Our agenda,
your
spark.
The programme — 97 sessions across three days and four rooms
The programme, day by day.
§ A note on reading How to read the Agenda
Main Stage · Room 1
The main stage — welcomes, keynotes, panels, and invited sponsor talks, plus parallel sessions through the afternoons.
Hall II · Room 2
Parallel sessions, Tuesday afternoon through Thursday.
Hall III · Room 3
Parallel sessions, Tuesday afternoon through Thursday.
Hall IV · Room 4
The smallest room. Parallel sessions, Tuesday afternoon through Thursday.
Day00
Monday · 12 October · pre-conference add-on
Tutorials
Day · hands-on, three rooms
Mon12 Oct
Code along
— Morning Tea —
Code Along
Tokens - load rust
Build your own provider
— Lunch —
Code along
Tokens
Build your own provider
— Afternoon Tea —
Code Along
— Finish Tutorial Day —
— Host Dinners · Tim, David and Matt —
— Conference Opening Evening · Diplomat Hotel —
Day01
Tuesday · 13 October
The
Arc · foundations & community
Tue13 Oct
Performance
Conference Opening
Welcome to the OpenSSL Conference 2026
Three Decades of OpenSSL: A Leadership Conversation
Cisco — Session Title Coming Soon
Beyond the Checkbox: How Product Certifications Drive Ongoing Security Strategy and Market Access
Post-Quantum Cryptography: Why Moving Too Fast Can Be as Risky as Moving Too Slowly
— Lunch —
Performance
Spooky Action at a Distance – Entanglement-Based QKD in Practice, From the Physical Layer to the Application
Rebranding OpenSSL: A Laboratory Perspective
Cryptsoft — Session Title Coming Soon
— Afternoon Tea —
Post-Quantum Cryptography: Evaluation, AI Threats and the Future
Why have the PQC standards taken so long? Bottlenecks, bickering, and building momentum
What's behind the MASQUE
Open Quantum Safe: Post-Quantum software research in the era of the first PQC standards
OpenSSL's TLS Implementation: Inside the State Machine and Record Layer
PLANTS and Merkle Tree Certificates
During a Breach: How Encryption is Evaluated by Regulators, Insurers, and Counsel
Architecting the Agility Layer: Forging a Common Crypto API for the Post-Quantum Era
Privacy Is Not the Enemy! What Law Enforcement Misunderstands and What Cryptographers Can Do About It
Who Pays for Open Source? A First-Party Answer from the OpenSSL Corporation
Instrumenting OpenSSL with Crypto-Auditing Probes for Post-Quantum Readiness
Verifiable Builds in Untrusted Clouds
Integrating Multiple Randomness Sources in an SP 800-90C RBGC Framework
How small can you (reasonably) get an ML-DSA and ML-KEM implementation?
The Perfect Storm: Why Tech Is the Next Target for Destructive Regulation
One Module Three Transitions
— End of Day —
— Boat transport starts —
— Boat Event · dinner and Cruise (starts 19:45) —
Day02
Wednesday · 14 October
The
Filament · deep-dive
Wed14 Oct
OpenSSL Corporation Keynote
Nobody Told Maintainers They Were Saving The World. Now Is The Time.
A library-agnostic hybrid classic/PQ OpenSSL provider — built with AI
Shipping OpenSSL downstream and its challenges
Fresh Eyes on OpenSSL: A Newcomer's Report
Securing the Next Generation: An OpenSSL Youth Outreach Strategy
— Morning Tea —
TLS keyshare caching for faster handshakes
From Copilot to Commit: Handling AI-Generated Code in Open Source Crypto Libraries
"git revert" review of an OpenSSL fork
Finding Timing Side Channels When Internal Clocks Are Hidden
Dr. Tokenlove or: How Bouncy Castle Learned to Stop Worrying and Love the LLM
Self-Encrypting Disks in Linux - Fast, Expensive, and Mostly Harmless
Navigating the Post-Quantum Transition: Integrating FAEST and Classic McEliece into libOQS
CRA and its Problematic Impacts on F/OSS
Hybrid FIPS module using OpenSSL code: the Kryoptic project
Crypto4A — Session Title Coming Soon
Is the current cryptography testing and validation pipeline process capable of handling the impending Tsunami?
Engineering Reality of CRA Compliance for Linux-based IoT Solutions
— Lunch —
Don McMillan Performance: Technically Funny
Daniel J. Bernstein — Session Title Coming Soon
Open Source: The Road to EU Sovereignty
Community panel: Distributions
Optimizing ML-KEM and ML-DSA with Vector Instructions and Mathematical Techniques
— Afternoon Tea —
Artificial Insecurity: how AI threatens digital security and what we can do about it
When Hallucinations Become Vulnerabilities: Building Reliable AI for Cryptography
DTLS 1.3 in OpenSSL
Building Cryptography on Locally Verified Entropy
Why People Trust the Internet but Ignore What Protects It
Testing PQC Timing Side-Channels
Investigating cryptography deployments in security-certified products with sec-certs
Shim in 2026: A Certificate Rotation and a Decade-Overdue OpenSSL Migration
OpenSSL Corporation Business & Technical Advisory Committees Panel
Jipher FIPS cryptography provider - Wrapping OpenSSL and the FIPS module using Java’s FFM API
Beyond Algorithms: Exploiting Platform Cryptography with OpenSSL Providers
The Bear Leap – How Polar Bear Care Has Transformed at Zoo Brno
What shall we do with two PKCS#11 providers?
New Insights into the Formal Verification of AWS-LC, a Fork of OpenSSL
Lessons Learned from Constructing Estonia’s PQC Migration Roadmap
— End of Day —
— Transport to Folklore —
— Folklore Performance and dinner —
Day03
Thursday · 15 October
The
Effect · close
Thu15 Oct
OpenSSL Foundation — Delivering the Mission
The Security Response Process of the OpenSSL Library
The Good, the Bad and the Ugly: Tales from the last three years PQC transition at Red Hat
Post-Quantum Cryptography on a Budget: Benchmarking ML-KEM and ML-DSA on Constrained IoT Hardware
The JOSTLE project from idea to first release.
— Morning Tea —
Tanja Lange — Session Title Coming Soon
Going beyond constant-time security in open-source cryptographic libraries
IT Security Product Certification in the Era of Automated Evidence Generation and AI-Assisted Evaluation
From OpenSSL 3 to OpenSSL 4 in Fedora: true story
The Case for Binding and Embedding – Many Modules One Validation
The Family Reunion: OpenSSL, BoringSSL, AWS-LC, and LibreSSL on Why They Forked and What Happens Now
Legal and Commercial Pitfalls of Poor Open Source and IP Management
DTLS 1.3 in the Linux Kernel via wolfSSL Kernel Module
— Lunch —
AI in Open-Source Cryptography: Maintainers Compare Notes
The State of the OpenSSL Community
Composites Aren’t Optional: Designing PKI for the Post-Quantum Transition and Beyond
Performance: The little sibling of cryptography
Student Bug Bounties for OpenSSL-Based Products
The Cost of Stunt Cryptography
AI assisted PQC integration in Bouncy Castle
FIPS 140-3 Meets PQC - The Compliance Gap Nobody Planned For
From Hidden Cryptography to Enterprise Risk: Securing Ecosystems for Cryptographic Compliance and Post-Quantum Readiness
— Afternoon Tea —
Beyond copyright: IP strategy in the age of generative AI
The EU CRA vs. Community: Why You’re Safe, and How Stewards Help
Hardware-enforced cryptographic contexts that RISC-V software can use but never read.
Managing millions of sboms with trustify
TLS 1.3, session resumption, 0-RTT early data, external PSKs and all that...
EU CRA is around the corner. Are you ready?
Breaking Deepfakes with Shared Secrets
Quantum-Resilient Confidential Computing: Securing Data in Use for the AI Era
OpenSSL Foundation Advisory Committee
Re: [URGENT] Eight Critical 0-Day Vulnerabilities in OpenSSL
From 1.1.1 to 3.5: Modernizing OpenSSL for Enterprise Networking, FIPS 140-3, and Crypto Agility
OpenSSL QUIC adventure
Closing Performance
Monday, before the arc strikes.
A whole day of hands-on workshops the day before the conference proper — in three room types, with the people who built the libraries you ship. Limited seats, paid add-on.
- In the round Horseshoe · code-along
- The walking lecture Grid · the long view
- The hardware bench Devices forward · HSMs & tokens