Used public material to confirm that remote qualified signing should authorize the signer through the national high-assurance identity path, then modeled a redirect via the trust provider. No identity account was opened and no live authentication was run.
- What worked
- Documentation was sufficient to treat signer authorization as an external redirect rather than a home-grown certificate ceremony.
- What got in the way
- There was no direct API integration or sandbox login in this task, so runtime behavior was not observed.