Hardware random number generator (HWRNG)

hello edmund.grimley-evans,

there’s hardware crypto security engine key slot for storing SBK, KEK, SSK…etc.
please also refer to Generating the RSA Key Pair, and Preparing the SBK Key sessions, you should generate and maintain keys by yourself.

there’s similar discussion thread for your reference, Topic 74903, you may use keys generated by HSM,
BUT, fusing and signing takes .pem file as the input; you’ll also need to consider how to convert your HSM output key as *.pem file.
thanks