ReaderIdentityConfig
The verifier's own reader-auth signing identity. privateKeyBase64 is the request-signing EC private key (CBOR-encoded, base64); certChainPem is its certificate chain, leaf-first, whose root a holder trusts via TrustConfig.readerRical / TrustConfig.readerRootsPem.