It is a private key probably still stored in a hardware module controlled by NSA CES, isn’t it?
This isn’t a problem: Just ask for decrypts by the usual FISA CES API and you don’t need the private key directly.