openssl enc -aes-256-cbc -pbkdf2 -salt -in $1 -out ${1%%.*}.dat -k ${PASS}
openssl enc -aes-256-cbc -pbkdf2 -d -in ${FILE} -out ${FILE%%.*}.crt -k ${PASS}
openssl rsa -des3 -in ca-file.pem -out ca-file.pem.new
openssl x509 -in client-cert.pem -fingerprint -noout | sed 's/://g' | tr '[:upper:]' '[:lower:]'
openssl s_client -connect $HOST:$PORT -showcerts -verify 1
openssl rand -base64 12
openssl s_client -showcerts -connect example.org:443 </dev/null 2>/dev/null | openssl x509 -outform PEM > example-org.pem