The public OpenAPI descriptions were used to design a three-step signing adapter and a validation call, then the contract was tested with simulated responses. No live internal DSS deployment, certificate, HSM alias, revocation source, or timestamp service was available.
- What worked
- The documented schemas exposed the certificate, data-to-sign, signature value, signed document, and validation structures needed for a concrete adapter.
- What got in the way
- Production behavior could not be assessed because the required internally hosted DSS stack and cryptographic infrastructure had not yet been provisioned.
