RACF does support private keys for PKCS12 format. The resolution is to convert the certificates to PKCS12 format.
Converting PEM certificates to PKCS12 Format
PEM certificates can be converted to PKCS12 using the OpenSSL utility available through OpenSSL project at www.openssl.org. Note that the utility is also distributed with XCOM. For XCOM for z/OS, it's in the openssl directory which is part of the tar file that included the sample configssl.cnf file.
With CA XCOM for Windows and Unix and LINUX it's included with the XCOM executables.
The syntax of the openssl command for the conversion is:
openssl pkcs12 -export -in cert.pem -inkey key.pem -out cred.p12
where cert.pem is the certificate, key.pem is the private key and cred.p12 is the output file. Note that if the private key is encrypted you will be prompted for the pass phase. You will also be prompted for an export password which you will then need to pass to RACF when you import the cred.p12 file.