fips140=only from #70123 breaks any non-FIPS cryptography. Testing a mode designed to break things is tricky.
Running the whole test suite is prohibitive. Instead, we should probably write a dedicated test that goes through things that are expected to work, and things that are not expected to work.
fips140=only
from #70123 breaks any non-FIPS cryptography. Testing a mode designed to break things is tricky.Running the whole test suite is prohibitive. Instead, we should probably write a dedicated test that goes through things that are expected to work, and things that are not expected to work.