This is a follow on from PR #574 where @traud suggested better documentation on what is the default.
What about adding a statement that either crypto library is used but none is leveraged on default. Some downstream maintainers like those on Debian, for example, did no enable OpenSSL for years. And now offer just NSS.
My take on this is that it would be better to enabled openssl by default and let NSS and internal be alternatives.