I need to add generated attestation key/application key into tpm2-pkcs11. It supports tss2 pem format like this:
-----BEGIN TSS2 PRIVATE KEY-----
...
-----END TSS2 PRIVATE KEY-----
Also AK should be in persistent handle.
How could I add attestation key (generated with tpm.NewAK(...)) into persistent handle and get TSS2 pem from attested application key (generated with tpm.NewKey(...))?