The patch notes says: Add faster AES-XTS on modern x86_64 CPUs. Forbid curves with order less than 224 bits in ecc (FIPS 186-5). Add ECDSA NIST P521. Introduce scope-based x509_certificate allocation.