Working with UserX509Certificate RRS feed

  • Question

  • Hi,

    i am trying to retrieve the certificate of a contact. It was set in Outlook by importing it in the certificate tab.

    It is available by using PidTagUserX509Certificate on EWS, see
    but i have to admit i do not understand how to handle the object as described in the documentation.

    I try to base64-decode the retrieved data, then use a X509 CertificateFactory to read the certificate, the same as i handle the MSExchangeCertificate and UserSMIMECertificate values.

    This leads to an parsing exception: error:0c0000be:ASN.1 encoding routines:OPENSSL_internal:WRONG_TAG

    My Code runs on Android, but the issue should be universal.

    You can find the base64 data here:

    Any idea how i could get to the certificate?

    Friday, March 6, 2020 7:47 AM


  • Got an answer on stackoverflow:

    You have to skip the first 12 Bytes, it seems to be some Kind of enevelope. In any case, leaving this here just in case somebody has the same arcane issue at some time.

    • Marked as answer by Simon Hain Friday, March 6, 2020 8:55 AM
    Friday, March 6, 2020 8:55 AM