See https://github.com/Mbed-TLS/mbedtls/issues/8136 - for 224-bit curves, we can just remove them and be done with it. Note that there are uses on the TLS side and in the framework, so we probably want to start with those.