OpenSSL Communities

What Should OpenSSL Improve for Individual Contributors?

Aditya KorangaAditya Koranga Wed 8 Jul 2026 4:10PMPublicSeen by 76

Hello everyone, hope you are doing well!

During the last OpenSSL Corporation Face-to-Face meeting, I had the opportunity to present feedback collected from the Individuals Community. The presentation was based on Individuals community discussions, survey responses, conversations with individuals at various conferences, and general feedback received over the past several months.

The presentation highlighted what the community appreciates, as well as several recurring pain points(slide 04 and 05). I'd love to hear from an even wider audience.

Do these pain points resonate with your experience?

Randall Becker

Randall BeckerWed 8 Jul 2026 4:17PM

No, my experience is different.(pls tell ur pain points)

Build/test cycle times on x86 NonStop

Richard Levitte (individual)

Richard Levitte (individual)Mon 20 Jul 2026 12:18PM

@randallbecker
Heh, OpenVMS was a similar pain point. But it's admittedly quite slow, even on x86_64.

Jon Ericson

Jon EricsonWed 8 Jul 2026 4:17PM

Yes, I relate to these pain points.

Putting on my individual contributor hat:

  • The documentation a huge pain point.
  • I'm concerned about the criticism OpenSSL has received recently.
  • The backlog and review process are daunting if you have anything complicated to submit. I'd love to get more reviewers and more automated tests to help.
Michael Baentsch

Michael BaentschWed 15 Jul 2026 8:23AM

@Jon Ericson Completely agree with/support your items 1&3. Just with item 2 I wonder whether you could be more concrete which criticism you mean/are mostly concerned about (to make this actionable)?

Jon Ericson

Jon EricsonSun 19 Jul 2026 2:08AM

@baentsch The space for a vote comment was too short to include details, but I'm specifically thinking of these articles. I am working on some blog post responses that highlight the concrete things the project has actually done in the last year or so.

dan pittman

dan pittmanWed 8 Jul 2026 4:17PM

No, my experience is different.(pls tell ur pain points)

I agree with others who have said that these are valid issues, but that they are either well known, or expected with a mature industrial codebase. At my place of work, we've been focussed on PQC algorithms, so if anything, I'd be curious if there is an OpenSSL organization-wide roadmap or plan published regarding post-quantum cryptography. Please excuse me, though, if it there has been; I've not gone looking for it very hard.

Aditya Koranga

Aditya KorangaSat 18 Jul 2026 4:28PM

@dan pittman I agree these are well-known issues, but we still receive this feedback today. That suggests they've either not been prioritized, haven't received enough attention, or a suitable solution hasn't been found yet.

Yes, people have asked us whether openssl project has any PQC roadmap or not and they would be interested to see a roadmap like that(this point is also mentioned in the slides btw)

Paul Dale

Paul DaleWed 8 Jul 2026 4:17PM

No, my experience is different.(pls tell ur pain points)

They've not been a problem for me.

S E

S EWed 8 Jul 2026 4:17PM

Yes, I relate to these pain points.

I second @Nikolas Gauder. The codebase is overwhelming for a beginner.

Michael Baentsch

Michael BaentschWed 15 Jul 2026 8:27AM

@S E Hmm -- I'd argue that all but the most trivial of code bases are overwhelming for beginners (unless they're geniuses or AIs :-). What make OpenSSL dauting is its long history and various architecture decisions that are not documented anywhere (echoing @Jon Ericson s comment above): Maybe time for an effort to get ADRs documented?

Item removed

Simon Cornish

Simon CornishThu 16 Jul 2026 9:44PM

I missed the poll deadline but I'd say:

  • The PR backlog is a problem

  • The codebase might be difficult for "beginners" but do we want PRs from contributors (or AIs) that don't understand it? "Solving" this by dumbing down the code seems like a distraction.
    (that being said, the previous comment about macro overuse is valid)

Aditya Koranga

Aditya KorangaSat 18 Jul 2026 4:36PM

@Simon Cornish Regarding the second point, every contributor starts somewhere so It would be great to have more beginners join, learn about the project, and contribute. If the project has a steep learning curve, good documentation plays a crucial role, and as mentioned above, documentation is one of the biggest pain points.

Richard Levitte (individual)

Richard Levitte (individual)Mon 20 Jul 2026 12:33PM

Middle of July voting... heh

I can relate to the codebase difficulty pain point. The codebase is humongous, and includes a pile of churn that's pretty daunting (just see everything that make update does). We also have a tendency to pile stuff into existing libraries and files where they don't really belong, which makes it hard to find what you want to work with.