=== How does this work? For AES-GCM and AES-CCM, NIST recommends generating a nonce using either a deterministic approach or using a 'Random Bit Generator (RBG)'. include::fix/randomized-nonce.adoc[] include::fix/deterministic-nonce.adoc[]