Merge pull request #779 from paul-elliott-arm/discrepancy_cert_2_16

Backport 2.16: Add missing tag check to signature check on certificate load