merge fips-mode-setup package into the scripts subpackage
Also:
OSPP subpolicy: remove AES-CCM
openssl: handle the AES-CCM removal properly
openssh/libssh: drop CBC ciphersuites from DEFAULT and FIPS
add AD-SUPPORT subpolicy which re-enables RC4 for Kerberos
gnutls: disallow X448/ED448 in FIPS policy