sapgenpse and CommonCryptoLib — managing the PSEs behind SNC and SSL/TLS: get_pse, gen_pse, import_own_cert, export_own_cert, maintain_pk, seclogin, the PSE/cred_v2 pairing that causes "works as one user, fails as another", SECUDIR, PSE types, SAProuter certificate renewal, HSM-backed PSEs.