[mbed-tls] TLS client authentication with a TPM-held private key (Mbed TLS 4.2): is our approach right, and how do we create the key ID?