Add ChangeLog entry for MBEDTLS_CIPHER_ENCRYPT_ONLY

Signed-off-by: Yanray Wang <yanray.wang@arm.com>
diff --git a/ChangeLog.d/add-cipher-encrypt-only.txt b/ChangeLog.d/add-cipher-encrypt-only.txt
new file mode 100644
index 0000000..1a0181d
--- /dev/null
+++ b/ChangeLog.d/add-cipher-encrypt-only.txt
@@ -0,0 +1,6 @@
+Features
+   * Add support to remove xxx_setkey_dec and xxx_decrypt for cipher type of
+     AES, ARIA, CAMELLIA and DES. This is achieved by implicitly enabling
+     MBEDTLS_CIPHER_ENCRYPT_ONLY when
+     - ECB and CBC cipher modes are not requested via the PSA API.
+     - ECB, CBC, XTS and KW are not enabled in the legacy API.