Our agenda,
your
spark.
The programme — 97 sessions across three days and four rooms
The programme, day by day.
§ A note on reading How to read the Agenda
Main Stage · Room 1
The main stage — welcomes, keynotes, panels, and invited sponsor talks, plus parallel sessions through the afternoons.
Hall II · Room 2
Parallel sessions, Tuesday afternoon through Thursday.
Hall III · Room 3
Parallel sessions, Tuesday afternoon through Thursday.
Hall IV · Room 4
The smallest room. Parallel sessions, Tuesday afternoon through Thursday.
Day00
Monday · 12 October · pre-conference add-on
Tutorials
Day · hands-on, three rooms
Mon12 Oct
Code along
— Morning Tea —
Code Along
Tokens - load rust
Build your own provider
— Lunch —
Code along
Tokens
Build your own provider
— Afternoon Tea —
Code Along
— Finish Tutorial Day —
— Host Dinners · Tim, David and Matt —
— Conference Opening Evening · Diplomat Hotel —
Day01
Tuesday · 13 October
The
Arc · foundations & community
Tue13 Oct
Performance
Conference Opening
Welcome to the OpenSSL Conference 2026
Three Decades of OpenSSL: A Leadership Conversation
The Last Mile of Trust
Beyond the Checkbox: How Product Certifications Drive Ongoing Security Strategy and Market Access
Post-Quantum Cryptography: Why Moving Too Fast Can Be as Risky as Moving Too Slowly
— Lunch —
Performance
Spooky Action at a Distance – Entanglement-Based QKD in Practice, From the Physical Layer to the Application
Rebranding OpenSSL: A Laboratory Perspective
OpenDaiY — Move fast and make things.
— Afternoon Tea —
Post-Quantum Cryptography: Evaluation, AI Threats and the Future
Why have the PQC standards taken so long? Bottlenecks, bickering, and building momentum
What's behind the MASQUE
Open Quantum Safe: Post-Quantum software research in the era of the first PQC standards
OpenSSL's TLS Implementation: Inside the State Machine and Record Layer
PLANTS and Merkle Tree Certificates
During a Breach: How Encryption is Evaluated by Regulators, Insurers, and Counsel
Architecting the Agility Layer: Forging a Common Crypto API for the Post-Quantum Era
Privacy Is Not the Enemy! What Law Enforcement Misunderstands and What Cryptographers Can Do About It
Self-Encrypting Disks in Linux - Fast, Expensive, and Mostly Harmless
Instrumenting OpenSSL with Crypto-Auditing Probes for Post-Quantum Readiness
Protecting the Human in a Digital World: How CyberCat Translates Digital Security into Safer Human Decisions
Integrating Multiple Randomness Sources in an SP 800-90C RBGC Framework
How small can you (reasonably) get an ML-DSA and ML-KEM implementation?
New Insights into the Formal Verification of AWS-LC, a Fork of OpenSSL
One Module Three Transitions
— End of Day —
— Boat transport starts —
— Boat Event · dinner and Cruise (starts 19:45) —
Day02
Wednesday · 14 October
The
Filament · deep-dive
Wed14 Oct
OpenSSL Corporation Keynote
Nobody Told Maintainers They Were Saving The World. Now Is The Time.
A library-agnostic hybrid classic/PQ OpenSSL provider — built with AI
Shipping OpenSSL downstream and its challenges
Fresh Eyes on OpenSSL: A Newcomer's Report
Securing the Next Generation: An OpenSSL Youth Outreach Strategy
— Morning Tea —
TLS keyshare caching for faster handshakes
From Copilot to Commit: Handling AI-Generated Code in Open Source Crypto Libraries
"git revert" review of an OpenSSL fork
Finding Timing Side Channels When Internal Clocks Are Hidden
Dr. Tokenlove or: How Bouncy Castle Learned to Stop Worrying and Love the LLM
What shall we do with two PKCS#11 providers?
Who Pays for Open Source? A First-Party Answer from the OpenSSL Corporation
Navigating the Post-Quantum Transition: Integrating FAEST and Classic McEliece into libOQS
Hybrid FIPS module using OpenSSL code: the Kryoptic project
Crypto4A — Session Title Coming Soon
Is the current cryptography testing and validation pipeline process capable of handling the impending Tsunami?
Engineering Reality of CRA Compliance for Linux-based IoT Solutions
— Lunch —
Don McMillan Performance: Technically Funny
Migration roadmaps and PQC standards -- A European perspective
Open Source: The Road to EU Sovereignty
Community panel: Distributions
Optimizing ML-KEM and ML-DSA with Vector Instructions and Mathematical Techniques
— Afternoon Tea —
Artificial Insecurity: how AI threatens digital security and what we can do about it
When Hallucinations Become Vulnerabilities: Building Reliable AI for Cryptography
DTLS 1.3 in OpenSSL
Building Cryptography on Locally Verified Entropy
Legal and Commercial Pitfalls of Poor Open Source and IP Management
Testing PQC Timing Side-Channels
Investigating cryptography deployments in security-certified products with sec-certs
Shim in 2026: A Certificate Rotation and a Decade-Overdue OpenSSL Migration
OpenSSL Corporation Business & Technical Advisory Committees Panel
Jipher FIPS cryptography provider - Wrapping OpenSSL and the FIPS module using Java’s FFM API
Beyond Algorithms: Exploiting Platform Cryptography with OpenSSL Providers
The Bear Leap – How Polar Bear Care Has Transformed at Zoo Brno
450 CVEs Later: Lessons from Securing Open Source with AI
Zero-Overhead Cryptography in OpenSSL-Powered Network Stack
Lessons Learned from Constructing Estonia’s PQC Migration Roadmap
— End of Day —
— Transport to Folklore —
— Folklore Performance and dinner —
Day03
Thursday · 15 October
The
Effect · close
Thu15 Oct
OpenSSL Foundation — Delivering the Mission
The Security Response Process of the OpenSSL Library
The Last Mile of PQC Migration: From Cryptographic Inventory to Production Remediation
Post-Quantum Cryptography on a Budget: Benchmarking ML-KEM and ML-DSA on Constrained IoT Hardware
Jostle, OpenSSL's new Java Cryptography Provider for JVMs 8 to 25+, with FIPS support
— Morning Tea —
Getting a subroutine right: a case study
Going beyond constant-time security in open-source cryptographic libraries
IT Security Product Certification in the Era of Automated Evidence Generation and AI-Assisted Evaluation
From OpenSSL 3 to OpenSSL 4 in Fedora: true story
The Case for Binding and Embedding – Many Modules One Validation
The Family Reunion: OpenSSL, BoringSSL, AWS-LC, and LibreSSL on Why They Forked and What Happens Now
CRA and its Problematic Impacts on F/OSS
DTLS 1.3 in the Linux Kernel via wolfSSL Kernel Module
— Lunch —
AI in Open-Source Cryptography: Maintainers Compare Notes
The State of the OpenSSL Community
Composites Aren’t Optional: Designing PKI for the Post-Quantum Transition and Beyond
Performance: The little sibling of cryptography
Student Bug Bounties for OpenSSL-Based Products
The Cost of Stunt Cryptography
AI assisted PQC integration in Bouncy Castle
FIPS 140-3 Meets PQC - The Compliance Gap Nobody Planned For
From Hidden Cryptography to Enterprise Risk: Securing Ecosystems for Cryptographic Compliance and Post-Quantum Readiness
— Afternoon Tea —
Beyond copyright: IP strategy in the age of generative AI
The EU CRA vs. Community: Why You’re Safe, and How Stewards Help
Hardware-enforced cryptographic contexts that RISC-V software can use but never read.
Managing millions of sboms with trustify
TLS 1.3, session resumption, 0-RTT early data, external PSKs and all that...
EU CRA is around the corner. Are you ready?
Breaking Deepfakes with Shared Secrets
Quantum-Resilient Confidential Computing: Securing Data in Use for the AI Era
OpenSSL Foundation Advisory Committee
Re: [URGENT] Eight Critical 0-Day Vulnerabilities in OpenSSL
From 1.1.1 to 3.5: Modernizing OpenSSL for Enterprise Networking, FIPS 140-3, and Crypto Agility
OpenSSL QUIC adventure
Closing Performance
Monday, before the arc strikes.
A whole day of hands-on workshops the day before the conference proper — in three room types, with the people who built the libraries you ship. Limited seats, paid add-on.
- In the round Horseshoe · code-along
- The walking lecture Grid · the long view
- The hardware bench Devices forward · HSMs & tokens