protocol captures into a shared terminal session or a ticket that records command output.

2. Parse a PEM input

The default input format is PEM and the default input source is standard input. Give the file explicitly when investigating a saved object:

$ openssl asn1parse -in /path/to/object.pem

For a certificate, output usually begins with a line shaped like this:

0:d=0  hl=4 l= 681 cons: SEQUENCE

The first number is the byte offset. d= is the nesting depth. hl= is the header length, covering the tag and length octets, while l= is the length of the contents. cons identifies a constructed value that contains other values; prim identifies a primitive value. Names such as SEQUENCE, INTEGER and BIT STRING are ASN.1 types.

Add -i when indentation makes the tree easier to scan:

$ openssl asn1parse -in /path/to/object.pem -i

Do not treat a successful parse as a signature or policy check. Use a suitable command such as openssl x509 or openssl verify for certificate-specific questions.

3. Parse DER explicitly

DER is binary encoding, so select it instead of relying on the PEM default:

$ openssl asn1parse -inform DER -in /path/to/object.der -i

The command prints the parsed tree to standard output. It does not rewrite the input. If the file is actually PEM, DER parsing normally fails with an encoding error. If a DER file starts at a known embedded offset, limit the view without modifying it:

$ openssl asn1parse -inform DER -in /path/to/container.der -offset 128 -length 64

Offsets and lengths are bytes, not line numbers. Verify them against the output from a full parse before using them in a script. A wrong offset can produce an error or make unrelated bytes look like a plausible short value.

Checkpoint

You can identify the top-level object, its encoding, and the byte offset of the nested value you want to inspect.

4. Drill into a nested value with strparse

-strparse follows the contents octets of the ASN.1 object at the supplied offset. It is useful for values wrapped inside an OCTET STRING or BIT STRING. The option can be repeated for deeper nesting.

For example, after finding a public-key BIT STRING at offset 229 in a certificate, inspect its contents with:

$ openssl asn1parse -in /path/to/certificate.pem -strparse 229 -i

Use the offset from your own parse, not the example number. The result should show a new ASN.1 tree whose first offset is normally zero. If you need to extract the decoded bytes, add -out:

$ openssl asn1parse -in /path/to/certificate.pem -strparse 229 -out /tmp/nested.der -noout
$ openssl asn1parse -inform DER -in /tmp/nested.der -i

This writes a new DER file under /tmp. It does not change the certificate. Treat extracted material as sensitive if the source contains a private key or credentials. Remove it through your normal temporary-file cleanup process once it is no longer needed.

5. Generate a small fixture

-genstr generates ASN.1 data using the ASN1_generate_nconf format, then parses it. This is useful for testing a parser without copying a real credential into a test directory:

$ openssl asn1parse -genstr 'UTF8:Hello World'
    0:d=0  hl=2 l=  11 prim: UTF8STRING        :Hello World

To save the generated encoding as DER and suppress the tree printed by that invocation, use both -noout and -out:

$ openssl asn1parse -genstr 'UTF8:Hello World' -noout -out /tmp/hello.der
$ openssl asn1parse -inform DER -in /tmp/hello.der
    0:d=0  hl=2 l=  11 prim: UTF8STRING        :Hello World

-out always writes DER. It is not a request to produce PEM, and it does not mean that parsed output will appear on standard output. Avoid redirecting over a valuable file with >; use a new path such as the temporary example above.

6. Generate a configured sequence

Use -genconf when the generated structure needs named sections. This verified configuration creates a sequence containing a boolean and an explicitly tagged UTF8 string:

asn1=SEQUENCE:seq_sect

[seq_sect]
field1=BOOL:TRUE
field2=EXP:0, UTF8:some random string

Save it as asn1.cnf, then generate a DER file:

$ openssl asn1parse -genconf asn1.cnf -noout -out /tmp/asn1.der
$ openssl asn1parse -inform DER -in /tmp/asn1.der -i
    0:d=0  hl=2 l=  25 cons: SEQUENCE
    2:d=1  hl=2 l=   1 prim:  BOOLEAN           :255
    5:d=1  hl=2 l=  20 cons:  cont [ 0 ]
    7:d=2  hl=2 l=  18 prim:   UTF8STRING        :some random string

The section name and field syntax are part of the ASN.1 generation format, not ordinary shell assignments. A sequence or set that needs child fields must have a configuration section. If you use -genstr 'SEQUENCE:...' without that section, the installed command reports that a sequence or set needs config.

Safety boundary

Generation and extraction change only the files named by -out. Do not point those options at a live key store, service configuration or production certificate. If a generated file is no longer useful, inspect its path before deleting it; deletion is irreversible.

7. Investigate failures without guessing

For an encoding error, first confirm the format, path and file type:

$ file /path/to/object.der
$ test -r /path/to/object.der && echo readable
$ openssl asn1parse -inform DER -in /path/to/object.der

For a confusing tree, rerun without -strparse, record the relevant offset, then add -i. For unknown values, -dump prints hexadecimal data and -dlimit 16 restricts that dump to the first 16 bytes:

$ openssl asn1parse -inform DER -in /path/to/object.der -dump -dlimit 16

Do not assume that a displayed OID name is available on every host. OpenSSL prints an unknown OID numerically. A file passed to -oid can add a numerical OID, one-word short name and long name, for example:

1.2.3.4       shortName       A long name

Keep that OID file with the diagnostic procedure so another operator can reproduce the same labels. Labels improve readability; they do not change the encoded bytes.

Done means

  • You confirmed the installed OpenSSL version and checked the local option syntax.
  • You selected PEM or DER explicitly when the input format mattered.
  • You read offsets as byte positions and used a verified offset with -strparse.
  • You know that -out writes DER and that -noout suppresses parsed output.
  • You kept generated and extracted files away from production key stores and service configuration.
  • You used a certificate or key-specific command for validation rather than treating ASN.1 parsing as proof of trust.