OK, the how makes sense. Still bugged by "why secp and not ed25519"
their rationale seems to be TPMs and HSMs, though id assume a lot support ed25519 as well due to ssh