While it’s less clear to me if tpm2-openssl itself supports the use of opaque certificates (all the examples given in the docs use regular PEM files for the public certificates), TPM hardware and software security modules certainly offer that feature.
As per https://discuss.python.org/t/pre-pep-discussion-revival-of-pep-543/51263/47