Move signing digest out of CERT.