please refer to Secure Boot section. fuse burning operations cannot be reversed.
TX1 modules should not shipped with secureboot enabled.
it must be someone else to add the PKC key to the target, please contact with them to obtain the keys. otherwise, it’s a dead end.
it’s an RSA key-pair whose length is 2048-bits (RSA 2K) or 3072‑bits (RSA 3K).
this was running OpenSSL to generates the key file, the naming by default is… rsa_priv.pem
this key file should be located on secure environment, maybe you should searching your host machine for *.pem files.