It would be nice to have *optional* support for libsodium as an alternative to the `openssl` extension, since libsodium is moving into core. This could be hacked in place, or done by isolating the crypto use in CryptoKey. Either way might complicate cipher selection (needs research).