
October 7-9, 2025


October 7-9, 2025

REGISTER
NOW
NOW
BECOME A
SPONSOR
SPONSOR
SPEAKERS
OUR MISSION
“We believe everyone should have access to security and privacy tools, whoever they are,
wherever they are or whatever their personal beliefs are, as a fundamental human right.”
OUR MISSION
“We believe everyone should have access to security and privacy tools, whoever they are,
wherever they are or whatever their personal beliefs are, as a fundamental human right.”
Speakers 2025
Building a Cloud-Native Private CA with OpenSSL and CloudHSM: A Secure, Self-Serve PKI Architecture
This talk presents a scalable framework for deploying an enterprise Private Certificate Authority (CA) using OpenSSL and cloud-based HSMs. We explore a solution that centralizes certificate lifecycle management including issuance, monitoring, and automated expiry alerts while enforcing security through offline key generation with OpenSSL (RSA-2048) and hardware-grade protection via AWS CloudHSM. The design eliminates direct key exposure by leveraging FIPS 140-2 Level 3-validated HSMs and enables self-service workflows with minimal manual intervention. Attendees will learn practical strategies for balancing security, automation, and usability in PKI deployments.
Date: 07.10.2025
Time: 13:30
Location: Belvedere I
Track: Security, Compliance & the Law