We do the hashing ourselves so that it's easy to use any hash function in the future. If you create a Keystore key but decide to use a hash function you didn't specify at generation time, it will be rejected by the API.
I don't know if you've done it correctly.
You can use the built-in signature digest support and still add support for whatever you want in the future.