computeSignature, but through an opaque key: accepts either a raw
PrivateKey (wrapped locally, byte-identical result) or an
IKeyOperations whose key may live in an HSM/KMS. This is the
choke point every application-level signature goes through — the
client's ActivateSession signature, the server's CreateSession signature,
and the X509 user-token signature.
signedCertificate picks what is signed when senderCertificate is a chain:
its leaf (the default, what OPC 10000-4 §6.1.8 recommends) or the whole
chain as given, the legacy calculation some deployed applications still use.
computeSignature, but through an opaque key: accepts either a raw PrivateKey (wrapped locally, byte-identical result) or an IKeyOperations whose key may live in an HSM/KMS. This is the choke point every application-level signature goes through — the client's ActivateSession signature, the server's CreateSession signature, and the X509 user-token signature.
signedCertificatepicks what is signed whensenderCertificateis a chain: its leaf (the default, what OPC 10000-4 §6.1.8 recommends) or the whole chain as given, the legacy calculation some deployed applications still use.