LBC Meeting Minutes Sept 8, 2026
Here are the meeting minutes for the September 2026 LBC meeting. If there are questions or comments, please post them here or reach out to me directly. Thanks!
-jj
Your Webex meeting content is available. |
OpenSSL LBC Monthly Meeting |
Host: Jeff Johnson |
Tuesday, September 8, 2026 |
10:29 AM | (UTC-04:00) Eastern Time (US & Canada) | 38 mins |
Recording | ||
Topic |
Password |
|
rYfBFZ56 |
||
|
Meeting summary AI-generated OverviewKey participants in this meeting included Jeff Johnson, Anton Arapov, Chris Ward, Kevin Micciche, Lutz Jänicke, Dan Wing, and Barry Fussell. The primary focus was on improving community engagement through a new lightweight request for guidance form designed to facilitate open discussions and feedback on OpenSSL issues, as explained by Jeff Johnson and supported by Anton Arapov and Kevin Micciche. The team addressed the recent end of life of OpenSSL 3.0, with Anton Arapov emphasizing the need to understand client usage to guide ongoing commercial support. Jeff Johnson and Barry Fussell noted limited adoption of version 3.0, with many users moving to newer releases. A significant portion of the discussion centered on the challenges posed by the European Cyber Resilience Act (CRA), particularly for industrial automation products with long lifecycles. Lutz Jänicke detailed the difficulties in meeting CRA requirements within tight timelines and the complexities of maintaining compliance over decades. Anton Arapov highlighted the distinction between open source stewardship and commercial vendor responsibilities under CRA. The upcoming OpenSSL conference was reviewed, with confirmations of speaker notifications and attendee plans. Chris Ward confirmed his attendance and speaking role, while Kevin Micciche awaited budget approval. The conference is viewed as a vital event for community interaction. Finally, the group discussed involvement in standards and regulatory committees related to CRA. Lutz Jänicke's leadership in German OT standardization and Anton Arapov's notes on advisory participation were highlighted, with plans for further collaboration to navigate regulatory challenges effectively. The team discussed the introduction of a new lightweight form to streamline requests for guidance or feature requests related to OpenSSL. This form aims to facilitate open discussions and feedback within the community and corporate members, improving communication and tracking of issues. The form is inspired by a more extensive version used by CMUS and is intended to be made available as a template on the Lumino site for easy access.
The group addressed the recent end of life (EOL) status of OpenSSL 3.0 as of September 7 and the implications for commercial support. Anton Arapov emphasized the importance of understanding client usage to determine ongoing support needs. Jeff Johnson and Barry Fussell noted that adoption of OpenSSL 3.0 was limited, with many moving to newer versions like 3.5. The team agreed to gather community feedback on continued use of 3.0 to inform support decisions.
Participants discussed the challenges posed by the European Cyber Resilience Act (CRA), especially for industrial automation products with long lifecycles. Lutz Jänicke highlighted the difficulty in meeting CRA requirements within tight timelines and the complexity of maintaining compliance for products expected to last 20-30 years. The conversation covered the need for risk-based approaches and the impact on both hardware and software vendors. Anton Arapov acknowledged the regulatory burden and the distinction between open source stewardship and commercial vendor responsibilities.
The upcoming OpenSSL conference scheduled for October 13-15 was reviewed, with confirmations of speaker notifications and attendee plans. Kevin Micciche is awaiting budget approval to attend, while others like Chris Ward confirmed participation and a speaking role. The conference is seen as an important opportunity for community engagement and knowledge sharing. Chris Ward offered support to help others attend if needed.
The group touched on involvement in standards and regulatory committees related to CRA and cybersecurity. Lutz Jänicke chairs the German national committee for OT standardization and spends significant time on CRA-related work. Anton Arapov acknowledged limited direct involvement but noted some members, including representatives from Red Hat and the OpenSSL Corporation, participate in advisory roles. The need for better communication and collaboration on these topics was recognized.
Action items AI-generated
|