Loading…
The OpenSSL Conference is the global meeting place for the people who build, deploy, govern, and rely on secure digital infrastructure. It brings together developers, security engineers, researchers, policymakers, enterprises, legal and compliance professionals, and community contributors, all united by a shared commitment to stronger open-source security.
Venue: Room 2 clear filter
Tuesday, October 13
 

15:20 CEST

Why have the PQC standards taken so long? Bottlenecks, bickering, and building momentum
Tuesday October 13, 2026 15:20 - 16:00 CEST
NIST published ML-KEM/ML-DSA/SLH-DSA in Aug 2024, yet stable specs for TLS, email, code signing remain elusive. This panel explores why and what the community can do.
Speakers
MO

Mike Ounsworth

Lead open source maintainer, Cryptic Forest Software
Mike Ounsworth is a software security architect and cryptographic protocol designer. He is deeply involved in the Post-Quantum transition, particularly in re-designing IETF networking protocols to accommodate the new PQC algorithms, dual-algorithm hybrids, and mechanisms to ease migration... Read More →
Tuesday October 13, 2026 15:20 - 16:00 CEST
Room 2
  Community, Talk

16:05 CEST

Merkle Tree Certificate Proofs - How Merkle Trees and Merkle Subtrees are used in MTC's
Tuesday October 13, 2026 16:05 - 16:55 CEST
An overview of Merkle Trees, Merkle subtrees, and Merkle tree proofs from Merkle Tree Certificates.
Speakers
BB

Bob Beck

Software Engineer, OpenSSL Corporation
Bob was born in the USA, with his parents escaping to Canada in a balloon during the Nixon Regime. He gained much unix experience at an early age and a fasicnation with fiddling with network stacks led tohis finding of a used SparcStation in the early 90's, When NetBSD did not run... Read More →
AD

Andrew Dinh

Software Engineer, OpenSSL Corporation
Andrew is a smart guy who is Bob's co-conspirator for these talks. this bio needs to be fixed by Andrew.
Tuesday October 13, 2026 16:05 - 16:55 CEST
Room 2
  Technical, Talk

17:00 CEST

Who Pays for Open Source? A First-Party Answer from the OpenSSL Corporation
Tuesday October 13, 2026 17:00 - 17:30 CEST
OpenSSL's contributor record shows the library is written overwhelmingly by paid engineers — a corrective to the volunteer-burnout narrative.
Speakers
KS

Kajal Sapkota

Business Development Manager, OpenSSL Corporation
Kajal Sapkota is Business Development Manager and Commercial Lead at OpenSSL Corporation, where she manages its funding: support contracts and partnerships across roughly one hundred organizations. She also leads sponsor relations for the OpenSSL Conference and has worked across marketing... Read More →
Tuesday October 13, 2026 17:00 - 17:30 CEST
Room 2
  Community, Talk

17:30 CEST

Lessons learned on proper cryptographic hygiene in Rust
Tuesday October 13, 2026 17:30 - 18:00 CEST
Rust language features for crypto: type safety, no_std, and why the optimizer breaks constant-time even for careful code.
Speakers
MO

Mike Ounsworth

Lead open source maintainer, Cryptic Forest Software
Mike Ounsworth is a software security architect and cryptographic protocol designer. He is deeply involved in the Post-Quantum transition, particularly in re-designing IETF networking protocols to accommodate the new PQC algorithms, dual-algorithm hybrids, and mechanisms to ease migration... Read More →
Tuesday October 13, 2026 17:30 - 18:00 CEST
Room 2
  Technical, Talk
 
Wednesday, October 14
 

09:30 CEST

A library-agnostic hybrid classic/PQ OpenSSL provider — built with AI
Wednesday October 14, 2026 09:30 - 10:00 CEST
In last year's presentation on oqs-provider, we concluded with proposed next work, namely an OpenSSL provider for hybrid classic/PQ logic independent of a specific PQ library. This talk presents how this new provider was created with the help of an AI, its functional capabilities and the lessons learned: the former dwarf the ones of the original oqs-provider, and the latter may be helpful for others using the same tooling in the context of a somewhat security-related software component.
Speakers
MB

Michael Baentsch

Independent
Michael Baentsch is the original author and long-time maintainer of oqs-provider, the OpenSSL provider that brought experimental post-quantum cryptography to OpenSSL via liboqs. He presented oqs-provider at the OpenSSL Conference 2025 in Prague; this talk covers the follow-up he proposed... Read More →
Wednesday October 14, 2026 09:30 - 10:00 CEST
Room 2
  Technical, Talk

10:30 CEST

From Copilot to Commit: Handling AI-Generated Code in Open Source Crypto Libraries
Wednesday October 14, 2026 10:30 - 11:00 CEST
The legal mechanics behind AI-assisted contributions to a security-critical project like OpenSSL: copyright, licensing, operational safety.
Speakers
DL

Dr. Lina Böcker

Partner, Osborne Clarke GmbH & Co KG
Dr Lina Böcker is a technology lawyer specialising in Free and Open Source Software (FOSS) compliance, IT law and AI regulation. She advises software vendors, open source projects, OEMs and research institutions on licence compliance, contributor workflows and “safe” use of AI-assisted... Read More →
Wednesday October 14, 2026 10:30 - 11:00 CEST
Room 2
  Security, Talk

11:00 CEST

Self-Encrypting Disks in Linux - Fast, Expensive, and Mostly Harmless
Wednesday October 14, 2026 11:00 - 11:30 CEST
Adding Opal2 self-encrypting drive support to cryptsetup: what we achieved, what we found, and why industry standards miss each other.
Speakers
MB

Milan Brož

Research & Development Manager, OpenSSL Corporation
A grumpy developer and researcher in the area of storage security. Linux cryptsetup and LUKS maintainer. For more info see https://mbroz.fedorapeople.org/talks/
Wednesday October 14, 2026 11:00 - 11:30 CEST
Room 2
  Community, Talk

11:30 CEST

HSM-Backed OpenPGP Signing for OpenSSL Releases: Architecture and Operations
Wednesday October 14, 2026 11:30 - 12:00 CEST
For most of OpenSSL's history a release was signed with the release manager's own OpenPGP key — the 1.1.1 and 3.0.0 tags carry signatures from different individuals. Automating the release process consolidated that onto one shared release key, but it was still a private key in a file on disk. Either way, the trust root for software that a large chunk of the internet depends on to build TLS was a file that could be copied. This talk covers moving that trust root onto hardware — an Entrust nShield HSM in FIPS 140-3 mode — without breaking release automation and without changing anything for verifiers. We cover: the two-tier key model (a Certify-only primary key under a card quorum, plus a signing subkey the pipeline uses unattended); sq-pkcs11, the open-source Rust CLI on Sequoia-OpenPGP we built to bridge OpenPGP and PKCS#11; the redesigned pipeline with an isolated signing stage; nshield-card-check, a small web app for custodians to verify their card and passphrase on demand with an audit trail; and generalizing the same HSM to sign RPM/DEB repos and Java code. Attendees leave with a concrete reference architecture that runs against SoftHSM2 as well as real hardware.
Speakers
DM

Dmitry Misharov

DevOps Engineer, OpenSSL Corporation
Dmitry Misharov is a Senior DevOps Engineer at OpenSSL Corporation, working on the infrastructure behind OpenSSL: release automation, the HSM-backed signing pipeline, and performance testing infrastructure. Dmitry designed and built the release-signing migration this talk covers... Read More →
Wednesday October 14, 2026 11:30 - 12:00 CEST
Room 2
  Technical, Talk

13:20 CEST

The State of the OpenSSL Community
Wednesday October 14, 2026 13:20 - 13:50 CEST
Session details are being finalized with the speakers and will be published here as soon as they are available.
Speakers
avatar for Jon Ericson

Jon Ericson

Communities Manager, OpenSSL Foundation
Jon Ericson is the OpenSSL Foundation Communities Manager. He started his career as a C programmer for the US National Weather Service and NASA's Jet Propulsion Laboratory. When Stack Overflow launched in beta, Jon was an early contributor and later joined as a full-time community... Read More →
CW

Chris Ward

Community Manager, OpenSSL Corporation
The speaker's biography is being finalized and will be published here shortly.
Wednesday October 14, 2026 13:20 - 13:50 CEST
Room 2
  Community, Talk

13:50 CEST

CRA and its Problematic Impacts on F/OSS
Wednesday October 14, 2026 13:50 - 14:20 CEST
The EU Cyber Resilience Act: scope, obligations on manufacturers and supply-chain actors, and its problematic impacts on F/OSS.
Speakers
PL

Pavel Loutocký

Assistant professor, Masaryk University
JUDr. Pavel Loutocký, Ph.D., BA (Hons) is an assistant professor at the Institute of Law and Technology, Faculty of Law, Masaryk University. He focuses in his research, teaching, and publishing activities on the regulatory aspects of electronic identification and trust services... Read More →
Wednesday October 14, 2026 13:50 - 14:20 CEST
Room 2
  Security, Talk

14:20 CEST

Open Source: The Road to EU Sovereignty
Wednesday October 14, 2026 14:20 - 14:50 CEST
The EU's 2026 Open Source Strategy as a sovereignty turning point, and its loopholes, weak enforcement and thin SME support.
Speakers
AG

Alix Guillard

individual, individual
Worked as webmaster for several organisations including leading Linux distribution. Lead the Paris Linux user group before leaving France. Living and working in Czechia as a developer for 12 years.
Wednesday October 14, 2026 14:20 - 14:50 CEST
Room 2
  Community, Talk

15:30 CEST

Building a Fail-Closed Cryptographic Code LLM Support Assistant
Wednesday October 14, 2026 15:30 - 16:10 CEST
Lessons from a fail-closed RAG support assistant for Bouncy Castle, where LLM probabilism clashes with deterministic crypto.
Speakers
avatar for Francis Mendoza

Francis Mendoza

Cryptographic Software Engineer, Keyfactor, Inc.
Francis Mendoza is a Filipino-American computer scientist working at the intersection of applied cryptography and resilient distributed systems. He holds a B.S. and M.S. in Computer Science from Arizona State University, where his research focused on cybersecurity for critical infrastructure... Read More →
Wednesday October 14, 2026 15:30 - 16:10 CEST
Room 2
  Technical, Talk

16:10 CEST

Testing PQC Timing Side-Channels
Wednesday October 14, 2026 16:10 - 16:50 CEST
Custom test harnesses and tlsfuzzer to measure timing variations in OpenSSL's ML-KEM and ML-DSA implementations for constant-time compliance.
Speakers
AK

Alicja Kario

Principal Quality Engineer, Red Hat
Alicja is a quality engineer specialised in cryptography at Red Hat. She is the quality team lead responsible for handling core cryptographic packages in Red Hat Enterprise Linux: OpenSSL, Mozilla NSS, GnuTLS, OpenSSH, libreswan, and others. With over 15 years of experience in the... Read More →
Wednesday October 14, 2026 16:10 - 16:50 CEST
Room 2
  Technical, Talk

16:50 CEST

Jipher FIPS cryptography provider - How we wrapped OpenSSL and the FIPS module using Java’s FFM API
Wednesday October 14, 2026 16:50 - 17:30 CEST
The open-source Jipher provider exposes OpenSSL-backed crypto through the JCA for FIPS-compliant Java, via a Java-to-native (FFM) architecture.
Speakers
JS

Jon Spillett

Principal Platform Software Engineer, Cryptography, Oracle Corporation
A principal developer and expert in applied cryptography, Jon Spillett has worked in this field for over 15 years. His introduction to cryptography at RSA Security brought experience with BSAFE cryptographic toolkits which he developed, maintained and customised.Over his time at Oracle... Read More →
Wednesday October 14, 2026 16:50 - 17:30 CEST
Room 2
  Technical, Talk

17:30 CEST

What shall we do with two PKCS#11 providers?
Wednesday October 14, 2026 17:30 - 18:00 CEST
openssl-projects' pkcs11-provider vs libp11's new provider: two implementations of the same thing, and the resulting user confusion.
Speakers
avatar for Jakub Jelen

Jakub Jelen

Principal Software Engineer, Red Hat
Everything Smart Cards, PKCS#11 and OpenSSL (mostly from outside).
Wednesday October 14, 2026 17:30 - 18:00 CEST
Room 2
  Community, Talk
 
Thursday, October 15
 

10:30 CEST

Going beyond constant-time security in open-source cryptographic libraries
Thursday October 15, 2026 10:30 - 11:10 CEST
A systematic software-engineering approach to integrating physical-attack (power/EM, fault-injection) defenses beyond baseline constant-time.
Speakers
LC

Lukasz Chmielewski

Assistant Professor, Masaryk University
Łukasz Chmielewski holds the position of Assistant Professor at Masaryk University in Brno, Czech Republic. His primary area of expertise revolves around side-channel analysis (SCA) of public-key cryptosystems. In general, he is also interested in hardware attacks, including fault... Read More →
JJ

Jan Janasek

Master's Student, Masaryk University
Jan Janasek is a Master's student at Masaryk University with a strong interest in hardware security, currently exploring side-channel analysis and fault injection, and participating in academic research to learn more about protecting embedded systems from physical vulnerabilities... Read More →
Thursday October 15, 2026 10:30 - 11:10 CEST
Room 2
  Technical, Talk

11:15 CEST

The Family Reunion: OpenSSL, BoringSSL, AWS-LC, and LibreSSL on Why They Forked and What Happens Now
Thursday October 15, 2026 11:15 - 11:55 CEST
In 2014 after Heartbleed the OpenSSL family split into LibreSSL, BoringSSL, AWS-LC, QuicTLS. A panel on why they forked and what happens now.
Speakers
KS

Kajal Sapkota

Business Development Manager, OpenSSL Corporation
Kajal Sapkota is Business Development Manager and Commercial Lead at OpenSSL Corporation, where she manages its funding: support contracts and partnerships across roughly one hundred organizations. She also leads sponsor relations for the OpenSSL Conference and has worked across marketing... Read More →
Thursday October 15, 2026 11:15 - 11:55 CEST
Room 2
  Community, Panel

13:20 CEST

The Good, the Bad and the Ugly: Tales from the last three years PQC transition at Red Hat
Thursday October 15, 2026 13:20 - 14:00 CEST
RHEL was first to sign packages with post-quantum keys. Trade-offs, what went wrong, TLS/SSH/IPSec state, and what to do first.
Speakers
avatar for Clemens Lang

Clemens Lang

RHEL Crypto Team Product Owner, Red Hat
Product Owner of the Red Hat Enterprise Linux Crypto Team. Resident Post-Quantum Transition Wrangler.
Thursday October 15, 2026 13:20 - 14:00 CEST
Room 2
  Business, Talk

14:00 CEST

Composites Aren’t Optional: Designing PKI for the Post-Quantum Transition and Beyond
Thursday October 15, 2026 14:00 - 14:30 CEST
The PQC transition will last years, requiring PKI to straddle classical and quantum-safe worlds. Composite algorithms as a first-class PKI design pattern.
Speakers
JG

John Gray

Senior Staff Software Developer, Entrust
John Gray is a Senior Staff Software Developer at Entrust, specializing in PKI architecture, cryptographic protocol implementation, and post-quantum migration strategies. He facilitates the PQC Interoperability project at the IETF and has contributed to post-quantum cryptography standards... Read More →
Thursday October 15, 2026 14:00 - 14:30 CEST
Room 2
  Technical, Talk

14:30 CEST

Student Bug Bounties for OpenSSL-Based Products
Thursday October 15, 2026 14:30 - 15:00 CEST
Whether supervised university students can responsibly extend security testing, from integrating bug bounties into a secure-coding course.
Speakers
KM

Kamil Malinka

associate professor, Brno University of Technology
Kamil Malinka is an associate professor at FIT VUT in Brno and head of the Security@FIT research group, which focuses on information technology security. His research focuses primarily on the security aspects of artificial intelligence, such as the risks associated with the misuse... Read More →
Thursday October 15, 2026 14:30 - 15:00 CEST
Room 2
  Community, Talk

15:30 CEST

TLS 1.3, session resumption, 0-RTT early data, external PSKs and all that...
Thursday October 15, 2026 15:30 - 16:10 CEST
TLS 1.3 overloaded the PSK mechanism with resumption, 0-RTT and ECH overlap. A complex feature with non-obvious limits, addressed by RFC9258 (OpenSSL 4.1).
Speakers
VD

Viktor Dukhovni

Staff Engineer, OpenSSL Corporation
OpenSSL staff engineer since May 2024, with focus on PQC and X.509.Unix system programmer since the mid 1980's with a focus on network security.
Long-term contributor to Postfix and maintainer of its TLS features.
Author of:RFC7435 (opportunistic security),RFC7161 (DANE updates)RFC7672 (DANE for SMTP),RFC9276 (DNSSEC NSEC3 BCP).Contributor to Heimdal and MIT Kerberos, OpenSSL, Haskell GHC compiler and libraries... Read More →
Thursday October 15, 2026 15:30 - 16:10 CEST
Room 2
  Technical, Talk

16:15 CEST

EU CRA is around the corner. Are you ready?
Thursday October 15, 2026 16:15 - 16:55 CEST
How software publishers selling in the EU/EEA can prepare for CRA vulnerability-reporting requirements and ENISA platform readiness by September 2026.
Speakers
SB

Sridhar Balasubramanian

Principal Product Security Architect, NetApp, Inc.,
Sridhar is currently working as Principal Security Architect within Product Security Group @ NetApp. With over 25 years in software industry, Sridhar is inventor/co-inventor for 16 US Patents and published 11 Conference papers till date.

Sridhar's area of expertise includes Storage and Information Security, Security Assurance, Cryptography, Secure Software Development Lifecycle, Secure Protocols, and Storage Management. Sridhar holds a Master's degrees in Physics and Electrical Engineering
... Read More →
Thursday October 15, 2026 16:15 - 16:55 CEST
Room 2
  Security, Talk

17:00 CEST

Re: [URGENT] Eight Critical 0-Day Vulnerabilities in OpenSSL
Thursday October 15, 2026 17:00 - 17:30 CEST
OpenSSL security report statistics and how the security handling process is being made faster and more efficient.
Speakers
NP

Norbert Pocs

Software Engineer, OpenSSL Corporation
Junior software enthusiast. Was working as crypto package manager and currently part of the software engineer team of openssl.
Thursday October 15, 2026 17:00 - 17:30 CEST
Room 2
  Security, Talk
 
OpenSSL Conference 2026
From €250.00
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.