Our agenda,
your
spark.
The programme — 100 sessions across three days and four rooms
The programme, day by day.
§ A note on reading How to read the Agenda
Main Stage · Room 1
The main stage — welcomes, keynotes, panels, and invited sponsor talks, plus parallel sessions through the afternoons.
Hall II · Room 2
Parallel sessions, Tuesday afternoon through Thursday.
Hall III · Room 3
Parallel sessions, Tuesday afternoon through Thursday.
The Laboratory · Room 4
The smallest room. Parallel sessions, Tuesday afternoon through Thursday.
Day01
Tuesday · 13 October
The
Arc · foundations & community
Tue13 Oct
Opening Conference
Welcome to the OpenSSL Conference 2026
Cisco — invited keynote
Topic to be announced.
Leadership 3-way: Matt, Eric, Tim (moderated)
Bouncy Castle — invited talk
Topic to be announced.
Rebranding OpenSSL FIPS 140-3 Validations from a Laboratory Perspective
— Lunch —
Jena — invited talk
Topic to be announced.
Securosys — invited talk
Topic to be announced.
Beyond the Checkbox: How Product Certifications Drive Ongoing Security Strategy and Market Access
— Afternoon Tea —
Hybrid FIPS module using OpenSSL code: the Kryotpic project
Why have the PQC standards taken so long? Bottlenecks, bickering, and building momentum
The EU CRA vs. Community: Why You’re Safe, and How Stewards Help
Open Quantum Safe: Post-Quantum software research in the era of the first PQC standards
OpenSSL's TLS Implementation: Inside the State Machine and Record Layer
Merkle Tree Certificate Proofs - How Merkle Trees and Merkle Subtrees are used in MTC's
During a Breach: How Encryption is Evaluated by Regulators, Insurers, and Counsel
Architecting the Agility Layer: Forging a Common Crypto API for the Post-Quantum Era
Privacy Is Not the Enemy! What Law Enforcement Misunderstands and What Cryptographers Can Do About It
Who Pays for Open Source? A First-Party Answer from the OpenSSL Corporation
Instrumenting OpenSSL with Crypto-Auditing Probes for Post-Quantum Readiness
Verifiable Builds in Untrusted Clouds
KeyPair — invited talk
Topic to be announced.
Lessons learned on proper cryptographic hygiene in Rust
The Perfect Storm: Why Tech Is the Next Target for Destructive Regulation
1 Module 3 Transitions
— End of Day —
— Boat transport —
— Boat event · dinner & cruise (starts 19:45) —
Day02
Wednesday · 14 October
The
Filament · deep-dive
Wed14 Oct
OpenSSL Corporation
Nobody Told Maintainers They Were Saving The World. Now Is The Time.
A library-agnostic hybrid classic/PQ OpenSSL provider — built with AI
Shipping openssl downstream and it's challenge
From Zero to Hero: A Student's Journey Contributing to Production Cryptography
Securing the Next Generation: An OpenSSL Youth Outreach Strategy
— Morning Tea —
TLS keyshare caching for faster handshakes
From Copilot to Commit: Handling AI-Generated Code in Open Source Crypto Libraries
How small can you (reasonably) get an ML-DSA and ML-KEM implementation?
Finding Timing Side Channels When Internal Clocks Are Hidden
Cryptsoft — invited talk
Topic to be announced.
Self-Encrypting Disks in Linux - Fast, Expensive, and Mostly Harmless
Navigating the Post-Quantum Transition: Integrating FAEST and Classic McEliece into libOQS
Where Post-Quantum Migration Hurts a Wi-Fi IoT Endpoint
Bill Buchanan — invited talk
Topic to be announced.
HSM-Backed OpenPGP Signing for OpenSSL Releases: Architecture and Operations
Is the current cryptography testing and validation pipeline process capable of handling the impending Tsunami?
Engineering Reality of CRA Compliance for Linux-based IoT Solutions
— Lunch —
Artificial Insecurity: how AI threatens digital security and what we can do about it
The State of the OpenSSL Community
Advancing Clarity Through Collaboration
The Security Response Process of the OpenSSL Library
CRA and its Problematic Impacts on F/OSS
Daniel J. Bernstein — invited talk
Topic to be announced.
Community panel: Distributions
Optimizing ML-KEM and ML-DSA with Vector Instructions and Mathematical Techniques
Open Source: The Road to EU Sovereignty
— Afternoon Tea —
PLANTS and Merkle Tree Certificates
Building a Fail-Closed Cryptographic Code LLM Support Assistant
DTLSv1.3 in OpenSSL
Building Cryptography on Locally Verified Entropy
Why People Trust the Internet but Ignore What Protects It
Testing PQC Timing Side-Channels
Investigation cryptography deployments in security-certified products with sec-certs
Shim in 2026: A Certificate Rotation and a Decade-Overdue OpenSSL Migration
OpenSSL Corporation Advisory Committees — BAC & TAC
Jipher FIPS cryptography provider - How we wrapped OpenSSL and the FIPS module using Java’s FFM API
Beyond Algorithms: Exploiting Platform Cryptography with OpenSSL Providers
The PQC Migration Copilot: Agentic AI for Crypto Discovery and Automated OpenSSL 3.5 Cutover
What shall we do with two PKCS#11 providers?
New Insights into the Formal Verification of AWS-LC, a Fork of OpenSSL
Lessons Learned from Constructing Estonia’s PQC Migration Roadmap
— End of Day —
— Transport to Folklore Garden —
— Folklore performance & dinner —
Day03
Thursday · 15 October
The
Effect · close
Thu15 Oct
OpenSSL Foundation — Delivering the Mission
— Morning Tea —
Tanja Lange — invited talk
Topic to be announced.
Going beyond constant-time security in open-source cryptographic libraries
IT Security Product Certification in the Era of Automated Evidence Generation and AI-Assisted Evaluation
From OpenSSL 3 to OpenSSL 4 in Fedora: true story
The Case for Binding and Embedding – Many Modules One Validation
The Family Reunion: OpenSSL, BoringSSL, AWS-LC, and LibreSSL on Why They Forked and What Happens Now
Tereza Formanová — invited talk
Topic to be announced.
DTLS 1.3... In the Kernel! Really?
— Lunch —
Agentic AI in security operations, liability when the agent acts
The Good, the Bad and the Ugly: Tales from the last three years PQC transition at Red Hat
Practical Viability of NIST Post-Quantum Algorithms on Constrained ARM Devices: A Timing and Energy Study
The JOSTLE project from idea to first release.
Performance: The little sibling of cryptography
Composites Aren’t Optional: Designing PKI for the Post-Quantum Transition and Beyond
FIPS 140-3 Meets PQC - The Compliance Gap Nobody Planned For
AI assisted PQC integration in Bouncy Castle
The Cost of Stunt Cryptography
Student Bug Bounties for OpenSSL-Based Products
Decoupling the OpenSSL FIPS Provider for Agility and Maintainability
From Hidden Cryptography to Enterprise Risk: Securing Ecosystems for Cryptographic Compliance and Post-Quantum Readiness
— Afternoon Tea —
Beyond copyright: IP strategy in the age of generative AI
TLS 1.3, session resumption, 0-RTT early data, external PSKs and all that...
Hardware-enforced cryptographic contexts that RISC-V software can use but never read.
Managing millions of sboms with trustify
What's behind the MASQUE
EU CRA is around the corner. Are you ready?
Breaking Deepfakes with Shared Secrets
Quantum-Resilient Confidential Computing: Securing Data in Use for the AI Era
OpenSSL Foundation Advisory Committee
Re: [URGENT] Eight Critical 0-Day Vulnerabilities in OpenSSL
From 1.1.1 to 3.5: Modernizing OpenSSL for Enterprise Networking, FIPS 140-3, and Crypto Agility
QUIC adventures
— End of Day —
Monday, before the arc strikes.
A whole day of hands-on workshops the day before the conference proper — in three room types, with the people who built the libraries you ship. Limited seats, paid add-on.
- In the round Horseshoe · code-along
- The walking lecture Grid · the long view
- The hardware bench Devices forward · HSMs & tokens