This section describes how to display the ASN.1 structure of a certificate using the EJBCA CLI.
You can generate an ASN.1 dump of a certificate to inspect its internal structure and encoding. This is useful for troubleshooting, validation, or understanding how certificate fields are represented at the binary level.
Prerequisites
-
Access to the EJBCA command-line interface
-
A certificate file in either PEM or DER format
Command Syntax
Run the following command from the EJBCA installation directory:
Bash
$ bin/ejbca.sh asn1dump <certificate-file>
-
<certificate-file>: Path to the certificate file (PEM or DER encoded)
Example
$ bin/ejbca.sh asn1dump managementca.pem