[tpm2] Generate restricted signing key under owner hierarchy