add a changelog entry for finalize_with_tag and move the note (#3531)

diff --git a/CHANGELOG.rst b/CHANGELOG.rst
index d0988b3..5223fea 100644
--- a/CHANGELOG.rst
+++ b/CHANGELOG.rst
@@ -6,6 +6,10 @@
 
 .. note:: This version is not yet released and is under active development.
 
+* Add support for providing ``tag`` during
+  :class:`~cryptography.hazmat.primitives.ciphers.modes.GCM` finalization via
+  :meth:`~cryptography.hazmat.primitives.ciphers.AEADDecryptionContext.finalize_with_tag`.
+
 
 1.8.1 - 2017-03-10
 ~~~~~~~~~~~~~~~~~~
diff --git a/docs/hazmat/primitives/symmetric-encryption.rst b/docs/hazmat/primitives/symmetric-encryption.rst
index 5f4d7bf..e99c2c0 100644
--- a/docs/hazmat/primitives/symmetric-encryption.rst
+++ b/docs/hazmat/primitives/symmetric-encryption.rst
@@ -574,6 +574,10 @@
 
     .. method:: finalize_with_tag(tag)
 
+        .. note::
+
+            This method is not supported when compiled against OpenSSL 1.0.1.
+
         :param bytes tag: The tag bytes to verify after decryption.
         :return bytes: Returns the remainder of the data.
         :raises ValueError: This is raised when the data provided isn't
@@ -587,10 +591,6 @@
         object, this method must be used instead of
         :meth:`~cryptography.hazmat.primitives.ciphers.CipherContext.finalize`.
 
-    .. note::
-
-        This method is not supported when compiled against OpenSSL 1.0.1.
-
 .. class:: CipherAlgorithm
 
     A named symmetric encryption algorithm.