In cases where it is interesting to only use fips algorithms from the systemcrypto backend, it would be interesting to support packaging for example openssl backend as as lib/fips140/systemcrypto.zip which would then slot into existing toolchain builds as is.
Note, this likely will restrict the number of available features, and might not be at all possible - as the rest of the golang toolchain has workaround specific to the geomys.zip snapshots.
In cases where it is interesting to only use fips algorithms from the systemcrypto backend, it would be interesting to support packaging for example openssl backend as as lib/fips140/systemcrypto.zip which would then slot into existing toolchain builds as is.
Note, this likely will restrict the number of available features, and might not be at all possible - as the rest of the golang toolchain has workaround specific to the geomys.zip snapshots.