Yocto Secure boot on CM3 uploading keys

I am using the scarthgap with meta-rockchip from https://git.yoctoproject.org/meta-rockchip/

All seems to work OK.

I am trying to enable secure boot. I have started by getting the bootloader signed manually using the rk_sign_tool.

Does anyone have any information on uploading the keys to a rk3566? I can not find much information about it. most of the information i find is for the rk3568 or other chips.