§ 03 — Agenda

The programme, day by day.

§ A note on reading How to read the Agenda

Main Stage · Room 1

§ 01 · the plenary hall

The main stage — welcomes, keynotes, panels, and invited sponsor talks, plus parallel sessions through the afternoons.

Hall II · Room 2

§ 02 · parallel

Parallel sessions, Tuesday afternoon through Thursday.

Hall III · Room 3

§ 03 · parallel

Parallel sessions, Tuesday afternoon through Thursday.

Hall IV · Room 4

§ 04 · parallel

The smallest room. Parallel sessions, Tuesday afternoon through Thursday.

Day00
Monday · 12 October · pre-conference add-on
Tutorials Day · hands-on, three rooms
Mon12 Oct
09:00
Tutorial

Code along

Room 1 · Tutorial90 min
10:30

— Morning Tea —

All rooms30 min
11:00
Tutorial

Code Along

Room 1 · Tutorial90 min
11:00
Tutorial

Tokens - load rust

Room 2 · Tutorial90 min
11:00
Tutorial

Build your own provider

Room 3 · Tutorial90 min
12:30

— Lunch —

All rooms60 min
13:30
Tutorial

Code along

Room 1 · Tutorial90 min
13:30
Tutorial

Tokens

Room 2 · Tutorial90 min
13:30
Tutorial

Build your own provider

Room 3 · Tutorial90 min
15:00

— Afternoon Tea —

All rooms30 min
15:30
Tutorial

Code Along

Room 1 · Tutorial90 min
17:00

— Finish Tutorial Day —

All rooms30 min
17:30

— Host Dinners · Tim, David and Matt —

Around Prague2 h
20:00

— Conference Opening Evening · Diplomat Hotel —

Diplomat5 h
Day01
Tuesday · 13 October
The Arc · foundations & community
Tue13 Oct
09:00
Main Stage

Performance

Room 1 · Community5 min
09:05
Plenary · Magda Zdunkiewicz

Conference Opening

Room 1 · Community5 min
09:10
Plenary · Tim Hudson, Anton Arapov

Welcome to the OpenSSL Conference 2026

Room 1 · Community10 min
09:20
Plenary · Eric A. Young, Tim Hudson, Matt Caswell, Magda Zdunkiewicz

Three Decades of OpenSSL: A Leadership Conversation

Room 1 · Community60 min
10:20
Plenary · Jonathan Felten

Cisco — Session Title Coming Soon

Room 1 · Business30 min
10:50
Plenary · Lisa Rogers

Beyond the Checkbox: How Product Certifications Drive Ongoing Security Strategy and Market Access

Room 1 · Security30 min
11:20
Plenary · Marcel Dasen

Post-Quantum Cryptography: Why Moving Too Fast Can Be as Risky as Moving Too Slowly

Room 1 · Security30 min
12:00

— Lunch —

All rooms70 min
13:10
Main Stage

Performance

Room 1 · Community5 min
13:20
Plenary · Kevin Füchsel

Spooky Action at a Distance – Entanglement-Based QKD in Practice, From the Physical Layer to the Application

Room 1 · Business30 min
13:50
Plenary · Jonathan Park

Rebranding OpenSSL: A Laboratory Perspective

Room 1 · Security30 min
14:20
Plenary · Justin Corlett

Cryptsoft — Session Title Coming Soon

Room 1 · Business30 min
14:50

— Afternoon Tea —

All rooms30 min
15:20
Bill Buchanan

Post-Quantum Cryptography: Evaluation, AI Threats and the Future

Room 1 · Security40 min
15:20
Mike Ounsworth

Why have the PQC standards taken so long? Bottlenecks, bickering, and building momentum

Room 2 · Community40 min
15:20
Yaroslav Rosomakho

What's behind the MASQUE

Room 3 · Technical40 min
15:20
Rodrigo Martín Sánchez-Ledesma

Open Quantum Safe: Post-Quantum software research in the era of the first PQC standards

Room 4 · Technical40 min
16:05
Matt Caswell

OpenSSL's TLS Implementation: Inside the State Machine and Record Layer

Room 1 · Technical50 min
16:05
Bob Beck, Andrew Dinh

PLANTS and Merkle Tree Certificates

Room 2 · Technical50 min
16:05
Amanda McAllister Novak

During a Breach: How Encryption is Evaluated by Regulators, Insurers, and Counsel

Room 3 · Security40 min
16:05
Dr. Vladimir Soukharev, Murugiah Souppaya, David Hook, Mike Kushner

Architecting the Agility Layer: Forging a Common Crypto API for the Post-Quantum Era

Room 4 · Security50 min
17:00
Dr. Katrina Khanta, D.Sc.

Privacy Is Not the Enemy! What Law Enforcement Misunderstands and What Cryptographers Can Do About It

Room 1 · Security30 min
17:00
Kajal Sapkota

Who Pays for Open Source? A First-Party Answer from the OpenSSL Corporation

Room 2 · Community30 min
17:00
Clemens Lang

Instrumenting OpenSSL with Crypto-Auditing Probes for Post-Quantum Readiness

Room 3 · Security30 min
17:00
Rene Malmgren

Verifiable Builds in Untrusted Clouds

Room 4 · Business30 min
17:30
Joshua Hill

Integrating Multiple Randomness Sources in an SP 800-90C RBGC Framework

Room 1 · Technical30 min
17:30
Mike Ounsworth

How small can you (reasonably) get an ML-DSA and ML-KEM implementation?

Room 2 · Technical30 min
17:30
Daniella Y Taveau

The Perfect Storm: Why Tech Is the Next Target for Destructive Regulation

Room 3 · Security30 min
17:30
Jake Maynard

One Module Three Transitions

Room 4 · Technical30 min
18:00

— End of Day —

All rooms5 min
19:00

— Boat transport starts —

Vltava30 min
19:30

— Boat Event · dinner and Cruise (starts 19:45) —

Vltava3 h
Day02
Wednesday · 14 October
The Filament · deep-dive
Wed14 Oct
09:00
Plenary · Tim Hudson

OpenSSL Corporation Keynote

Room 1 · Community30 min
09:30
Roman Zhukov

Nobody Told Maintainers They Were Saving The World. Now Is The Time.

Room 1 · Community30 min
09:30
Michael Baentsch

A library-agnostic hybrid classic/PQ OpenSSL provider — built with AI

Room 2 · Technical30 min
09:30
Angel Yankov, Lucas Mülling

Shipping OpenSSL downstream and its challenges

Room 3 · Community30 min
09:30
Stefan Eberle

Fresh Eyes on OpenSSL: A Newcomer's Report

Room 4 · Community15 min
09:45
Carla Jedani

Securing the Next Generation: An OpenSSL Youth Outreach Strategy

Room 4 · Community15 min
10:00

— Morning Tea —

All rooms30 min
10:30
Panos Kampanakis

TLS keyshare caching for faster handshakes

Room 1 · Community30 min
10:30
Dr. Lina Böcker

From Copilot to Commit: Handling AI-Generated Code in Open Source Crypto Libraries

Room 2 · Security30 min
10:30
Rich Salz

"git revert" review of an OpenSSL fork

Room 3 · Community30 min
10:30
Veronika Hanulíková

Finding Timing Side Channels When Internal Clocks Are Hidden

Room 4 · Technical30 min
11:00
David Hook

Dr. Tokenlove or: How Bouncy Castle Learned to Stop Worrying and Love the LLM

Room 1 · Technical30 min
11:00
Milan Brož

Self-Encrypting Disks in Linux - Fast, Expensive, and Mostly Harmless

Room 2 · Community30 min
11:00
Norman Ashley

Navigating the Post-Quantum Transition: Integrating FAEST and Classic McEliece into libOQS

Room 3 · Community30 min
11:00
Pavel Loutocký

CRA and its Problematic Impacts on F/OSS

Room 4 · Security30 min
11:30
Simo Sorce

Hybrid FIPS module using OpenSSL code: the Kryoptic project

Room 1 · Technical30 min
11:30
Sponsor session

Crypto4A — Session Title Coming Soon

Room 2 · Business30 min
11:30
Shawn Geddis, Jasmine Geddis

Is the current cryptography testing and validation pipeline process capable of handling the impending Tsunami?

Room 3 · Security30 min
11:30
Pavel Polach, Maxim Kostin

Engineering Reality of CRA Compliance for Linux-based IoT Solutions

Room 4 · Security30 min
12:00

— Lunch —

All rooms70 min
13:20
Main Stage

Don McMillan Performance: Technically Funny

Room 1 · Community60 min
14:20
Daniel J. Bernstein

Daniel J. Bernstein — Session Title Coming Soon

Room 1 · Technical40 min
14:20
Alix Guillard

Open Source: The Road to EU Sovereignty

Room 2 · Community30 min
14:20
Lucas Mülling

Community panel: Distributions

Room 3 · Community40 min
14:20
Timo Keller

Optimizing ML-KEM and ML-DSA with Vector Instructions and Mathematical Techniques

Room 4 · Technical40 min
15:00

— Afternoon Tea —

All rooms30 min
15:30
Marcel Kolaja

Artificial Insecurity: how AI threatens digital security and what we can do about it

Room 1 · Security40 min
15:30
Francis Mendoza

When Hallucinations Become Vulnerabilities: Building Reliable AI for Cryptography

Room 2 · Technical40 min
15:30
Ryan Hooper

DTLS 1.3 in OpenSSL

Room 3 · Technical40 min
15:30
Jordi Prieto Gallego

Building Cryptography on Locally Verified Entropy

Room 4 · Security40 min
16:10
Brandan Payne

Why People Trust the Internet but Ignore What Protects It

Room 1 · Business40 min
16:10
Alicja Kario

Testing PQC Timing Side-Channels

Room 2 · Technical40 min
16:10
Vashek Matyas, Yasir Yakup Demircan

Investigating cryptography deployments in security-certified products with sec-certs

Room 3 · Security40 min
16:10
Brian bex Exelbierd

Shim in 2026: A Certificate Rotation and a Decade-Overdue OpenSSL Migration

Room 4 · Community40 min
16:50
Paul Yang, Jaroslav Řezník, Randall Becker, Jeff Johnson, Nikolas Gauder, Simo Sorce, Dmitry Belyavskiy, Aditya Koranga, Kevin Micciche, Chris Ward

OpenSSL Corporation Business & Technical Advisory Committees Panel

Room 1 · Community60 min
16:50
Jon Spillett

Jipher FIPS cryptography provider - Wrapping OpenSSL and the FIPS module using Java’s FFM API

Room 2 · Technical40 min
16:50
Holger Dengler

Beyond Algorithms: Exploiting Platform Cryptography with OpenSSL Providers

Room 3 · Technical40 min
16:50
Matyáš Bernardy, Tereza Zerhau

The Bear Leap – How Polar Bear Care Has Transformed at Zoo Brno

Room 4 · Community30 min
17:30
Jakub Jelen

What shall we do with two PKCS#11 providers?

Room 2 · Community30 min
17:30
Nicky Mouha

New Insights into the Formal Verification of AWS-LC, a Fork of OpenSSL

Room 3 · Technical30 min
17:30
Jelizaveta Vakarjuk

Lessons Learned from Constructing Estonia’s PQC Migration Roadmap

Room 4 · Community30 min
18:00

— End of Day —

All rooms5 min
19:00

— Transport to Folklore —

Coaches30 min
19:30

— Folklore Performance and dinner —

Folklore Garden5 h
Day03
Thursday · 15 October
The Effect · close
Thu15 Oct
09:00
Plenary · Matt Caswell

OpenSSL Foundation — Delivering the Mission

Room 1 · Community30 min
09:30
Tomáš Mráz

The Security Response Process of the OpenSSL Library

Room 1 · Community30 min
09:30
Clemens Lang

The Good, the Bad and the Ugly: Tales from the last three years PQC transition at Red Hat

Room 2 · Business30 min
09:30
Olivier Gillot

Post-Quantum Cryptography on a Budget: Benchmarking ML-KEM and ML-DSA on Constrained IoT Hardware

Room 3 · Technical30 min
09:30
Megan Woods

The JOSTLE project from idea to first release.

Room 4 · Technical30 min
10:00

— Morning Tea —

All rooms30 min
10:30
Tanja Lange

Tanja Lange — Session Title Coming Soon

Room 1 · Technical40 min
10:30
Jan Janasek

Going beyond constant-time security in open-source cryptographic libraries

Room 2 · Technical40 min
10:30
Jussipekka Leiwo

IT Security Product Certification in the Era of Automated Evidence Generation and AI-Assisted Evaluation

Room 3 · Security40 min
10:30
Dmitry Belyavskiy

From OpenSSL 3 to OpenSSL 4 in Fedora: true story

Room 4 · Business40 min
11:15
Tricia Wolff

The Case for Binding and Embedding – Many Modules One Validation

Room 1 · Security40 min
11:15
Kajal Sapkota

The Family Reunion: OpenSSL, BoringSSL, AWS-LC, and LibreSSL on Why They Forked and What Happens Now

Room 2 · Community40 min
11:15
Tereza Formanová

Legal and Commercial Pitfalls of Poor Open Source and IP Management

Room 3 · Security40 min
11:15
Anthony Hu

DTLS 1.3 in the Linux Kernel via wolfSSL Kernel Module

Room 4 · Technical40 min
12:00

— Lunch —

All rooms70 min
13:20
Plenary · Peter Gutmann, David Hook

AI in Open-Source Cryptography: Maintainers Compare Notes

Room 1 · Community40 min
14:00
Jon Ericson, Chris Ward

The State of the OpenSSL Community

Room 1 · Community30 min
14:00
John Gray

Composites Aren’t Optional: Designing PKI for the Post-Quantum Transition and Beyond

Room 2 · Technical30 min
14:00
Neil Horman, Bob Beck

Performance: The little sibling of cryptography

Room 3 · Technical30 min
14:00
Kamil Malinka

Student Bug Bounties for OpenSSL-Based Products

Room 4 · Community30 min
14:30
Peter Gutmann

The Cost of Stunt Cryptography

Room 1 · Technical30 min
14:30
Roy Basmacier

AI assisted PQC integration in Bouncy Castle

Room 2 · Technical30 min
14:30
Chris Brych

FIPS 140-3 Meets PQC - The Compliance Gap Nobody Planned For

Room 3 · Security30 min
14:30
Dr. Vladimir Soukharev

From Hidden Cryptography to Enterprise Risk: Securing Ecosystems for Cryptographic Compliance and Post-Quantum Readiness

Room 4 · Security30 min
15:00

— Afternoon Tea —

All rooms30 min
15:30
Hayden Delaney

Beyond copyright: IP strategy in the age of generative AI

Room 1 · Security40 min
15:30
Jaroslav Řezník

The EU CRA vs. Community: Why You’re Safe, and How Stewards Help

Room 2 · Security40 min
15:30
Radim Krčmář

Hardware-enforced cryptographic contexts that RISC-V software can use but never read.

Room 3 · Technical40 min
15:30
James Fuller

Managing millions of sboms with trustify

Room 4 · Security40 min
16:15
Viktor Dukhovni

TLS 1.3, session resumption, 0-RTT early data, external PSKs and all that...

Room 1 · Technical40 min
16:15
Sridhar Balasubramanian

EU CRA is around the corner. Are you ready?

Room 2 · Security40 min
16:15
Jonathan Bateman

Breaking Deepfakes with Shared Secrets

Room 3 · Community40 min
16:15
Paul Yang

Quantum-Resilient Confidential Computing: Securing Data in Use for the AI Era

Room 4 · Technical30 min
17:00
Shubham Kumar, Clemens Lang, Randall Becker, Yi Ouyang, Nicola Tuveri, Dmitry Belyavskiy, Igor Ustinov, Aditya Koranga, Jon Ericson

OpenSSL Foundation Advisory Committee

Room 1 · Community40 min
17:00
Norbert Pocs

Re: [URGENT] Eight Critical 0-Day Vulnerabilities in OpenSSL

Room 2 · Security30 min
17:00
William Bellingrath

From 1.1.1 to 3.5: Modernizing OpenSSL for Enterprise Networking, FIPS 140-3, and Crypto Agility

Room 3 · Technical30 min
17:00
Alexandr Nedvedicky

OpenSSL QUIC adventure

Room 4 · Technical30 min
17:40
Main Stage

Closing Performance

Room 1 · Community7 min
§ 03 — 97 sessions scheduled · four rooms · invited topics announced as they land

Monday, before the arc strikes.

A whole day of hands-on workshops the day before the conference proper — in three room types, with the people who built the libraries you ship. Limited seats, paid add-on.

  • In the round Horseshoe · code-along
  • The walking lecture Grid · the long view
  • The hardware bench Devices forward · HSMs & tokens
Confirmed tutors Bouncy Castle engineering · Prof. Bill Buchanan · Daniel Heinrich · more locking in through spring
See tutorials ~80 seats across the day · paid add-on