Stop reading. This path is a course you can put down — and the YubiKey is the best first HSM precisely because you can: it is on your desk, not in a change window. Reading about custody produces opinions; adopting one real key produces reflexes — the touch that has to land inside the deadline, the refusal that names the pinRef it used. Work the previous frame now, token in hand.
You are done when three things are true:
- The console shows it: a root CA in custody
pkcs11, its key recording your module's name — and the module's Test connection is still green, login verified. - The audit log shows it: the module apply and the CA creation sit in the chain, and audit verify still answers intact.
- Unplugging proves it: pull the token and a signature becomes a per-request refusal that names the reason — no hang, no blind retry, and a restart still comes up without it. The key was never anywhere else.
Honest clock: with Test connection already green, the key and the root are about an hour — much of it reading refusals you caused on purpose, which is the point. Starting from a bare Windows machine, the WSL2-and-usbipd plumbing makes it an afternoon; the Windows + YubiKey quickstart walks that half.
When you come back, the next frame explains key wrapping — the trade goca makes you sign for when hardware alone cannot keep up.