NGINX Certificate Compression: RFC 8879 for Every Browser
by Danila Vershinin, September 15, 2026
Technical Briefing: RFC 8879 Certificate Compression in NGINX Problem Statement The TLS 1.3 certificate chain dominates the server’s first flight and competes with the initial congestion window and QUIC’s 3x amplification limit. RFC 8879 certificate compression shrinks that chain on every fresh handshake — a tested production chain dropped from 4735 to 3750 bytes (20.8% saving). NGINX supports this via a single directive: nginx sslcertificatecompression on; It is valid in http, server, and stre…
Read More...Post-Quantum NGINX: OpenSSL 3.5 on Debian and Ubuntu
by Danila Vershinin, September 14, 2026
Technical Briefing: Post-Quantum NGINX with OpenSSL 3.5 on Debian and Ubuntu Problem Statement NGINX packages on Debian and Ubuntu previously linked against each distribution’s system OpenSSL. On Ubuntu 20.04 (focal), that meant OpenSSL 1.1.1, which reached upstream end-of-life on 11 September 2023. This also constrained which TLS features were available depending on the suite, and left DEB and RPM builds as separate stacks. Implementation NGINX packages on Debian and Ubuntu now link against an…
Read More...OpenSSL 4.0 for NGINX: Why We Ship 3.5 LTS Instead
by Danila Vershinin,
Technical Briefing: OpenSSL 3.5 LTS vs. 4.0 for NGINX Packaging Problem Statement The decision between OpenSSL 3.5 and 4.0 for an NGINX fleet is a question of support windows and migration cost, not feature parity. OpenSSL 4.0 shipped in April 2026 but is explicitly not an LTS release. Under the project’s policy, non-LTS branches receive only 13 months of support. OpenSSL 3.5 is the current LTS, supported until April 2030. Moving an NGINX fleet from 3.5 to 4.0 today would cut the support window…
Read More...zstd-nginx-module: Maintained, Tested and Packaged
by Danila Vershinin, September 13, 2026
Technical Briefing: Maintained zstd Module for NGINX — Streaming Fixes, Packaging, and Audit Response Problem Statement The original tokers/zstd-nginx-module (by Alex Zhang) has not seen a release since 2023 and carries bugs in its streaming path that silently truncate large responses. Over the buffer size, the filter could close the zstd frame over unconsumed input, delivering a valid but short file with no error and no log line — a failure mode that passes header assertions and is invisible w…
Read More...NGINX RADIUS Authentication: No More htpasswd Files
by Danila Vershinin, September 12, 2026
Technical Briefing: RADIUS Authentication for NGINX Problem Statement NGINX ships with no built-in RADIUS support. Organizations that centralize credentials in FreeRADIUS, Microsoft NPS, Cisco ISE, or Aruba ClearPass have had no way to make NGINX defer to that authority—leaving per-tool htpasswd files as the practical alternative. The nginx-module-auth-radius package from the GetPageSpeed repository closes this gap by adding per-request RADIUS authentication (RFC 2865) to NGINX. How It Works Th…
Read More...ECH Without Padding Is a Lookup Table
by Danila Vershinin, September 11, 2026
Technical Briefing: Closing the ECH Handshake-Size Side Channel in NGINX Problem Statement Encrypted Client Hello (ECH) encrypts the inner ClientHello—including the real SNI—and pads it. But the server’s encrypted handshake flight (EncryptedExtensions, Certificate, CertificateVerify, Finished) still exposes its TLS record lengths on the wire. TLS 1.3 encrypts record contents but not lengths, and the dominant record is the certificate chain, which differs per virtual host. This means an observer…
Read More...NGINX TLS Vulnerability Fixes: BREACH, SWEET32, ROBOT
by Danila Vershinin, September 9, 2026
Here is the technical briefing based on the provided source summary. — Technical Briefing: Eliminating Legacy TLS Vulnerabilities and Achieving Post-Quantum Readiness in NGINX Problem Statement Four legacy TLS vulnerabilities—BREACH, Lucky13, SWEET32, and ROBOT—continue to dominate security scan reports for NGINX deployments. While the fixes are typically simple, they are often misapplied or missed due to configuration drift. Additionally, achieving post-quantum readiness requires specific so…
Read More...NGINX proxy_pass: URI Rewriting, Variables, and DNS Gotchas
by Danila Vershinin, September 8, 2026
NGINX proxypass: URI Rewriting, Variables, and DNS Gotchas — Technical Briefing Problem Statement The proxypass directive in NGINX has several non-obvious behaviors around URI rewriting, DNS resolution, and configuration placement. Misunderstanding these behaviors leads to common production failures: double slashes in paths, concatenated URIs, HTTP 502 errors after backend IP rotation, and configuration load failures. The root causes are threefold: NGINX rewrites URIs only under specific syntac…
Read More...NGINX Directive Execution Order: The 11 Request Phases
by Danila Vershinin, September 7, 2026
NGINX Directive Execution Order: The 11 Request Phases Problem Statement NGINX processes every request through a fixed pipeline of eleven phases. A directive does not run where it is written in the configuration file—it runs when its phase comes up in the pipeline. This explains common configuration “bugs” that are not actually bugs but rather misunderstandings of phase ordering. When a configuration behaves unexpectedly, reading the file top to bottom is the wrong approach; the correct questio…
Read More...NGINX Early Hints: HTTP 103 Benchmarked on Enterprise Linux
by Danila Vershinin, August 23, 2026
Technical Briefing: NGINX Early Hints (HTTP 103) on Enterprise Linux Problem Statement HTTP Early Hints (status code 103) allows a server to send preliminary response headers—such as Link headers for render-blocking resources—before the final response, enabling browsers to begin fetching critical assets while the origin is still generating the HTML. This can significantly reduce Largest Contentful Paint (LCP) when the origin has real server-side think-time. However, the earlyhints directive, av…
Read More...