Port tls12_check_peer_sigalg to CBS. This avoids having to do the CBS_skip dance and is better about returning the right alert. Change-Id: Id84eba307d7c67269ccbc07a38d9044b6f4f7c6c Reviewed-on: https://boringssl-review.googlesource.com/1169 Reviewed-by: Adam Langley <agl@google.com>