Hi guys,
it seems that there is a "problem" with parsing some CSRs using the mbedtls_x509_csr_parse function. If the requests starts with "----BEGIN NEW CERTIFICATE REQUEST----" instead of "----BEGIN CERTIFICATE REQUEST----" (without the new), parsing will fail.
We ran into this problem while parsing CSRs generated by (I guess) Windows machines.
Not that this is a show stopper, but it was definitely not the first thing we were looking for when the errors occurred and only realized it by accident ;).
Best,
Michael