Loading…
The OpenSSL Conference is the global meeting place for the people who build, deploy, govern, and rely on secure digital infrastructure. It brings together developers, security engineers, researchers, policymakers, enterprises, legal and compliance professionals, and community contributors, all united by a shared commitment to stronger open-source security.
Venue: Room 3 clear filter
Tuesday, October 13
 

15:20 CEST

The EU CRA vs. Community: Why You’re Safe, and How Stewards Help
Tuesday October 13, 2026 15:20 - 16:00 CEST
The CRA is the first horizontal law to recognise open source in the commercial supply chain. An opportunity to standardise and elevate security; how stewards help.
Speakers
avatar for Jaroslav Řezník

Jaroslav Řezník

Program Manager, Red Hat Czech, s.r.o.
Jaroslav is the Principal Program Manager guiding standards and regulatory initiatives for Red Hat's Product Security Compliance team. His 18-year tenure is defined by his unique versatility: he is as dedicated to his beloved Fedora open-source community as he is to ensuring Red Hat... Read More →
Tuesday October 13, 2026 15:20 - 16:00 CEST
Room 3
  Security, Talk

16:05 CEST

During a Breach: How Encryption is Evaluated by Regulators, Insurers, and Counsel
Tuesday October 13, 2026 16:05 - 16:45 CEST
How encryption is assessed by regulators, cyber insurers, and legal counsel after a data security incident, and how those assessments shape legal exposure.
Speakers
AM

Amanda McAllister Novak

Senior Counsel, Constangy, Brooks, Smith & Prophete, LLP
Amanda is a cybersecurity and privacy attorney focused on incident response and regulatory compliance. She advises organizations on complex data security incidents, including ransomware attacks and business email compromises, as well as compliance with a wide range of data protection... Read More →
Tuesday October 13, 2026 16:05 - 16:45 CEST
Room 3
  Security, Talk

17:00 CEST

Instrumenting OpenSSL with Crypto-Auditing Probes for Post-Quantum Readiness
Tuesday October 13, 2026 17:00 - 17:30 CEST
The crypto-auditing project: dynamically auditing cryptographic operations in production for PQC readiness where static analysis fails.
Speakers
avatar for Daiki Ueno

Daiki Ueno

Principal Software Engineer, Red Hat
later
Tuesday October 13, 2026 17:00 - 17:30 CEST
Room 3
  Security, Talk

17:30 CEST

The Perfect Storm: Why Tech Is the Next Target for Destructive Regulation
Tuesday October 13, 2026 17:30 - 18:00 CEST
Public anxiety over AI, breaches, disinformation and dysfunctional legislatures create conditions for reactive, poorly designed tech regulation.
Speakers
DY

Daniella Y Taveau

Chair of the Board, OASIS-Open
Daniella Taveau is the Founder of Bold Text Strategies and, as of September 2025, Chair of the Board for OASIS-Open. She is an internationally recognized expert in government affairs, global trade, regulation, and complex business strategy, with deep experience across international... Read More →
Tuesday October 13, 2026 17:30 - 18:00 CEST
Room 3
  Security, Talk
 
Wednesday, October 14
 

09:30 CEST

Shipping OpenSSL downstream and its challenge
Wednesday October 14, 2026 09:30 - 10:00 CEST
Distribution maintainers as system integrators: maintaining multiple OpenSSL versions across OS releases while keeping them secure and compatible.
Speakers
PM

Pedro Monreal

Software Engineer - Cryptography, SUSE Software Solutions
Software Engineer at SUSEkey member of the Cryptography Group. As a dedicated maintainer of OpenSSL and other cryptographic libraries. His work also involves participating in FIPS certification rounds for SUSE, where he focuses on the implementation of FIPS requirements... Read More →
LM

Lucas Mülling

Linux Distribution Engineer Cryptography, SUSE Software Solutions
Computer scientist with experience in PKI, protocols, and cryptography. Maintainer for SUSE.
AY

Angel Yankov

Linux Distribution Engineer Cryptography, SUSE Software Solutions
Embedded engineer, transitioned to maintaining cryptographic libraries at SUSE.
Wednesday October 14, 2026 09:30 - 10:00 CEST
Room 3
  Community, Talk

10:30 CEST

How small can you (reasonably) get an ML-DSA and ML-KEM implementation?
Wednesday October 14, 2026 10:30 - 11:00 CEST
Speed-vs-memory tradeoffs in ML-DSA and ML-KEM: key representations and deferring expansion until values are needed.
Speakers
MO

Mike Ounsworth

Lead open source maintainer, Cryptic Forest Software
Mike Ounsworth is a software security architect and cryptographic protocol designer. He is deeply involved in the Post-Quantum transition, particularly in re-designing IETF networking protocols to accommodate the new PQC algorithms, dual-algorithm hybrids, and mechanisms to ease migration... Read More →
Wednesday October 14, 2026 10:30 - 11:00 CEST
Room 3
  Technical, Talk

11:00 CEST

Navigating the Post-Quantum Transition: Integrating FAEST and Classic McEliece into libOQS
Wednesday October 14, 2026 11:00 - 11:30 CEST
Practical challenges and implementation details of integrating FAEST and an updated Classic McEliece into libOQS.
Speakers
NA

Norman Ashley

Software Engineer, Cisco Systems
Software Engineer working crypro libraries at Cisco. Contributor to OQS
Wednesday October 14, 2026 11:00 - 11:30 CEST
Room 3
  Community, Talk

11:30 CEST

Is the current cryptography testing and validation pipeline process capable of handling the impending Tsunami?
Wednesday October 14, 2026 11:30 - 12:00 CEST
The cryptographic community has been abuzz for a decade about everyone needing to be ready for Post Quantum Cryptography. In April 2016, NIST published NISTIR 8105, "Report on Post-Quantum Cryptography", a technical report assessing the threat that quantum computers pose to existing public-key cryptographic systems. The real question we should be asking ourselves by now: "Is the current cryptography testing and validation pipeline capable of handling the impending Tsunami?" Under the leadership at NIST/NCCoE, we have begun the challenging journey of transforming this problematic workflow from labor intensive to the speed of computing. As with any such endeavor, we began breaking the problem down into organized and achievable workflows starting with the validation of the Entropy Source, the Algorithms, and the Module itself. With any such endeavor under intense pressure and through a collaboration between highly focused practitioners, much has been accomplished, but we still have much more work to be done. The defining of protocols for the exchange of evidence between an accredited laboratory and a certifying body to prove conformance has indeed been revolutionary. However, without extensive analysis and improvement on the workflow for ALL stakeholders, we will hit a brick wall and come to an untimely collapse. The answer to our problem is not simply to claim "AI" (Artificial Intelligence) will solve everything. This talk will take the listener through the troubled past of slow, human-centric cryptographic validations and how we can enter the twenty-first century of fast, computer-centric accelerated, and repeatable validations through "IA" — "Intelligent Automation".
Speakers
SG

Shawn Geddis

Co-founder and CTO/CPO, Katalyst LLC
During his 25 years at Apple, Shawn drove the engineering work for Apple Platform Security Certifications and built Apple Inc.'s SECLAB (NVLAP accredited, first-party Crypto Testing and Validation Lab) while also delivering on the roles of lab manager, tooling architect/developer... Read More →
JG

Jasmine Geddis

Co-founder and CEO, Katalyst LLC
Jasmine is a natural born leader. Her passion for connecting with people is unrivaled and she is known as the "Great Connector". She has a gift for making fast and lifelong friends, on elevators, planes, and of course at conferences. Jasmine launched two healthcare startups in the... Read More →
Wednesday October 14, 2026 11:30 - 12:00 CEST
Room 3
  Security, Talk

13:20 CEST

Advancing Clarity Through Collaboration
Wednesday October 14, 2026 13:20 - 14:00 CEST
The CMUF Request for Guidance Working Group: how government, labs and industry create community-driven guidance for cryptographic modules.
Speakers
TW

Tricia Wolff

Security Reserch Engineer Technical Leader, Cisco Systems, Inc
Tricia Wolff is a Security Research Engineer Technical Leader at Cisco Systems, Inc., serving as an expert in Federal Information Processing Standards (FIPS). With over a decade of experience in cybersecurity, she shapes cryptographic compliance strategies across Cisco’s global... Read More →
Wednesday October 14, 2026 13:20 - 14:00 CEST
Room 3
  Community, Talk

14:00 CEST

Community panel: Distributions
Wednesday October 14, 2026 14:00 - 14:50 CEST
A distributions panel on upstream time-to-merge bottlenecks and how upstream, distros and enterprises can share the certification burden.
Speakers
LM

Lucas Mülling

Linux Distribution Engineer Cryptography, SUSE Software Solutions
Computer scientist with experience in PKI, protocols, and cryptography. Maintainer for SUSE.
Wednesday October 14, 2026 14:00 - 14:50 CEST
Room 3
  Community, Panel

15:30 CEST

DTLSv1.3 in OpenSSL
Wednesday October 14, 2026 15:30 - 16:10 CEST
DTLS 1.3 brings a variable-length unified header, encrypted sequence numbers, and an explicit ACK mechanism. This talk covers its implementation in OpenSSL.
Speakers
RH

Ryan Hooper

Technical Leader/Associate OpenSSL Foundation Engineer, Cisco Systems/OpenSSL Foundation
Associate OpenSSL Foundation Engineer on part-time secondment from his role as Software Developer at Cisco Systems. With years of hands-on experience on many different platforms across both TLS and IPsec stacks, Ryan brings deep expertise in secure communications. At OpenSSL Foundation... Read More →
Wednesday October 14, 2026 15:30 - 16:10 CEST
Room 3
  Technical, Talk

16:10 CEST

Investigating cryptography deployments in security-certified products with sec-certs
Wednesday October 14, 2026 16:10 - 16:50 CEST
What can be learned about crypto library usage in CC/FIPS-certified products from public documents, using the sec-certs tool.
Speakers
YY

Yasir Yakup Demircan

PhD student, Masaryk University
Yasir is a PhD candidate at Masaryk University exploring the intersection of automated data science and security standardization. He leverages machine learning to scrutinize the efficacy of frameworks like Common Criteria (CC) and FIPS 140, proactively uncovering systemic security... Read More →
VM

Vashek Matyas

Professor, Masaryk University
Vashek (Václav) Matyáš is a Professor at Masaryk University, Brno, heading its Centre for Research on Cryptography and Security. His research interests relate to applied cryptography and security; with over 200 peer-reviewed papers and articles. He worked also with Cybernetica... Read More →
Wednesday October 14, 2026 16:10 - 16:50 CEST
Room 3
  Security, Talk

16:50 CEST

Beyond Algorithms: Exploiting Platform Cryptography with OpenSSL Providers
Wednesday October 14, 2026 16:50 - 17:30 CEST
Using OpenSSL Providers to exploit platform crypto hardware (mainframes, HSMs, embedded) where key material never surfaces in memory.
Speakers
FC

Finn Callies

Software Developer, IBM Deutschland Research&Development GmbH
Opensource Developer @ IBM, Confidential Computing and Secure Execution for Linux (SEL)
HD

Holger Dengler

Software Developer, IBM Deutschland Research&Development GmbH
Opensource Developer @ IBM, Nominated community member for OpenSSL platform linux64-s390x, Linux Kernel co-Maintainer for crypto-related stuff for s390 architecture
Wednesday October 14, 2026 16:50 - 17:30 CEST
Room 3
  Technical, Talk

17:30 CEST

New Insights into the Formal Verification of AWS-LC, a Fork of OpenSSL
Wednesday October 14, 2026 17:30 - 18:00 CEST
Formal verification of cryptographic implementations, particularly PQC in AWS-LC (a fork of OpenSSL): memory safety, type safety, functional correctness.
Speakers
NM

Nicky Mouha

Cryptography and Security Expert, KeyCryptic
Nicky Mouha is the Founder of KeyCryptic, a company that provides cryptography and security consulting services. He has a Ph.D. and two decades of experience in cryptanalysis, cryptographic design, and both hardware and software implementations. During his time at NIST (2016-2025), he collaborated on a wide range of nat... Read More →
Wednesday October 14, 2026 17:30 - 18:00 CEST
Room 3
  Technical, Talk
 
Thursday, October 15
 

10:30 CEST

IT Security Product Certification in the Era of Automated Evidence Generation and AI-Assisted Evaluation
Thursday October 15, 2026 10:30 - 11:10 CEST
Challenging the classic certify-and-freeze certification model with automated evidence generation and AI-assisted evaluation.
Speakers
JL

Jussipekka Leiwo

Product Cyber Security Strategy Consultant, DNV Cyber
Jussipekka is a cybersecurity certification strategist and practitioner with over 25 years of experience. His experience ranges from security assurance strategy and practice via capability development to the evaluation and certification of high‑assurance IT security products. Jussi... Read More →
Thursday October 15, 2026 10:30 - 11:10 CEST
Room 3
  Security, Talk

11:15 CEST

Tereza Formanová — Session Title Coming Soon
Thursday October 15, 2026 11:15 - 11:55 CEST
Session details are being finalized with the speaker and will be published here as soon as they are available.
Speakers
avatar for Tereza Formanová

Tereza Formanová

Attorney at Law, Sedlakova Legal
Tereza is an attorney at law in the Czech Republic. She helps start-ups and SME´s to identify and protect their intellectual property. She provides consulting services in the field of open-source licensing and makes sure the FOSS components are not omitted in contracts. She also... Read More →
Thursday October 15, 2026 11:15 - 11:55 CEST
Room 3
  Security, Talk

13:20 CEST

Practical Viability of NIST Post-Quantum Algorithms on Constrained ARM Devices: A Timing and Energy Study
Thursday October 15, 2026 13:20 - 14:00 CEST
Empirical timing/energy benchmarks of ML-KEM, ML-DSA and SLH-DSA on constrained 32-bit ARM IoT devices.
Speakers
OG

Olivier Gillot

MSc Cybersecurity Student, Edinburgh Napier University
I am completing an MSc in Cybersecurity at Edinburgh Napier University, supervised by Prof. Bill Buchanan OBE. My dissertation benchmarks NIST-standardised post-quantum cryptography on constrained IoT hardware, using OpenSSL and wolfSSL across Linux-based single-board computers and... Read More →
Thursday October 15, 2026 13:20 - 14:00 CEST
Room 3
  Technical, Talk

14:00 CEST

FIPS 140-3 Meets PQC - The Compliance Gap Nobody Planned For
Thursday October 15, 2026 14:00 - 14:30 CEST
PQC adoption is outpacing FIPS 140 validation; how regulated industries justify hybrid PQC deployments while awaiting validated modules.
Speakers
CB

Chris Brych

Lead Principal Security Engineer , Security Evaluations - OCI Cryptography, Oracle Corporation
Chris is a Lead Principal Security Engineer to support Oracle’s security evaluations within Oracle. Chris has worked exclusively with the FIPS-140 Standard for over 25 years - on the lab side and vendor side testing cryptographic modules to FIPS 140 compliance.  
Chris was the lead security test engineer who worked with OpenSSL management on the very first FIPS 140-2 validation for the OpenSSL FIPS Object Module back in 2004 and participated in the OpenSSL 3.0 design meetings providing input on FIPS 140 compliance requirements.  He is a mem... Read More →
Thursday October 15, 2026 14:00 - 14:30 CEST
Room 3
  Security, Talk

14:30 CEST

Decoupling the OpenSSL FIPS Provider for Agility and Maintainability
Thursday October 15, 2026 14:30 - 15:00 CEST
Trade-offs of decoupling the OpenSSL FIPS provider from the rest of the library on Yocto-based enterprise networking platforms.
Speakers
WB

William Bellingrath

Senior Systems/Software Engineer, HPE
William has been part of the team that handles the core security libraries and applications across the Juniper Networks (now part of HPE) network portfolio for the past 8 years. He leads the major OpenSSL upgrades and maintains FIPS compliance across the company's networking operating... Read More →
Thursday October 15, 2026 14:30 - 15:00 CEST
Room 3
  Technical, Talk

15:30 CEST

Hardware-enforced cryptographic contexts that RISC-V software can use but never read.
Thursday October 15, 2026 15:30 - 16:10 CEST
The RISC-V Atomic Cryptography Extension keeps plaintext keys out of process memory via hardware-enforced Cryptographic Contexts.
Speakers
RK

Radim Krčmář

Engineer, Qualcomm, Inc.
Radim Krčmář is an engineer at Qualcomm, a contributor to the RISC-V Atomic Cryptography Extension (ACE) and to other RISC-V task groups focused on architectural isolation. Before turning to hardware-software interfaces, he was most visible in the Linux kernel community as a co-maintainer... Read More →
Thursday October 15, 2026 15:30 - 16:10 CEST
Room 3
  Technical, Talk

16:15 CEST

Breaking Deepfakes with Shared Secrets
Thursday October 15, 2026 16:15 - 16:55 CEST
Deepfakes attack the human decision layer, not the crypto; a shared-secret approach where passwords, OTP and biometrics fail.
Speakers
JB

Jonathan Bateman

Founder, realxreal.ai | Senior @ RIT, Rochester Institute of Technology
Jonathan Bateman is a secure‑software developer and applied mathematician who blends technical depth with social awareness to solve complex problems. As the founder of Real Recognizes Real AI (realxreal.ai), he helps people authenticate the online identities of their digital contacts... Read More →
Thursday October 15, 2026 16:15 - 16:55 CEST
Room 3
  Community, Talk

17:00 CEST

From 1.1.1 to 3.5: Modernizing OpenSSL for Enterprise Networking, FIPS 140-3, and Crypto Agility
Thursday October 15, 2026 17:00 - 17:30 CEST
Upgrading Junos from OpenSSL 1.1.1 to 3.5 across FreeBSD/Linux and multiple architectures under FIPS 140-3 and Common Criteria.
Speakers
WB

William Bellingrath

Senior Systems/Software Engineer, HPE
William has been part of the team that handles the core security libraries and applications across the Juniper Networks (now part of HPE) network portfolio for the past 8 years. He leads the major OpenSSL upgrades and maintains FIPS compliance across the company's networking operating... Read More →
Thursday October 15, 2026 17:00 - 17:30 CEST
Room 3
  Technical, Talk
 
OpenSSL Conference 2026
From €250.00
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.