For improved security we should make sure that the signing tool and refresh tools both support HSM's. This requires further delegation, since refresh has to happen automatically, unlike signing.