Logging something to stderr was not helpful, and it's best to be on the safe side anyways. Whitelist a single null byte following the SAN extension. This is a harmless and common error. As of now, all certificates in the CT logs parse successfully.