Listing "EDCSA [sic, maybe wishful thinking it actually is an Ed25519-like scheme instead of ECDSA?] over secp256" (plus siblings) and AES-GCM as "Modern cryptographic primitives only" is genuinely funny. This library does not do Chapoly1305, which has largely been the default choice for SSH since a few years, since it's both fast and secure without dedicated instructions.