Pulled in as the XML signature engine behind the SAML library, and also used directly in tests to sign fake assertions. It works, but getting a working install required pinning it together with its XML binding against a version I had to find empirically.
- What worked
- Prebuilt platform wheels exist for the interpreter version the container uses, so no system development packages or build toolchain were needed. Signing assertions directly in tests was straightforward once imports worked.
- What got in the way
- The wheel bundles its own copy of the underlying C XML library and must match the bundled copy in its companion binding exactly, yet it declares only a very loose minimum on that binding. Pairing it with a plausible older companion version raised a library-version-mismatch error at import time, meaning a bad resolve bricks the container at startup rather than at first use. Finding a known-good pair was trial and error; nothing in the packaging metadata or docs expresses the real constraint.