JM
Jake Maynard
— On the schedule —
One Module Three Transitions
Cryptographic implementers in the United States are navigating several overlapping transitions: the move from FIPS 140-2 to FIPS 140-3, the migration from CNSA 1.0 to CNSA 2.0, and the upcoming NIST 2030 algorithm transitions. Other jurisdictions are also managing their cryptographic transition policies, post-quantum timelines, certification requirements, and legacy deployments. The policy details differ, but the implementation challenge is similar: how can applications adapt to changing cryptographic requirements without duplicating compliance logic throughout the product? OpenSSL provides many of the building blocks for policy-driven cryptography, including configuration, providers, property queries, algorithm fetching, security levels, and FIPS-specific controls. This talk examines how those mechanisms have been used historically and explores how they can be taken further into a cryptographic policy control plane—allowing different regulatory, governmental, or organizational policies to be expressed above the application and enforced through a common OpenSSL-based architecture.
— Compositor's note —
Jake Maynard is the head of engineering at SafeLogic, where his team leads cryptographic research and development for the organization. He is currently pursuing a PhD in Cryptology from Florida Atlantic University. His team built the first NIST SP-800 90B ESV validated CPU jitter based OpenSSL entropy provider for the OpenSSL 3.x architecture. Jake has previously presented at Citrix Synergy, OpenSSL Conference, and the International Cryptographic Module Conference (ICMC) and is a Subject Matter Expert in FIPS module implementation.