Meeting Minutes: Board and TAC Monthly (2026-07-20)
Below are the minutes from the recent TAC and Board of Directors meeting. Everyone is encouraged to review the minutes and actively participate in the discussion. This is an opportunity to talk directly with TAC members by replying in the thread below. Your input helps ensure the OpenSSL community remains transparent, collaborative, and responsive to your needs.
Attendees
@Anton Arapov, @Nikolas Gauder, @Simo Sorce, @Kevin Micciche
(A short, reduced vacation-season session.)
High-level topics covered
Communities housekeeping: delegates, F2F follow-ups, community-manager idea
OpenSSL Conference: call-for-papers status
HSM-based release signing
Post-quantum in SSH: hybrids, CNSA 2.0, interoperability
FrodoKEM
TPM / TCG and attribute certificates
FIPS 140-3 status and certification-driven requirements
Detailed points and discussion
1) Communities housekeeping
The delegate cleanup announced earlier is being completed, so each community's list reflects only active delegates.
The action items from the May face-to-face will be revived with named owners pushing each one forward — a separate post on this will follow.
Community manager: there is no open position today, but referrals for someone who would make a great community manager for OpenSSL are welcome — a role could be created for the right person.
2) OpenSSL Conference
The call for papers closed during the week with roughly 120 submissions; a short extension is being considered. If it reopens, submissions from a broader set of organizations are encouraged.
The program committee will be engaged soon, with a defined review process this year.
3) HSM-based release signing
Release signing now runs end to end on HSMs, and the lab devices are available for tests and experimentation.
Conversations with further HSM vendors are ongoing to broaden the lab setup; pointers to vendors active in the PQC space were exchanged.
4) Post-quantum in SSH
Kevin raised the constraints faced by high-assurance government customers: X25519-based hybrids are not permitted under CNSA, leaving ML-KEM-1024 with P-384 as the single viable option in OpenSSH today, and asked about the appetite for further options, including pure PQ.
Perspective from the discussion: with the post-quantum component present, the classical component in a hybrid is effectively belt-and-braces; the ML-KEM-1024 + P-384 option exists precisely for the CNSA 2.0 profile, so it is the one to use there — while CISA, for its part, leans toward pure ML-KEM.
The IETF working groups are deliberately keeping the number of algorithm combinations small, aligned across TLS, SSH, OpenPGP, and JOSE/COSE, which keeps the testing matrix manageable — though being left with a single compliant option is uncomfortable if that option is ever found deficient.
Hybrids matter most for key establishment, where recorded traffic must stay confidential for years; for signatures, key rotation limits the damage, so pure ML-DSA options are a reasonable expectation over time.
Several vendors are meanwhile shipping their own combinations without published drafts, raising interoperability concerns.
Kevin will follow up on the OpenSSH side and report back; the conversation can also be channeled through the Communities, where OpenSSL has people active in OpenSSH.
5) FrodoKEM
Kevin asked about FrodoKEM following its addition to ISO/IEC 18033-2, with interest visible from parts of Europe and South Korea.
The practical blocker: no protocol currently defines how to use it, so implementing ahead of demand has little value; OpenSSL has no current plans.
Kevin will check whether there are active implementation efforts and circle back.
6) TPM / TCG
The TPM 2.0 specification revision published in March added post-quantum support; the software stack around it (tpm2-tss, tpm2-openssl) is catching up.
Kevin shared the tpm2-openssl project and the attribute-certificates work in openssl/openssl#25981 for awareness. Platform certificates and attestation are drawing growing interest, including from governments, and will likely deserve more attention over the coming year.
7) FIPS 140-3 and certification-driven requirements
The FIPS provider 3.5.4 submission with the post-quantum algorithms has been in the CMVP comment phase since 2 July; historically, two to three weeks separate this stage from a certificate.
Certification work across the ecosystem is surfacing additional lab expectations for the PQC algorithms — notably zeroization of intermediate values in ML-DSA, SLH-DSA, and ML-KEM. Different labs flag different things, and comparing notes openly benefits everyone.
Rather than private channels, a Communities discussion is the preferred venue for requirements of this kind; Simo will start a post.