§ 03 — Agenda

The programme, day by day.

§ A note on reading How to read the Agenda

Main Stage · Room 1

§ 01 · the plenary hall

The main stage — welcomes, keynotes, panels, and invited sponsor talks, plus parallel sessions through the afternoons.

Hall II · Room 2

§ 02 · parallel

Parallel sessions, Tuesday afternoon through Thursday.

Hall III · Room 3

§ 03 · parallel

Parallel sessions, Tuesday afternoon through Thursday.

Hall IV · Room 4

§ 04 · parallel

The smallest room. Parallel sessions, Tuesday afternoon through Thursday.

Day00
Monday · 12 October · pre-conference add-on
Tutorials Day · hands-on, three rooms
Mon12 Oct
09:00
Tutorial

Code along

Room 1 · Tutorial90 min
10:30

— Morning Tea —

All rooms30 min
11:00
Tutorial

Code Along

Room 1 · Tutorial90 min
11:00
Tutorial

Tokens - load rust

Room 2 · Tutorial90 min
11:00
Tutorial

Build your own provider

Room 3 · Tutorial90 min
12:30

— Lunch —

All rooms60 min
13:30
Tutorial

Code along

Room 1 · Tutorial90 min
13:30
Tutorial

Tokens

Room 2 · Tutorial90 min
13:30
Tutorial

Build your own provider

Room 3 · Tutorial90 min
15:00

— Afternoon Tea —

All rooms30 min
15:30
Tutorial

Code Along

Room 1 · Tutorial90 min
17:00

— Finish Tutorial Day —

All rooms30 min
17:30

— Host Dinners · Tim, David and Matt —

Around Prague2 h
20:00

— Conference Opening Evening · Diplomat Hotel —

Diplomat5 h
Day01
Tuesday · 13 October
The Arc · foundations & community
Tue13 Oct
09:00
Main Stage

Performance

Room 1 · Community5 min
09:05
Plenary · Magda Zdunkiewicz

Conference Opening

Room 1 · Community5 min
09:10
Plenary · Tim Hudson, Anton Arapov

Welcome to the OpenSSL Conference 2026

Room 1 · Keynote10 min
09:20

Three Decades of OpenSSL: A Leadership Conversation

Room 1 · Community60 min
10:20
Plenary · Jonathan Felten

The Last Mile of Trust

Room 1 · Keynote30 min
10:50
Plenary · Lisa Rogers

Beyond the Checkbox: How Product Certifications Drive Ongoing Security Strategy and Market Access

Room 1 · Security30 min
11:20
Plenary · Marcel Dasen

Post-Quantum Cryptography: Why Moving Too Fast Can Be as Risky as Moving Too Slowly

Room 1 · Security30 min
12:00

— Lunch —

All rooms70 min
13:10
Main Stage

Performance

Room 1 · Community5 min
13:20
Plenary · Kevin Füchsel

Spooky Action at a Distance – Entanglement-Based QKD in Practice, From the Physical Layer to the Application

Room 1 · Business30 min
13:50
Plenary · Jonathan Park

Rebranding OpenSSL: A Laboratory Perspective

Room 1 · Security30 min
14:20
Plenary · Justin Corlett

OpenDaiY — Move fast and make things.

Room 1 · Business30 min
14:50

— Afternoon Tea —

All rooms30 min
15:20

Post-Quantum Cryptography: Evaluation, AI Threats and the Future

Room 1 · Security40 min
15:20

Why have the PQC standards taken so long? Bottlenecks, bickering, and building momentum

Room 2 · Community40 min
15:20

What's behind the MASQUE

Room 3 · Technical40 min
15:20

Open Quantum Safe: Post-Quantum software research in the era of the first PQC standards

Room 4 · Technical40 min
16:05

OpenSSL's TLS Implementation: Inside the State Machine and Record Layer

Room 1 · Technical50 min
16:05

PLANTS and Merkle Tree Certificates

Room 2 · Technical50 min
16:05

During a Breach: How Encryption is Evaluated by Regulators, Insurers, and Counsel

Room 3 · Security40 min
16:05

Architecting the Agility Layer: Forging a Common Crypto API for the Post-Quantum Era

Room 4 · Security50 min
17:00

Privacy Is Not the Enemy! What Law Enforcement Misunderstands and What Cryptographers Can Do About It

Room 1 · Security30 min
17:00

Self-Encrypting Disks in Linux - Fast, Expensive, and Mostly Harmless

Room 2 · Community30 min
17:00

Instrumenting OpenSSL with Crypto-Auditing Probes for Post-Quantum Readiness

Room 3 · Security30 min
17:00

Protecting the Human in a Digital World: How CyberCat Translates Digital Security into Safer Human Decisions

Room 4 · Community30 min
17:30

Integrating Multiple Randomness Sources in an SP 800-90C RBGC Framework

Room 1 · Technical30 min
17:30

How small can you (reasonably) get an ML-DSA and ML-KEM implementation?

Room 2 · Technical30 min
17:30

New Insights into the Formal Verification of AWS-LC, a Fork of OpenSSL

Room 3 · Technical30 min
17:30

One Module Three Transitions

Room 4 · Technical30 min
18:00

— End of Day —

All rooms5 min
19:00

— Boat transport starts —

Vltava30 min
19:30

— Boat Event · dinner and Cruise (starts 19:45) —

Vltava3 h
Day02
Wednesday · 14 October
The Filament · deep-dive
Wed14 Oct
09:00
Plenary · Tim Hudson, Anton Arapov

OpenSSL Corporation Keynote

Room 1 · Keynote30 min
09:30

Nobody Told Maintainers They Were Saving The World. Now Is The Time.

Room 1 · Community30 min
09:30

A library-agnostic hybrid classic/PQ OpenSSL provider — built with AI

Room 2 · Technical30 min
09:30

Shipping OpenSSL downstream and its challenges

Room 3 · Community30 min
09:30

Fresh Eyes on OpenSSL: A Newcomer's Report

Room 4 · Community15 min
09:45

Securing the Next Generation: An OpenSSL Youth Outreach Strategy

Room 4 · Community15 min
10:00

— Morning Tea —

All rooms30 min
10:30

TLS keyshare caching for faster handshakes

Room 1 · Community30 min
10:30

From Copilot to Commit: Handling AI-Generated Code in Open Source Crypto Libraries

Room 2 · Security30 min
10:30

"git revert" review of an OpenSSL fork

Room 3 · Community30 min
10:30

Finding Timing Side Channels When Internal Clocks Are Hidden

Room 4 · Technical30 min
11:00

Dr. Tokenlove or: How Bouncy Castle Learned to Stop Worrying and Love the LLM

Room 1 · Technical30 min
11:00

What shall we do with two PKCS#11 providers?

Room 2 · Community30 min
11:00

Who Pays for Open Source? A First-Party Answer from the OpenSSL Corporation

Room 3 · Community30 min
11:00

Navigating the Post-Quantum Transition: Integrating FAEST and Classic McEliece into libOQS

Room 4 · Community30 min
11:30

Hybrid FIPS module using OpenSSL code: the Kryoptic project

Room 1 · Technical30 min
11:30

Crypto4A — Session Title Coming Soon

Room 2 · Business30 min
11:30

Is the current cryptography testing and validation pipeline process capable of handling the impending Tsunami?

Room 3 · Security30 min
11:30

Engineering Reality of CRA Compliance for Linux-based IoT Solutions

Room 4 · Security30 min
12:00

— Lunch —

All rooms70 min
13:20
Main Stage

Don McMillan Performance: Technically Funny

Room 1 · Special60 min
14:20

Migration roadmaps and PQC standards -- A European perspective

Room 1 · Technical40 min
14:20

Open Source: The Road to EU Sovereignty

Room 2 · Community30 min
14:20

Community panel: Distributions

Room 3 · Community40 min
14:20

Optimizing ML-KEM and ML-DSA with Vector Instructions and Mathematical Techniques

Room 4 · Technical40 min
15:00

— Afternoon Tea —

All rooms30 min
15:30

Artificial Insecurity: how AI threatens digital security and what we can do about it

Room 1 · Security40 min
15:30

When Hallucinations Become Vulnerabilities: Building Reliable AI for Cryptography

Room 2 · Technical40 min
15:30

DTLS 1.3 in OpenSSL

Room 3 · Technical40 min
15:30

Building Cryptography on Locally Verified Entropy

Room 4 · Security40 min
16:10

Legal and Commercial Pitfalls of Poor Open Source and IP Management

Room 1 · Security40 min
16:10

Testing PQC Timing Side-Channels

Room 2 · Technical40 min
16:10

Investigating cryptography deployments in security-certified products with sec-certs

Room 3 · Security40 min
16:10

Shim in 2026: A Certificate Rotation and a Decade-Overdue OpenSSL Migration

Room 4 · Community40 min
16:50

OpenSSL Corporation Business & Technical Advisory Committees Panel

Room 1 · Community60 min
16:50

Jipher FIPS cryptography provider - Wrapping OpenSSL and the FIPS module using Java’s FFM API

Room 2 · Technical40 min
16:50

Beyond Algorithms: Exploiting Platform Cryptography with OpenSSL Providers

Room 3 · Technical40 min
16:50

The Bear Leap – How Polar Bear Care Has Transformed at Zoo Brno

Room 4 · Community30 min
17:30

450 CVEs Later: Lessons from Securing Open Source with AI

Room 2 · Business30 min
17:30

Zero-Overhead Cryptography in OpenSSL-Powered Network Stack

Room 3 · Technical30 min
17:30

Lessons Learned from Constructing Estonia’s PQC Migration Roadmap

Room 4 · Community30 min
18:00

— End of Day —

All rooms5 min
19:00

— Transport to Folklore —

Coaches30 min
19:30

— Folklore Performance and dinner —

Folklore Garden5 h
Day03
Thursday · 15 October
The Effect · close
Thu15 Oct
09:00
Plenary · Matt Caswell

OpenSSL Foundation — Delivering the Mission

Room 1 · Keynote30 min
09:30

The Security Response Process of the OpenSSL Library

Room 1 · Community30 min
09:30

The Last Mile of PQC Migration: From Cryptographic Inventory to Production Remediation

Room 2 · Business30 min
09:30

Post-Quantum Cryptography on a Budget: Benchmarking ML-KEM and ML-DSA on Constrained IoT Hardware

Room 3 · Technical30 min
09:30

Jostle, OpenSSL's new Java Cryptography Provider for JVMs 8 to 25+, with FIPS support

Room 4 · Technical30 min
10:00

— Morning Tea —

All rooms30 min
10:30

Getting a subroutine right: a case study

Room 1 · Technical40 min
10:30

Going beyond constant-time security in open-source cryptographic libraries

Room 2 · Technical40 min
10:30

IT Security Product Certification in the Era of Automated Evidence Generation and AI-Assisted Evaluation

Room 3 · Security40 min
10:30

From OpenSSL 3 to OpenSSL 4 in Fedora: true story

Room 4 · Business40 min
11:15

The Case for Binding and Embedding – Many Modules One Validation

Room 1 · Security40 min
11:15

The Family Reunion: OpenSSL, BoringSSL, AWS-LC, and LibreSSL on Why They Forked and What Happens Now

Room 2 · Community40 min
11:15

CRA and its Problematic Impacts on F/OSS

Room 3 · Security30 min
11:15

DTLS 1.3 in the Linux Kernel via wolfSSL Kernel Module

Room 4 · Technical40 min
12:00

— Lunch —

All rooms70 min
13:20

AI in Open-Source Cryptography: Maintainers Compare Notes

Room 1 · Community40 min
14:00

The State of the OpenSSL Community

Room 1 · Community30 min
14:00

Composites Aren’t Optional: Designing PKI for the Post-Quantum Transition and Beyond

Room 2 · Technical30 min
14:00

Performance: The little sibling of cryptography

Room 3 · Technical30 min
14:00

Student Bug Bounties for OpenSSL-Based Products

Room 4 · Community30 min
14:30

The Cost of Stunt Cryptography

Room 1 · Technical30 min
14:30

AI assisted PQC integration in Bouncy Castle

Room 2 · Technical30 min
14:30

FIPS 140-3 Meets PQC - The Compliance Gap Nobody Planned For

Room 3 · Security30 min
14:30

From Hidden Cryptography to Enterprise Risk: Securing Ecosystems for Cryptographic Compliance and Post-Quantum Readiness

Room 4 · Security30 min
15:00

— Afternoon Tea —

All rooms30 min
15:30

Beyond copyright: IP strategy in the age of generative AI

Room 1 · Security40 min
15:30

The EU CRA vs. Community: Why You’re Safe, and How Stewards Help

Room 2 · Security40 min
15:30

Hardware-enforced cryptographic contexts that RISC-V software can use but never read.

Room 3 · Technical40 min
15:30

Managing millions of sboms with trustify

Room 4 · Security40 min
16:15

TLS 1.3, session resumption, 0-RTT early data, external PSKs and all that...

Room 1 · Technical40 min
16:15

EU CRA is around the corner. Are you ready?

Room 2 · Security40 min
16:15

Breaking Deepfakes with Shared Secrets

Room 3 · Community40 min
16:15

Quantum-Resilient Confidential Computing: Securing Data in Use for the AI Era

Room 4 · Technical30 min
17:00
Room 1 · Community40 min
17:00

Re: [URGENT] Eight Critical 0-Day Vulnerabilities in OpenSSL

Room 2 · Security30 min
17:00

From 1.1.1 to 3.5: Modernizing OpenSSL for Enterprise Networking, FIPS 140-3, and Crypto Agility

Room 3 · Technical30 min
17:00

OpenSSL QUIC adventure

Room 4 · Technical30 min
17:40
Main Stage

Closing Performance

Room 1 · Community7 min
§ 03 — 97 sessions scheduled · four rooms · invited topics announced as they land

Monday, before the arc strikes.

A whole day of hands-on workshops the day before the conference proper — in three room types, with the people who built the libraries you ship. Limited seats, paid add-on.

  • In the round Horseshoe · code-along
  • The walking lecture Grid · the long view
  • The hardware bench Devices forward · HSMs & tokens
Confirmed tutors Bouncy Castle engineering · Prof. Bill Buchanan · Daniel Heinrich · more locking in through spring
See tutorials ~80 seats across the day · paid add-on