I'm burning through a bunch of work so I can't do it right now, but if you can extract the GCM in the NSP/XCI, you can probably just get the SHA-1 of that to verify that it's actually using SHA-1.
From there, get another rom, trim the first 100 bytes and generate another SHA-1.