Add sign/verify digest API to handle an explicit digest instead of finalising