make sure the trusted cert's hrn is a prefix of the signed cert's hrn