Certify now returns raw TPMT_SIGNATURE, so no need to pack it.
* replace CertifyCreation() by CertifyEx() to handle certification of objects for which we cannot extract CreationData * add AK.Certify(handle) allowing to certify externally-created keys