Chose remote hash signing with this qualified provider, implemented a CSC client, and covered it with mocked HTTP. Public docs explained subscriber versus signing-application roles, but there was no live account and one vendor search failed.
- What worked
- The hash-only CSC pattern matched the hosting constraint of not sending the PDF out. Test and production credential placement was clear enough to wire env and secret injection without putting the secret in charts.
- What got in the way
- Signup is contract-based rather than self-serve, billing and platform accounts stay outside the app, and a first documentation search failed so setup details had to be pieced together from later pages.
