Convert the RSA keys stored in the HSM into a format that BIND 9 understands. The dnssec-keyfromlabel tool from BIND 9 can link the raw keys stored in the HSM with the K<zone>+<alg>+<id> files. Provide the OpenSSL engine name (pkcs11), the algorithm and the PKCS#11 label that specify the token the name of the PKCS#11 object (called label when generating the keys using p11tool2) and the HSM Slot PIN.