§ 01 — The Mission In plain English

Half a billion users.
Twenty people.
One Library.

Once a year, the team that keeps it comes into the same room with the integrators, regulators and partners who ship what they make.
A small room. Three days. The work of the next year, decided by the people who do it.

Convened byOpenSSL Corporation
In partnership withPrague TechCity
In Prague12 — 15 October 2026
Edition№ 02
§ 02 — The OpenSSL Mission · verbatim — openssl-mission.org
We believe everyone should have access to security and privacy tools — whoever they are, wherever they are, or whatever their personal beliefs are — as a fundamental human right.
Křižík believed the same about light — that it belonged to everyone, not just the boulevards.
This conference is the line drawn between.
The OpenSSL workspace in Brno — engineering team visible at desks through the glass
The team at work. The Brno office — the room where most of the daily work happens, when the conference isn't.Plate I · Brno · 2026
§ 03 — The Twenty

The roster, in plain sight.

The OpenSSL Library is the world's most widely deployed cryptographic toolkit. It runs in operating systems, browsers, payment networks, satellites, regulated medical devices and the back rooms of every industry that handles a key. By a fair count, it touches well over half a billion users a day.

It is stewarded by a team of around twenty. Maintainers, FIPS engineers, support, legal, ops. Brno, Munich, Auckland, Melbourne, Granada, Spain. The OpenSSL Corporation employs them; the OpenSSL Foundation safeguards the project's independence and the public record; the Advisory Committees keep the room honest.

We're a tiny team. We're twenty people. If we've got funding we expand. What we haven't got is idle engineers. Conversation · partner bank · April 2026

That ratio — twenty people, half a billion users — is the entire reason this conference exists. The work doesn't scale by hiring. It scales by being in the same room as the people who deploy it, regulate it, package it, and depend on it. Three days a year, that room is Prague.

Role
What they carry
Posted
i.
Maintainers. The hands on master.
Patches. Releases. The 4.0 line.
Brno · remote
ii.
FIPS engineers. The validation desk.
140-3 modules. Algorithm tests. Lightship liaison.
Granada · Brno
iii.
Crypto leads. Post-quantum, providers, the standards loop.
ML-KEM · ML-DSA · SLH-DSA · X9.146
Auckland · Melbourne
iv.
Support. The phone that rings when production is on fire.
SLAs. Triage. The customer side of the wall.
EU · APAC · NA
v.
Security coordination. The triage of incoming.
CVEs. Disclosure. The flood (see § 05).
Brno
vi.
Operations. Contracts, rebrands, the office in Brno.
Logistics. Faculty of Informatics partnership. Conference.
Brno · Prague
vii.
Foundation board & advisors. The public-record desk.
Bylaws. Governance. Business & Technical Advisory.
Distributed
Counted at the start of Edition Nº 02
Roster ≈ 20 souls
§ 03 — twenty people · five surfaces · one library

If you do this work, this room is yours. See who's on stage Submit a talk Reserve a seat

§ 04 — How the work gets done

It is a small industry. That is the secret, and the constraint.

Cryptography moves through this industry the way a draft standard moves through a hallway: someone says it to someone, and a week later it exists. The X9.146 hybrid PQC certificate work happened that way — Wells Fargo, Bouncy Castle, Wolf SSL, OpenSSL — over conversations and a couple of glasses of scotch. Now it is a draft, and three implementations interoperate.

And David said to Peter, and Peter said, yeah, I'll do it. And it gets done. It's a really small industry. Conversation · partner bank · April 2026

The pattern repeats. Coalitions of the willing — five or six vendors who each put a few dollars in — produce things no single company could justify. That is how the original FIPS module shipped. It is how the BSI / EUCC module will ship if the room agrees. It is how the next standard will be tested, the next provider written, the next migration funded.

The unit of currency is small and specific: one engineer-year. That is the price of an enterprise tier — a developer, on your platform, every day, finding the breakage early instead of six months late. It is the smallest meaningful commitment. The room knows this. Most of the room is this.

We're ruthless at automation and cost control. Because we're so small, we just see problems differently. Where you'd cost X, we might come in at a tenth. Conversation · OpenSSL · April 2026

The governance follows from the size. The Foundation and the Corporation are co-equal — either body may say yes; neither may say no to the other. The Advisory Committees, Business and Technical, are elected from the community. The approval process is an email that says yes. That is not a slogan. That is the actual process.

This is why the conference is in person. A coalition forms over a coffee, not a calendar invite. A maintainer agrees to a piece of work because the person asking is across the table, not on a thread. The hallway is the work. The talks are the index to it.

§ 04 — coalitions · half-engineer-years · the hallway track
Five OpenSSL maintainers on stage at the inaugural conference, Prague October 2025
The panel. Once a year, the team comes into the same room with the people who ship what they make.Plate III · Prague · 2025
§ 05 — The flood

Two months. The number that put this edition on the calendar.

Increase · inbound CVE reports
1,500%
↑ over baseline Reported · maintainers & partner LCs · April 2026

The volume of inbound security reports landing on open-source cryptographic projects has multiplied by an order of magnitude in eight weeks. Not because the bugs multiplied. Because the tools writing the reports did.

Some of it is excellent. The false-positive rate of the best tools is approaching zero, and important things are being found. Most of it is noise — proofs-of-concept that don't reproduce, severities that are either nothing or doomsday with nothing in between, twenty reports of the same finding from twenty different addresses.

We don't let a day go by without incidents coming in. We're hiring an actual security-coordination person — for the corporation, just to help with the stuff that's coming through. Conversation · cryptographic project lead · April 2026

Twenty people cannot triage at this rate without help, and help cannot be hired at the speed of the inflow. Open source has three current responses: ban it, ignore it, or be slowly consumed by it. None of those is acceptable. A fourth response has to be invented, and it has to be invented with the people on the receiving end.

That is a topic for a hallway, a whiteboard, and three days. Edition Nº 02 is on the calendar for it.
§ 06 — The year of consequence

Edition Nº 02 lands on top of seven concrete things, all moving at once.

OpenSSL 4.0 is in the field — the release that retired the ENGINE API after twenty-six years and put the project's governance on the public record. Post-quantum cryptography stopped being a research topic: ML-KEM, ML-DSA and SLH-DSA are FIPS standards, shipping in the Library, interoperable with fifteen providers, one command from a working TLS session.

X9.146 — hybrid PQC certificates — is in draft and has three interoperating implementations. FIPS 140-3 validation continues with Lightship Security and the new Teron Labs partnership. BSI and EUCC are diverging from FIPS in ways the room needs to reconcile, and a coalition is forming to do it.

Code-signing has been hardened with Entrust nShield HSMs. The Brno office is open. The Faculty of Informatics at Masaryk University is a partner. The flood from § 05 has put security coordination on the hiring plan.

None of that is press-release filler. It is the work of the next year, condensed into three days of talks, hallway conversations, code, and the kind of decisions that only happen when the people who do the work are in the same room.

§ 06 — 4.0 · pq · x9.146 · 140-3 · bsi · hsm · brno · masaryk
§ 07 — Who this is for

Practitioners over pundits. Code over keynotes.

Maintainers and committers. Engineers integrating the Library into operating systems, devices, networks and regulated products. The legal and policy people reading the Bylaws, the eIDAS files, the NIS2 obligations, the BSI profile.

Distributions packaging OpenSSL for the world. Member banks running PQC pilots in production. Hyperscalers running the third-party crypto desk. The Business and Technical Advisory Committees. The sponsors who keep the lights on. Researchers and students arriving with their first patch.

If you have real-world work on cryptography, FIPS, post-quantum, governance, or the OpenSSL Mission — this room is yours. The Call for Papers is open until 15 June 2026.

i.
Maintainers & committers
The people who land patches into the Library.
ii.
Integrators
OS, device, network, regulated product teams.
iii.
Distributions
Packaging OpenSSL for half a billion users.
iv.
Legal & policy
Bylaws, eIDAS, NIS2, FIPS, BSI, the public record.
v.
Advisory committees
Business and Technical — the project's compass.
vi.
Researchers & students
First-patch newcomers welcome. Scholarships open.
§ 07 — practitioners over pundits · code over keynotes
Four attendees in OpenSSL Conference 2025 lanyards on the conference floor, mid-conversation
The floor. This is the room you're invited to join.
§ 08 — A standing invitation

If you do this work, this room is yours.

Three days. Four halls. Twenty maintainers, the people they answer to, and the people who ship what they make. Prague — the city that taught Europe to glow — for the people teaching the world to keep a secret.

Come on the record. Submit a paper, take a seat, sponsor a chair, file a patch, ask a hard question. The Library is the work of the room. The room is open until 15 October 2026.

Submit your paper
Convened by OpenSSL Corporation Edition Nº 02 · Prague