Long day today in preparation for an upcoming, and much needed, month off. Got to know `-engine pkcs11` as an option to many openssl tools today as I put the trio of Nitrokey HSM 2 modules purchased for my team to use in eliminating single points of failure in the safe storage of critical secrets. Sadly almost none of these tasks are even tangentially documented by Nitrokey, OpenSC, or anyone else - but now that I’ve sorted that out for my team I’ll put something together publicly as well.