Generating an EEK should be done using always the current keyversion of a key name. We should enforce that by API by handing off EEKs for the last keyversion of a keyname only, thus we should ask for EEKs for a keyname and the CryptoExtension should use the last keyversion.