LBC July 2026 Recurring Meeting
Agenda:
1 - FP CVE's in non-LTS branches per this discussion:
https://openssl-communities.org/d/FgEaRN9M/review-openssl-3-1-end-of-support
2 - Review AI's from previous meeting.
3 - Discuss Request for Guidance (??) form/process
4 - Discussion/Overview of new AI policy:
https://openssl-library.org/post/2026-06-18-ai-policy/
5 - OpenSSL conference (talks/attendance, etc)
https://openssl-conference.org/
6 - Upcoming events
See you there!
Thanks, — jj
🎥 Join the Webex meeting → Join meeting Meeting number (access code): 2663 759 2176 Password: PPw3v5T23pq(77938582 when dialing from a phone)
☎️ Join by phone +1-408-525-6800 — call-in toll number (US/Canada) One-tap mobile (attendees): +1-408-525-6800,,26637592176#77938582# ; Global call-in numbers
📹 Join from a video system or application Dial [email protected] — or dial 173.243.2.68 and enter the meeting number
🛠️ Hosts: log in here to view host information ❓ Need help? help.webex.com
🗓️ Add to calendar: Google · Apple · Office 365 · Outlook · Yahoo · ICS
Jeff Johnson ·Tue 14 Jul 2026 5:16PM
Here are the minutes from the July 2026 LBC Monthly Meeting. If you have any questions or additional thoughts, please feel free to post here!
OpenSSL LBC Monthly Meeting
Host: Jeff Johnson
Tuesday, July 14, 2026
10:26 AM | (UTC-04:00) Eastern Time (US & Canada) | 52 mins
If you want others to view all of the meeting content, and you haven't set the preference option to automatically share meeting content, click View meeting content below to view the meeting content page and then share it with others.
If you want to share only the recording with others, share the recording link and password below.
Recording
Topic
Password
OpenSSL LBC Monthly Meeting-20260714 1520-1
cXJgcmT4
Chapters AI-generated
00:00:00 CVE Discussion and FIPS Compliance
00:05:02 Validation and Update Streams
00:12:08 Formalizing Feature Requests
00:19:26 Community Engagement Strategies
00:30:47 AI and Compliance Challenges
00:33:36 AI Integration Challenges
00:37:01 AI Vulnerabilities and Triage
Meeting summary AI-generated
The meeting focused on improving OpenSSL's processes and security compliance while discussing the implications of AI on vulnerability management and contributor guidelines.
The meeting aims to establish regular schedules and improve attendance with better agendas.
Participants discuss the impact of CVEs, particularly in non-LTS branches of OpenSSL.
Ongoing discussions focus on ensuring valid FIPS provider updates for security compliance.
Participants express the need for formalized requests to OpenSSL regarding features and guidance.
OpenSSL's new AI policy requires contributors to declare AI usage in commit messages.
The upcoming OpenSSL conference is highlighted, encouraging paper submissions and attendance.
Concerns arise about increased volume and depth of security reports due to AI tools.
Participants explore using AI for initial triage in processing security issues more efficiently.
AI increasingly aids in identifying and triaging vulnerabilities in source code.
Concerns arise about the potential misuse of AI tools by individuals not reporting discovered issues.
Action items AI-generated
Push for a statement from OpenSSL regarding the lifecycle and update stream for validated FIPS providers.
Create a formalized document template for submitting requests for guidance or feature requests to OpenSSL.
Share the modified request template with the group for feedback before posting it publicly.
Participant joining from RTP6P-2-HR266 device (Jeff Johnson) will put together the RFG and create a template for it, seeking comments from others.
Participant joining from RTP6P-2-HR266 device (Jeff Johnson) will work on getting input regarding the update flow for CVEs and non-LTS FPs.