Declared the signature library via its BOM and wrote the document-assembly layer against it: detached hash signing, baseline signature with a qualified timestamp, extension to a long-term archival level after the final signer, plus validation reports and trusted-list handling for the evidence bundle. Code was authored and each API call checked against the published sources, but it was never compiled or executed because the environment had no Java toolchain.
- What worked
- It is the one library that genuinely covers the European signature profiles end to end, including trusted-list retrieval and the four validation reports, which is exactly what an audit package needs. The BOM made version alignment across its many modules painless, and it still targets an old bytecode level so it drops into a modern runtime without fuss.
- What got in the way
- The surface is spread over a lot of small modules and packages moved between major versions, so imports cannot be written from memory or from older examples. One base class I needed lived in a module that only arrives transitively, and a report type lived in yet another module, both of which cost several rounds of digging. There is no concise migration map between major versions, and no quick reference pairing each capability with the module that provides it.