BINMAN tool is currently used to sign u-boot binary in Linux SDK, where the signing key is locatable under Linux SDK folder. There's a need to use the signing key stored in the external secure key server when switching to the production key. The FAQ discuss options on how to sign u-boot binary on an external secure key server using AM62x Linux SDK as an example.