Parse UID fields correctly in our various certificate parsers.

Ideally we'd reuse the main certificate parser, but some of that blocks
on moving to BoringSSL for dependency reasons. Others I've split into

Bug: 1199744
