Loading…
The OpenSSL Conference is the global meeting place for the people who build, deploy, govern, and rely on secure digital infrastructure. It brings together developers, security engineers, researchers, policymakers, enterprises, legal and compliance professionals, and community contributors, all united by a shared commitment to stronger open-source security.
Type: Security clear filter
Tuesday, October 13
 

11:20 CEST

Rebranding OpenSSL FIPS 140-3 Validations from a Laboratory Perspective
Tuesday October 13, 2026 11:20 - 11:50 CEST
Why a vendor would rebrand the OpenSSL FIPS Provider, what the rebranded certificate allows, and alternatives (full validation, binding).
Speakers
JP

Jonathan Park

Associate FIPS Tester, Lightship Security, Inc
Jonathan (Jon) Park is an Associate FIPS Tester with Lightship Security Inc. and brings more than 25 years of experience in IT, project support, and compliance testing. Leveraging a strong background in technology operations and quality assurance, he now focuses on cybersecurity testing... Read More →
Tuesday October 13, 2026 11:20 - 11:50 CEST
Room 1
  Security, Talk

13:50 CEST

Securosys — Session Title Coming Soon
Tuesday October 13, 2026 13:50 - 14:20 CEST
Session details are being finalized with the speaker and will be published here as soon as they are available.
Speakers
avatar for Marcel Dasen

Marcel Dasen

Executive Vice President of Engineering, Securosys
Throughout his career, Marcel has amassed a comprehensive skill set in engineering, applied cryptography, and technical leadership. He is an expert in designing and implementing secure, scalable, and high-performance systems, with a deep understanding of the latest trends and best... Read More →
Tuesday October 13, 2026 13:50 - 14:20 CEST
Room 1
  Security, Talk

14:20 CEST

Beyond the Checkbox: How Product Certifications Drive Ongoing Security Strategy and Market Access
Tuesday October 13, 2026 14:20 - 14:50 CEST
Beyond the Checkbox will show how product certifications can become a strategic advantage instead of just a compliance burden. Using real-world examples, you'll see how to reduce engineering effort through smarter operating models, reuse and maintenance paths, lab partnerships, and automation and AI, while keeping rigor intact as requirements like PQC and entropy continue to evolve. You'll leave with practical ideas to make your certification program more efficient, strategic, and valuable to the business.
Speakers
LR

Lisa Rogers

Product Certification, NetApp, Inc.
Lisa Rogers is a Technical Program Manager at NetApp, with more than 12 years of experience leading certifications including FIPS 140, Common Criteria, CSfC, DoDIN APL, FedRAMP, HITRUST, EUCC, 508 VPAT, Ready Logo, USGv6, and related frameworks. She partners with engineering, legal... Read More →
Tuesday October 13, 2026 14:20 - 14:50 CEST
Room 1
  Security, Talk

15:20 CEST

The EU CRA vs. Community: Why You’re Safe, and How Stewards Help
Tuesday October 13, 2026 15:20 - 16:00 CEST
The CRA is the first horizontal law to recognise open source in the commercial supply chain. An opportunity to standardise and elevate security; how stewards help.
Speakers
avatar for Jaroslav Řezník

Jaroslav Řezník

Program Manager, Red Hat Czech, s.r.o.
Jaroslav is the Principal Program Manager guiding standards and regulatory initiatives for Red Hat's Product Security Compliance team. His 18-year tenure is defined by his unique versatility: he is as dedicated to his beloved Fedora open-source community as he is to ensuring Red Hat... Read More →
Tuesday October 13, 2026 15:20 - 16:00 CEST
Room 3
  Security, Talk

16:05 CEST

During a Breach: How Encryption is Evaluated by Regulators, Insurers, and Counsel
Tuesday October 13, 2026 16:05 - 16:45 CEST
How encryption is assessed by regulators, cyber insurers, and legal counsel after a data security incident, and how those assessments shape legal exposure.
Speakers
AM

Amanda McAllister Novak

Senior Counsel, Constangy, Brooks, Smith & Prophete, LLP
Amanda is a cybersecurity and privacy attorney focused on incident response and regulatory compliance. She advises organizations on complex data security incidents, including ransomware attacks and business email compromises, as well as compliance with a wide range of data protection... Read More →
Tuesday October 13, 2026 16:05 - 16:45 CEST
Room 3
  Security, Talk

16:05 CEST

Architecting the Agility Layer: Forging a Common Crypto API for the Post-Quantum Era
Tuesday October 13, 2026 16:05 - 16:55 CEST
PQC transition exposes a lack of structural crypto agility. A panel on forging a common crypto API across the ecosystem.
Speakers
avatar for David Hook

David Hook

VP Software Engineering, Bouncy Castle
David has been working on Cryptography APIs and secure protocols since the mid-1990s and in IT and open-source since the mid-1980s. He is a founder and still active committer of the Legion of the Bouncy Castle Cryptography project which began in the year 2000 and provides APIs in... Read More →
avatar for Mike Kushner

Mike Kushner

Senior Product Architect, Keyfactor
Mike Kushner is a Senior Product Architect at Keyfactor and a longtime contributor to EJBCA, one of the world's leading open-source PKI platforms. A self-described "certificate nurturer," Mike brings deep expertise in public key infrastructure (PKI), digital certificates, and cryptographic lifecycle... Read More →
DV

Dr. Vladimir Soukharev

VP, Cryptographic Technology, Keyfactor
Vladimir Soukharev, Ph.D., is a cryptographer specializing in post-quantum security and the broader cryptographic landscape. He earned his doctorate at the University of Waterloo’s David R. Cheriton School of Computer Science, focusing on elliptic curve cryptography under Professor... Read More →
MS

Murugiah Souppaya

Distinguished Technologist, HP Security Lab
Murugiah Souppaya is a Distinguished Technologist at HP Security Lab, where he leads strategic advanced development projects to help customers adopt state of the art endpoint security capabilities to further enterprise zero trust and security outcomes. He collaborates with HP’s... Read More →
Tuesday October 13, 2026 16:05 - 16:55 CEST
Room 4
  Security, Panel

17:00 CEST

Instrumenting OpenSSL with Crypto-Auditing Probes for Post-Quantum Readiness
Tuesday October 13, 2026 17:00 - 17:30 CEST
The crypto-auditing project: dynamically auditing cryptographic operations in production for PQC readiness where static analysis fails.
Speakers
avatar for Daiki Ueno

Daiki Ueno

Principal Software Engineer, Red Hat
later
Tuesday October 13, 2026 17:00 - 17:30 CEST
Room 3
  Security, Talk

17:00 CEST

Privacy Is Not the Enemy! What Law Enforcement Misunderstands and What Cryptographers Can Do About It
Tuesday October 13, 2026 17:00 - 17:30 CEST
Doctoral research on threat actors in online gaming targeting children, and why law enforcement wrongly views privacy as the problem.
Speakers
DK

Dr. Katrina Khanta, D.Sc.

Senior Cybersecurity Consultant, The Cyber Doctor
Dr. Katrina Khanta is a Senior Cybersecurity Consultant at The Cyber Doctor and is based in the Washington DC area. She possesses a background in International Relations and Chinese, where she began her career writing grants for global initiatives to combating human trafficking, work... Read More →
Tuesday October 13, 2026 17:00 - 17:30 CEST
Room 1
  Security, Talk

17:30 CEST

The Perfect Storm: Why Tech Is the Next Target for Destructive Regulation
Tuesday October 13, 2026 17:30 - 18:00 CEST
Public anxiety over AI, breaches, disinformation and dysfunctional legislatures create conditions for reactive, poorly designed tech regulation.
Speakers
DY

Daniella Y Taveau

Chair of the Board, OASIS-Open
Daniella Taveau is the Founder of Bold Text Strategies and, as of September 2025, Chair of the Board for OASIS-Open. She is an internationally recognized expert in government affairs, global trade, regulation, and complex business strategy, with deep experience across international... Read More →
Tuesday October 13, 2026 17:30 - 18:00 CEST
Room 3
  Security, Talk
 
Wednesday, October 14
 

10:30 CEST

From Copilot to Commit: Handling AI-Generated Code in Open Source Crypto Libraries
Wednesday October 14, 2026 10:30 - 11:00 CEST
The legal mechanics behind AI-assisted contributions to a security-critical project like OpenSSL: copyright, licensing, operational safety.
Speakers
DL

Dr. Lina Böcker

Partner, Osborne Clarke GmbH & Co KG
Dr Lina Böcker is a technology lawyer specialising in Free and Open Source Software (FOSS) compliance, IT law and AI regulation. She advises software vendors, open source projects, OEMs and research institutions on licence compliance, contributor workflows and “safe” use of AI-assisted... Read More →
Wednesday October 14, 2026 10:30 - 11:00 CEST
Room 2
  Security, Talk

11:30 CEST

Bill Buchanan — Session Title Coming Soon
Wednesday October 14, 2026 11:30 - 12:00 CEST
Session details are being finalized with the speaker and will be published here as soon as they are available.
Speakers
avatar for Bill Buchanan

Bill Buchanan

Professor of Applied Cryptography, Edinburgh Napier University
William (Bill) J Buchanan OBE FRSE is a Professor of Applied Cryptography in the School of Computing, Edinburgh and the Built Environment at Edinburgh Napier University. He is a Fellow of the BCS and a Principal Fellow of the HEA. Bill was appointed an Officer of the Order of the... Read More →
Wednesday October 14, 2026 11:30 - 12:00 CEST
Room 1
  Security, Talk

11:30 CEST

Engineering Reality of CRA Compliance for Linux-based IoT Solutions
Wednesday October 14, 2026 11:30 - 12:00 CEST
Making a stock OpenWrt One router secure-by-design vs paper-compliant with the CRA: a gap assessment against Annex I.
Speakers
MK

Maxim Kostin

Solutions and Business Development, Tropic Square s.r.o.
I’m a technical business and solutions developer with more than 20 years of experience in embedded security, with expertise across PayTV and IoT solutions for both startups and corporates. I work at the intersection of secure boot, firmware signing, trusted updates, cryptography... Read More →
PP

Pavel Polach

Head of Product, Tropic Square s.r.o.
Pavel Polach is a product and engineering leader focused on secure technologies, embedded systems, and developer platforms. At Tropic Square, he led SDK and application development for secure hardware, balancing developer usability with technical robustness. In recent months, he transitioned... Read More →
Wednesday October 14, 2026 11:30 - 12:00 CEST
Room 4
  Security, Talk

11:30 CEST

Is the current cryptography testing and validation pipeline process capable of handling the impending Tsunami?
Wednesday October 14, 2026 11:30 - 12:00 CEST
The cryptographic community has been abuzz for a decade about everyone needing to be ready for Post Quantum Cryptography. In April 2016, NIST published NISTIR 8105, "Report on Post-Quantum Cryptography", a technical report assessing the threat that quantum computers pose to existing public-key cryptographic systems. The real question we should be asking ourselves by now: "Is the current cryptography testing and validation pipeline capable of handling the impending Tsunami?" Under the leadership at NIST/NCCoE, we have begun the challenging journey of transforming this problematic workflow from labor intensive to the speed of computing. As with any such endeavor, we began breaking the problem down into organized and achievable workflows starting with the validation of the Entropy Source, the Algorithms, and the Module itself. With any such endeavor under intense pressure and through a collaboration between highly focused practitioners, much has been accomplished, but we still have much more work to be done. The defining of protocols for the exchange of evidence between an accredited laboratory and a certifying body to prove conformance has indeed been revolutionary. However, without extensive analysis and improvement on the workflow for ALL stakeholders, we will hit a brick wall and come to an untimely collapse. The answer to our problem is not simply to claim "AI" (Artificial Intelligence) will solve everything. This talk will take the listener through the troubled past of slow, human-centric cryptographic validations and how we can enter the twenty-first century of fast, computer-centric accelerated, and repeatable validations through "IA" — "Intelligent Automation".
Speakers
SG

Shawn Geddis

Co-founder and CTO/CPO, Katalyst LLC
During his 25 years at Apple, Shawn drove the engineering work for Apple Platform Security Certifications and built Apple Inc.'s SECLAB (NVLAP accredited, first-party Crypto Testing and Validation Lab) while also delivering on the roles of lab manager, tooling architect/developer... Read More →
JG

Jasmine Geddis

Co-founder and CEO, Katalyst LLC
Jasmine is a natural born leader. Her passion for connecting with people is unrivaled and she is known as the "Great Connector". She has a gift for making fast and lifelong friends, on elevators, planes, and of course at conferences. Jasmine launched two healthcare startups in the... Read More →
Wednesday October 14, 2026 11:30 - 12:00 CEST
Room 3
  Security, Talk

13:20 CEST

Artificial Insecurity: how AI threatens digital security and what we can do about it
Wednesday October 14, 2026 13:20 - 14:00 CEST
How the proliferation of LLMs impacts privacy and encryption, with a focus on at-risk communities.
Speakers
MK

Marcel Kolaja

Policy and Advocacy Director — Europe, Access Now
Marcel Kolaja is the Policy and Advocacy Director for Europe at Access Now, an organization defending and extending the digital rights of people and communities at risk. He leads a team of digital rights policy experts and drives the advocacy agenda at the intersection of human rights... Read More →
Wednesday October 14, 2026 13:20 - 14:00 CEST
Room 1
  Security, Talk

13:50 CEST

CRA and its Problematic Impacts on F/OSS
Wednesday October 14, 2026 13:50 - 14:20 CEST
The EU Cyber Resilience Act: scope, obligations on manufacturers and supply-chain actors, and its problematic impacts on F/OSS.
Speakers
PL

Pavel Loutocký

Assistant professor, Masaryk University
JUDr. Pavel Loutocký, Ph.D., BA (Hons) is an assistant professor at the Institute of Law and Technology, Faculty of Law, Masaryk University. He focuses in his research, teaching, and publishing activities on the regulatory aspects of electronic identification and trust services... Read More →
Wednesday October 14, 2026 13:50 - 14:20 CEST
Room 2
  Security, Talk

15:30 CEST

Building Cryptography on Locally Verified Entropy
Wednesday October 14, 2026 15:30 - 16:10 CEST
Cryptography as the transformation of entropy into security, and the case for locally verified entropy generation and delivery.
Speakers
JP

Jordi Prieto Gallego

Security Architect, Quside
Jordi Prieto Gallego works as Security Architect at Quside, leading compliance and certification programs covering entropy sources and cryptographic modules. His work focuses on certification strategy, cryptographic architecture and compliance with international security requirem... Read More →
Wednesday October 14, 2026 15:30 - 16:10 CEST
Room 4
  Security, Talk

16:10 CEST

Investigating cryptography deployments in security-certified products with sec-certs
Wednesday October 14, 2026 16:10 - 16:50 CEST
What can be learned about crypto library usage in CC/FIPS-certified products from public documents, using the sec-certs tool.
Speakers
YY

Yasir Yakup Demircan

PhD student, Masaryk University
Yasir is a PhD candidate at Masaryk University exploring the intersection of automated data science and security standardization. He leverages machine learning to scrutinize the efficacy of frameworks like Common Criteria (CC) and FIPS 140, proactively uncovering systemic security... Read More →
VM

Vashek Matyas

Professor, Masaryk University
Vashek (Václav) Matyáš is a Professor at Masaryk University, Brno, heading its Centre for Research on Cryptography and Security. His research interests relate to applied cryptography and security; with over 200 peer-reviewed papers and articles. He worked also with Cybernetica... Read More →
Wednesday October 14, 2026 16:10 - 16:50 CEST
Room 3
  Security, Talk

16:50 CEST

The PQC Migration Copilot: Agentic AI for Crypto Discovery and Automated OpenSSL 3.5 Cutover
Wednesday October 14, 2026 16:50 - 17:30 CEST
An agentic-AI copilot for cryptographic discovery and automated cutover to OpenSSL 3.5's PQC providers.
Speakers
RK

Ranjan Kathuria

Staff Cloud Security Engineer, Rubrik Inc
My name is Ranjan Kathuria, and I am currently a Staff Cloud Security Engineer / Cloud Security Architect at Rubrik, a recognized leader in Data Backup and Data Security. Based in San Francisco, I lead Rubrik’s Cloud & Infrastructure Security Program, drawing on nearly a decade... Read More →
Wednesday October 14, 2026 16:50 - 17:30 CEST
Room 4
  Security, Talk
 
Thursday, October 15
 

10:30 CEST

IT Security Product Certification in the Era of Automated Evidence Generation and AI-Assisted Evaluation
Thursday October 15, 2026 10:30 - 11:10 CEST
Challenging the classic certify-and-freeze certification model with automated evidence generation and AI-assisted evaluation.
Speakers
JL

Jussipekka Leiwo

Product Cyber Security Strategy Consultant, DNV Cyber
Jussipekka is a cybersecurity certification strategist and practitioner with over 25 years of experience. His experience ranges from security assurance strategy and practice via capability development to the evaluation and certification of high‑assurance IT security products. Jussi... Read More →
Thursday October 15, 2026 10:30 - 11:10 CEST
Room 3
  Security, Talk

11:15 CEST

Tereza Formanová — Session Title Coming Soon
Thursday October 15, 2026 11:15 - 11:55 CEST
Session details are being finalized with the speaker and will be published here as soon as they are available.
Speakers
avatar for Tereza Formanová

Tereza Formanová

Attorney at Law, Sedlakova Legal
Tereza is an attorney at law in the Czech Republic. She helps start-ups and SME´s to identify and protect their intellectual property. She provides consulting services in the field of open-source licensing and makes sure the FOSS components are not omitted in contracts. She also... Read More →
Thursday October 15, 2026 11:15 - 11:55 CEST
Room 3
  Security, Talk

11:15 CEST

The Case for Binding and Embedding – Many Modules One Validation
Thursday October 15, 2026 11:15 - 11:55 CEST
Applying FIPS 140-3 IG on Bound and Embedded Modules to justify boundaries and demonstrate compliance for multiple modules in one enclosure.
Speakers
TW

Tricia Wolff

Security Reserch Engineer Technical Leader, Cisco Systems, Inc
Tricia Wolff is a Security Research Engineer Technical Leader at Cisco Systems, Inc., serving as an expert in Federal Information Processing Standards (FIPS). With over a decade of experience in cybersecurity, she shapes cryptographic compliance strategies across Cisco’s global... Read More →
Thursday October 15, 2026 11:15 - 11:55 CEST
Room 1
  Security, Talk

13:20 CEST

Agentic AI in security operations, liability when the agent acts
Thursday October 15, 2026 13:20 - 14:00 CEST
AI agents acting autonomously in security operations, and the liability gap when procurement treats them as conventional software.
Speakers
avatar for Hayden Delaney

Hayden Delaney

Partner, Thomson Geer Lawyers
With both law and IT qualifications, Hayden has a deep understanding of the technology and digital economy sector. Hayden can quickly grasp how both new and established technologies impact a client’s legal and commercial risks, and also how it can transform a business. He is sought... Read More →
Thursday October 15, 2026 13:20 - 14:00 CEST
Room 1
  Security, Talk

14:00 CEST

FIPS 140-3 Meets PQC - The Compliance Gap Nobody Planned For
Thursday October 15, 2026 14:00 - 14:30 CEST
PQC adoption is outpacing FIPS 140 validation; how regulated industries justify hybrid PQC deployments while awaiting validated modules.
Speakers
CB

Chris Brych

Lead Principal Security Engineer , Security Evaluations - OCI Cryptography, Oracle Corporation
Chris is a Lead Principal Security Engineer to support Oracle’s security evaluations within Oracle. Chris has worked exclusively with the FIPS-140 Standard for over 25 years - on the lab side and vendor side testing cryptographic modules to FIPS 140 compliance.  
Chris was the lead security test engineer who worked with OpenSSL management on the very first FIPS 140-2 validation for the OpenSSL FIPS Object Module back in 2004 and participated in the OpenSSL 3.0 design meetings providing input on FIPS 140 compliance requirements.  He is a mem... Read More →
Thursday October 15, 2026 14:00 - 14:30 CEST
Room 3
  Security, Talk

14:30 CEST

From Hidden Cryptography to Enterprise Risk: Securing Ecosystems for Cryptographic Compliance and Post-Quantum Readiness
Thursday October 15, 2026 14:30 - 15:00 CEST
Cryptography as a board-level risk; Keyfactor's Fortune 500 analysis of visibility into where crypto and OpenSSL are used.
Speakers
DV

Dr. Vladimir Soukharev

VP, Cryptographic Technology, Keyfactor
Vladimir Soukharev, Ph.D., is a cryptographer specializing in post-quantum security and the broader cryptographic landscape. He earned his doctorate at the University of Waterloo’s David R. Cheriton School of Computer Science, focusing on elliptic curve cryptography under Professor... Read More →
Thursday October 15, 2026 14:30 - 15:00 CEST
Room 4
  Security, Talk

15:30 CEST

Beyond copyright: IP strategy in the age of generative AI
Thursday October 15, 2026 15:30 - 16:10 CEST
Using the 2026 Claude Code source-map leak and the DMCA takedown blitz as a stress test of copyright in the age of generative AI.
Speakers
avatar for Hayden Delaney

Hayden Delaney

Partner, Thomson Geer Lawyers
With both law and IT qualifications, Hayden has a deep understanding of the technology and digital economy sector. Hayden can quickly grasp how both new and established technologies impact a client’s legal and commercial risks, and also how it can transform a business. He is sought... Read More →
Thursday October 15, 2026 15:30 - 16:10 CEST
Room 1
  Security, Talk

15:30 CEST

Managing millions of sboms with trustify
Thursday October 15, 2026 15:30 - 16:10 CEST
The engineering behind Trustify, the open-source core of Red Hat's Trusted Profile Analyzer, to ingest and correlate SBOMs at scale.
Speakers
JF

James Fuller

Senior Principal Software Engineer, Red Hat
Jim Fuller is a Senior Principal Software Engineer on Red Hat's Product Security (PSIRT) team, where for the past five years he has helped build tooling that triages, analyzes, and remediates vulnerabilities across Red Hat's vast portfolio — including OSIDB (the Open Source Incident... Read More →
Thursday October 15, 2026 15:30 - 16:10 CEST
Room 4
  Security, Talk

16:15 CEST

EU CRA is around the corner. Are you ready?
Thursday October 15, 2026 16:15 - 16:55 CEST
How software publishers selling in the EU/EEA can prepare for CRA vulnerability-reporting requirements and ENISA platform readiness by September 2026.
Speakers
SB

Sridhar Balasubramanian

Principal Product Security Architect, NetApp, Inc.,
Sridhar is currently working as Principal Security Architect within Product Security Group @ NetApp. With over 25 years in software industry, Sridhar is inventor/co-inventor for 16 US Patents and published 11 Conference papers till date.

Sridhar's area of expertise includes Storage and Information Security, Security Assurance, Cryptography, Secure Software Development Lifecycle, Secure Protocols, and Storage Management. Sridhar holds a Master's degrees in Physics and Electrical Engineering
... Read More →
Thursday October 15, 2026 16:15 - 16:55 CEST
Room 2
  Security, Talk

17:00 CEST

Re: [URGENT] Eight Critical 0-Day Vulnerabilities in OpenSSL
Thursday October 15, 2026 17:00 - 17:30 CEST
OpenSSL security report statistics and how the security handling process is being made faster and more efficient.
Speakers
NP

Norbert Pocs

Software Engineer, OpenSSL Corporation
Junior software enthusiast. Was working as crypto package manager and currently part of the software engineer team of openssl.
Thursday October 15, 2026 17:00 - 17:30 CEST
Room 2
  Security, Talk
 
OpenSSL Conference 2026
From €250.00
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.