§ 03 — Agenda

The programme, day by day.

§ A note on reading How to read the Agenda

Main Stage · Room 1

§ 01 · the plenary hall

The main stage — welcomes, keynotes, panels, and invited sponsor talks, plus parallel sessions through the afternoons.

Hall II · Room 2

§ 02 · parallel

Parallel sessions, Tuesday afternoon through Thursday.

Hall III · Room 3

§ 03 · parallel

Parallel sessions, Tuesday afternoon through Thursday.

The Laboratory · Room 4

§ 04 · parallel

The smallest room. Parallel sessions, Tuesday afternoon through Thursday.

Day01
Tuesday · 13 October
The Arc · foundations & community
Tue13 Oct
09:00
Plenary · Magda Zdunkiewicz

Opening Conference

Room 1 · Community5 min
09:05
Plenary · Tim Hudson, Anton Arapov

Welcome to the OpenSSL Conference 2026

Room 1 · Community15 min
09:20
Keynote · Jonathan Felten — Cisco · Platinum sponsor

Cisco — invited keynote

Topic to be announced.

Room 1 · Business30 min
09:50
Panel · Eric A. Young, Tim Hudson, Matt Caswell, Magda Zdunkiewicz

Leadership 3-way: Matt, Eric, Tim (moderated)

Room 1 · Community60 min
10:50
Sponsor · David Hook — Bouncy Castle · Silver, in-kind

Bouncy Castle — invited talk

Topic to be announced.

Room 1 · Technical30 min
11:20
Jonathan Park

Rebranding OpenSSL FIPS 140-3 Validations from a Laboratory Perspective

Room 1 · Security30 min
12:00

— Lunch —

Interval70 min
13:20
Sponsor · Jena — Silver

Jena — invited talk

Topic to be announced.

Room 1 · Business30 min
13:50
Sponsor · Marcel Dasen — Securosys · Silver

Securosys — invited talk

Topic to be announced.

Room 1 · Security30 min
14:20
Lisa Rogers

Beyond the Checkbox: How Product Certifications Drive Ongoing Security Strategy and Market Access

Room 1 · Security30 min
14:50

— Afternoon Tea —

Interval30 min
15:20
Simo Sorce

Hybrid FIPS module using OpenSSL code: the Kryotpic project

Room 1 · Technical40 min
15:20
Mike Ounsworth

Why have the PQC standards taken so long? Bottlenecks, bickering, and building momentum

Room 2 · Community40 min
15:20
Jaroslav Řezník

The EU CRA vs. Community: Why You’re Safe, and How Stewards Help

Room 3 · Security40 min
15:20
Rodrigo Martín Sánchez-Ledesma

Open Quantum Safe: Post-Quantum software research in the era of the first PQC standards

Room 4 · Technical40 min
16:05
Matt Caswell

OpenSSL's TLS Implementation: Inside the State Machine and Record Layer

Room 1 · Technical50 min
16:05
Bob Beck, Andrew Dinh

Merkle Tree Certificate Proofs - How Merkle Trees and Merkle Subtrees are used in MTC's

Room 2 · Technical50 min
16:05
Amanda McAllister Novak

During a Breach: How Encryption is Evaluated by Regulators, Insurers, and Counsel

Room 3 · Security40 min
16:05
Dr. Vladimir Soukharev, Murugiah Souppaya, David Hook, Mike Kushner

Architecting the Agility Layer: Forging a Common Crypto API for the Post-Quantum Era

Room 4 · Security50 min
17:00
Dr. Katrina Khanta, D.Sc.

Privacy Is Not the Enemy! What Law Enforcement Misunderstands and What Cryptographers Can Do About It

Room 1 · Security30 min
17:00
Kajal Sapkota

Who Pays for Open Source? A First-Party Answer from the OpenSSL Corporation

Room 2 · Community30 min
17:00
Daiki Ueno

Instrumenting OpenSSL with Crypto-Auditing Probes for Post-Quantum Readiness

Room 3 · Security30 min
17:00
Rene Malmgren

Verifiable Builds in Untrusted Clouds

Room 4 · Business30 min
17:30
Sponsor · Joshua Hill — KeyPair

KeyPair — invited talk

Topic to be announced.

Room 1 · Technical30 min
17:30
Mike Ounsworth

Lessons learned on proper cryptographic hygiene in Rust

Room 2 · Technical30 min
17:30
Daniella Y Taveau

The Perfect Storm: Why Tech Is the Next Target for Destructive Regulation

Room 3 · Security30 min
17:30
Jake Maynard

1 Module 3 Transitions

Room 4 · Technical30 min
18:00

— End of Day —

All rooms5 min
19:00

— Boat transport —

Vltava30 min
19:30

— Boat event · dinner & cruise (starts 19:45) —

Vltava3 h
Day02
Wednesday · 14 October
The Filament · deep-dive
Wed14 Oct
09:00
Keynote · Tim Hudson

OpenSSL Corporation

Room 1 · Community30 min
09:30
Roman Zhukov

Nobody Told Maintainers They Were Saving The World. Now Is The Time.

Room 1 · Community30 min
09:30
Michael Baentsch

A library-agnostic hybrid classic/PQ OpenSSL provider — built with AI

Room 2 · Technical30 min
09:30
Angel Yankov, Lucas Mülling, Pedro Monreal

Shipping openssl downstream and it's challenge

Room 3 · Community30 min
09:30
Stefan Eberle

From Zero to Hero: A Student's Journey Contributing to Production Cryptography

Room 4 · Community15 min
09:45
Carla Jedani

Securing the Next Generation: An OpenSSL Youth Outreach Strategy

Room 4 · Community15 min
10:00

— Morning Tea —

Interval30 min
10:30
Panos Kampanakis

TLS keyshare caching for faster handshakes

Room 1 · Community30 min
10:30
Dr. Lina Böcker

From Copilot to Commit: Handling AI-Generated Code in Open Source Crypto Libraries

Room 2 · Security30 min
10:30
Mike Ounsworth

How small can you (reasonably) get an ML-DSA and ML-KEM implementation?

Room 3 · Technical30 min
10:30
Veronika Hanulíková

Finding Timing Side Channels When Internal Clocks Are Hidden

Room 4 · Technical30 min
11:00
Sponsor · Cryptsoft — Gold

Cryptsoft — invited talk

Topic to be announced.

Room 1 · Business30 min
11:00
Milan Brož

Self-Encrypting Disks in Linux - Fast, Expensive, and Mostly Harmless

Room 2 · Community30 min
11:00
Norman Ashley

Navigating the Post-Quantum Transition: Integrating FAEST and Classic McEliece into libOQS

Room 3 · Community30 min
11:00
Martin Perešíni

Where Post-Quantum Migration Hurts a Wi-Fi IoT Endpoint

Room 4 · Technical30 min
11:30
Invited · Bill Buchanan

Bill Buchanan — invited talk

Topic to be announced.

Room 1 · Security30 min
11:30
Dmitry Misharov

HSM-Backed OpenPGP Signing for OpenSSL Releases: Architecture and Operations

Room 2 · Technical30 min
11:30
Shawn Geddis, Jasmine Geddis

Is the current cryptography testing and validation pipeline process capable of handling the impending Tsunami?

Room 3 · Security30 min
11:30
Pavel Polach, Maxim Kostin

Engineering Reality of CRA Compliance for Linux-based IoT Solutions

Room 4 · Security30 min
12:00

— Lunch —

Interval70 min
13:20
Marcel Kolaja

Artificial Insecurity: how AI threatens digital security and what we can do about it

Room 1 · Security40 min
13:20
Jon Ericson, Chris Ward

The State of the OpenSSL Community

Room 2 · Community30 min
13:20
Tricia Wolff

Advancing Clarity Through Collaboration

Room 3 · Community40 min
13:20
Tomáš Mráz

The Security Response Process of the OpenSSL Library

Room 4 · Community40 min
13:50
Pavel Loutocký

CRA and its Problematic Impacts on F/OSS

Room 2 · Security30 min
14:00
Daniel J. Bernstein · remote

Daniel J. Bernstein — invited talk

Topic to be announced.

Room 1 · Technical40 min
14:00
Lucas Mülling

Community panel: Distributions

Room 3 · Community50 min
14:00
Timo Keller

Optimizing ML-KEM and ML-DSA with Vector Instructions and Mathematical Techniques

Room 4 · Technical50 min
14:20
Alix Guillard

Open Source: The Road to EU Sovereignty

Room 2 · Community30 min
15:00

— Afternoon Tea —

Interval30 min
15:30
Bob Beck, Andrew Dinh

PLANTS and Merkle Tree Certificates

Room 1 · Technical40 min
15:30
Francis Mendoza

Building a Fail-Closed Cryptographic Code LLM Support Assistant

Room 2 · Technical40 min
15:30
Ryan Hooper

DTLSv1.3 in OpenSSL

Room 3 · Technical40 min
15:30
Jordi Prieto Gallego

Building Cryptography on Locally Verified Entropy

Room 4 · Security40 min
16:10
Brandan Payne

Why People Trust the Internet but Ignore What Protects It

Room 1 · Business40 min
16:10
Alicja Kario

Testing PQC Timing Side-Channels

Room 2 · Technical40 min
16:10
Vashek Matyas, Yasir Yakup Demircan

Investigation cryptography deployments in security-certified products with sec-certs

Room 3 · Security40 min
16:10
Brian bex Exelbierd

Shim in 2026: A Certificate Rotation and a Decade-Overdue OpenSSL Migration

Room 4 · Community40 min
16:50
Panel · Billy Brumley, Paul Yang, Jaroslav Řezník, Randall Becker, Jeff Johnson, Nikolas Gauder, Simo Sorce, Dmitry Belyavskiy, Aditya Koranga, Kevin Micciche, Chris Ward

OpenSSL Corporation Advisory Committees — BAC & TAC

Room 1 · Community60 min
16:50
Jon Spillett

Jipher FIPS cryptography provider - How we wrapped OpenSSL and the FIPS module using Java’s FFM API

Room 2 · Technical40 min
16:50
Holger Dengler, Finn Callies

Beyond Algorithms: Exploiting Platform Cryptography with OpenSSL Providers

Room 3 · Technical40 min
16:50
Ranjan Kathuria

The PQC Migration Copilot: Agentic AI for Crypto Discovery and Automated OpenSSL 3.5 Cutover

Room 4 · Security40 min
17:30
Jakub Jelen

What shall we do with two PKCS#11 providers?

Room 2 · Community30 min
17:30
Nicky Mouha

New Insights into the Formal Verification of AWS-LC, a Fork of OpenSSL

Room 3 · Technical30 min
17:30
Jelizaveta Vakarjuk

Lessons Learned from Constructing Estonia’s PQC Migration Roadmap

Room 4 · Community30 min
18:00

— End of Day —

All rooms5 min
19:00

— Transport to Folklore Garden —

Folklore Garden30 min
19:30

— Folklore performance & dinner —

Folklore Garden5 h
Day03
Thursday · 15 October
The Effect · close
Thu15 Oct
09:00
Keynote · Matt Caswell

OpenSSL Foundation — Delivering the Mission

Room 1 · Community35 min
10:00

— Morning Tea —

Interval30 min
10:30
Tanja Lange · remote

Tanja Lange — invited talk

Topic to be announced.

Room 1 · Technical40 min
10:30
Jan Janasek, Lukasz Chmielewski

Going beyond constant-time security in open-source cryptographic libraries

Room 2 · Technical40 min
10:30
Jussipekka Leiwo

IT Security Product Certification in the Era of Automated Evidence Generation and AI-Assisted Evaluation

Room 3 · Security40 min
10:30
Dmitry Belyavskiy

From OpenSSL 3 to OpenSSL 4 in Fedora: true story

Room 4 · Business40 min
11:15
Tricia Wolff

The Case for Binding and Embedding – Many Modules One Validation

Room 1 · Security40 min
11:15
Kajal Sapkota

The Family Reunion: OpenSSL, BoringSSL, AWS-LC, and LibreSSL on Why They Forked and What Happens Now

Room 2 · Community40 min
11:15
Invited · Tereza Formanová

Tereza Formanová — invited talk

Topic to be announced.

Room 3 · Security40 min
11:15
Anthony Hu

DTLS 1.3... In the Kernel! Really?

Room 4 · Technical40 min
12:00

— Lunch —

Interval70 min
13:20
Hayden Delaney

Agentic AI in security operations, liability when the agent acts

Room 1 · Security40 min
13:20
Clemens Lang

The Good, the Bad and the Ugly: Tales from the last three years PQC transition at Red Hat

Room 2 · Business40 min
13:20
Olivier Gillot

Practical Viability of NIST Post-Quantum Algorithms on Constrained ARM Devices: A Timing and Energy Study

Room 3 · Technical40 min
13:20
Megan Woods

The JOSTLE project from idea to first release.

Room 4 · Technical40 min
14:00
Neil Horman, Bob Beck

Performance: The little sibling of cryptography

Room 1 · Technical30 min
14:00
John Gray

Composites Aren’t Optional: Designing PKI for the Post-Quantum Transition and Beyond

Room 2 · Technical30 min
14:00
Chris Brych

FIPS 140-3 Meets PQC - The Compliance Gap Nobody Planned For

Room 3 · Security30 min
14:00
Roy Basmacier

AI assisted PQC integration in Bouncy Castle

Room 4 · Technical30 min
14:30
Peter Gutmann

The Cost of Stunt Cryptography

Room 1 · Technical30 min
14:30
Kamil Malinka

Student Bug Bounties for OpenSSL-Based Products

Room 2 · Community30 min
14:30
William Bellingrath

Decoupling the OpenSSL FIPS Provider for Agility and Maintainability

Room 3 · Technical30 min
14:30
Dr. Vladimir Soukharev

From Hidden Cryptography to Enterprise Risk: Securing Ecosystems for Cryptographic Compliance and Post-Quantum Readiness

Room 4 · Security30 min
15:00

— Afternoon Tea —

Interval30 min
15:30
Hayden Delaney

Beyond copyright: IP strategy in the age of generative AI

Room 1 · Security40 min
15:30
Viktor Dukhovni

TLS 1.3, session resumption, 0-RTT early data, external PSKs and all that...

Room 2 · Technical40 min
15:30
Radim Krčmář

Hardware-enforced cryptographic contexts that RISC-V software can use but never read.

Room 3 · Technical40 min
15:30
James Fuller

Managing millions of sboms with trustify

Room 4 · Security40 min
16:15
Yaroslav Rosomakho

What's behind the MASQUE

Room 1 · Technical40 min
16:15
Sridhar Balasubramanian

EU CRA is around the corner. Are you ready?

Room 2 · Security40 min
16:15
Jonathan Bateman

Breaking Deepfakes with Shared Secrets

Room 3 · Community40 min
16:15
Paul Yang

Quantum-Resilient Confidential Computing: Securing Data in Use for the AI Era

Room 4 · Technical30 min
17:00
Panel · Shubham Kumar, Clemens Lang, Randall Becker, Yi Ouyang, Nicola Tuveri, Dmitry Belyavskiy, Igor Ustinov, Barry Fussell, Aditya Koranga, Jon Ericson

OpenSSL Foundation Advisory Committee

Room 1 · Community50 min
17:00
Norbert Pocs

Re: [URGENT] Eight Critical 0-Day Vulnerabilities in OpenSSL

Room 2 · Security30 min
17:00
William Bellingrath

From 1.1.1 to 3.5: Modernizing OpenSSL for Enterprise Networking, FIPS 140-3, and Crypto Agility

Room 3 · Technical30 min
17:00
Alexandr Nedvedicky

QUIC adventures

Room 4 · Technical30 min
17:50

— End of Day —

All rooms5 min
§ 03 — 100 sessions scheduled · four rooms · invited topics announced as they land

Monday, before the arc strikes.

A whole day of hands-on workshops the day before the conference proper — in three room types, with the people who built the libraries you ship. Limited seats, paid add-on.

  • In the round Horseshoe · code-along
  • The walking lecture Grid · the long view
  • The hardware bench Devices forward · HSMs & tokens
Confirmed tutors Bouncy Castle engineering · Prof. Bill Buchanan · Daniel Heinrich · more locking in through spring
See tutorials ~80 seats across the day · paid add-on