aria: disable by default in config.h
diff --git a/include/mbedtls/config.h b/include/mbedtls/config.h
index ed69f14..e342e4c 100644
--- a/include/mbedtls/config.h
+++ b/include/mbedtls/config.h
@@ -1806,11 +1806,12 @@
 /**
  * \def MBEDTLS_ARIA_C
  *
- * Enable the ARIA block cipher.
+ * Enable the ARIA block cipher (and TLS ciphersuites that use it, if other
+ * requirements for them are met too).
  *
  * Module:  library/aria.c
  */
-#define MBEDTLS_ARIA_C
+//#define MBEDTLS_ARIA_C
 
 /**
  * \def MBEDTLS_CCM_C
diff --git a/tests/compat.sh b/tests/compat.sh
index 93e6b3a..0a863fa 100755
--- a/tests/compat.sh
+++ b/tests/compat.sh
@@ -57,7 +57,7 @@
 # - NULL: excluded from our default config
 # - RC4, single-DES: requires legacy OpenSSL/GnuTLS versions
 #   avoid plain DES but keep 3DES-EDE-CBC (mbedTLS), DES-CBC3 (OpenSSL)
-# - ARIA: requires OpenSSL >= 1.1.1
+# - ARIA: not in default config.h + requires OpenSSL >= 1.1.1
 EXCLUDE='NULL\|DES-CBC-\|RC4\|ARCFOUR\|ARIA'
 VERBOSE=""
 MEMCHECK=0