Best practice would be to leverage an HSM (hardware security module) to store such material. Hyperledger Fabric supports HSMs that implement the PKCS11 standard API (though we do not publish images with PKCS11 support enabled by default, you would need to build a set of images with the appropriate compile flag).