IX509AttributeRenewalCertificate::InitializeDecode method (certenroll.h)

The InitializeDecode method initializes the object from a Distinguished Encoding Rules (DER) encoded byte array that contains the certificate to be renewed. The byte array is represented by a Unicode-encoded string.

Syntax

HRESULT InitializeDecode(
  [in] EncodingType Encoding,
  [in] BSTR         strEncodedData
);

Parameters

[in] Encoding

An EncodingType enumeration value that specifies the type of Unicode encoding applied to the input string.

[in] strEncodedData

A BSTR variable that contains the DER-encoded certificate.

Beginning with Windows 7 and Windows Server 2008 R2, you can specify a certificate thumb print or serial number rather than an encoded certificate. Doing so causes the function to search the appropriate local stores for the matching certificate. Keep in mind the following points:

  • The BSTR must be an even number of hexadecimal digits.
  • Whitespace between hexadecimal pairs is ignored.
  • The Encoding parameter must be set to XCN_CRYPT_STRING_HEXRAW.
  • If a private key is needed, only the personal and request stores are searched.
  • If a private key is not needed, the root and intermediate CA stores are also searched.

Return value

If the function succeeds, the function returns S_OK.

If the function fails, it returns an HRESULT value that indicates the error. For a list of common error codes, see Common HRESULT Values.

Remarks

The object identifier (OID) for this attribute is XCN_OID_RENEWAL_CERTIFICATE (1.3.6.1.4.1.311.13.1). For more information, see CERTENROLL_OBJECTID.

You can use this method if you have a DER-encoded Abstract Syntax Notation One (ASN.1) object that contains the attribute value. You must supply the DER-encoded object in a Unicode encoded string. For more information, see the IBinaryConverter interface.

You must call either InitializeEncode or InitializeDecode before you can use an IX509AttributeRenewalCertificate object. The two methods complement each other. The InitializeEncode method enables you to construct an encoded ASN.1 structure from raw data, and the InitializeDecode method enables you to initialize raw data from an encoded ASN.1 structure. You can call the RenewalCertificate property to retrieve the raw data.

Requirements

Requirement Value
Minimum supported client Windows Vista [desktop apps only]
Minimum supported server Windows Server 2008 [desktop apps only]
Target Platform Windows
Header certenroll.h
DLL CertEnroll.dll

See also

IX509AttributeRenewalCertificate