We should clean up the unit test from ML-KEM with EnvelopedCms to document how some of the "bad" documents were constructed.
My main concern is that right now it's just a data blob. Instructions on how to make a replacement would be one fix, or the mutation with a comment like
// Inspection in an ASN.1 visualizer shows that the encrypted key is bytes 55-74
blob[59] ^= 0xFF;
Just a "if we need to recreate these for any reason, how does the next person know how to?"
Originally posted by @bartonjs in #133046 (comment)
We should clean up the unit test from ML-KEM with EnvelopedCms to document how some of the "bad" documents were constructed.
My main concern is that right now it's just a data blob. Instructions on how to make a replacement would be one fix, or the mutation with a comment like
Just a "if we need to recreate these for any reason, how does the next person know how to?"
Originally posted by @bartonjs in #133046 (comment)