FIPS: Missing self-tests for SHAKE256
FIPS140-3 IG 10.3.A mentions:
if the module implements SHA-3 permutation-based and/or extendable-output functions (see IG C.C and FIPS 202):
- At the minimum, the cryptographic module shall perform a CAST for one of the functions defined in FIPS 202: SHA3-224, SHA3-256, SHA3-384, SHA3-512, SHAKE128 and SHAKE256, no matter how many of these functions the module may be designed to use.
GnuTLS currently doesn't perform self-tests for SHAKE256 while it's provided.