> +        if (!(tls_item_in_cipher_list("AES-128-GCM", options->ncp_ciphers)
> +              && tls_item_in_cipher_list("AES-256-GCM", 
> options->ncp_ciphers)))

What about AES-192-GCM?  What *exactly* does IV_NCP=2 guarantee?

Can we have something nicer for cipher negotiation instead?

