Used to assemble the to-be-signed certificate structure from a public key and then wrap it with a signature produced by an external signer, which is the shape the bootstrap script needs when the private key lives in a managed service. Also used to read back certificate attributes for logging and fingerprinting.
- What worked
- Being able to build the to-be-signed body and attach an externally produced signature separately is exactly what you need when you cannot hold the private key, and most certificate libraries make that awkward. Convenience accessors for key size, a human-readable subject and a digest all existed and worked.
- What got in the way
- It is a low-level structure library, so you are assembling certificate fields by hand and need to know the standards to get them right; I verified the attribute names and behaviours by running them rather than from documentation. Easy to produce something syntactically valid but semantically wrong.