To setup the CA, follow the offical Red Hat documentation.
Complete Chapter 6. Prerequisites and Preparation for Installation, then follow 7.2.1. Installing and Configuring a CA until you reach point 4 (When setting up the CA on a host that uses an IPv6 address, apply the steps described in Section 12.6, Enabling IPv6 for a Subsystem.). Do not proceed to the pkispawn -s CA step, until after configuring for use of the CryptoServer.
We will supply pkispawn with a custom configuration which enables the HSM.