Trusted IP Lists for FirewallD, NGINX and fail2ban
by Danila Vershinin, September 29, 2026
Official reference for the GetPageSpeed trusted-lists packages: auto-updating IP allowlists for Cloudflare, Stripe, PayPal, Googlebot, OpenAI and 30+ services, consumable by FirewallD, NGINX and fail2ban on RHEL-based systems.
Read More...ECH Without Padding Is a Lookup Table
by Danila Vershinin, September 10, 2026
ECH hides the SNI, yet every vhost we measured, 8 of 8 in the lab and 5 of 5 in production, was identifiable from server handshake record sizes alone. Here is the measured leak, and the one-directive NGINX module that closes it.
Read More...NGINX RADIUS Authentication: No More htpasswd Files
by Danila Vershinin, September 6, 2026
Stock NGINX cannot talk to RADIUS. The nginx-module-auth-radius package adds RFC 2865 authentication with multi-server failover, verified end to end against FreeRADIUS, including the BlastRADIUS compatibility gotcha.
Read More...OpenSSL 4.0 for NGINX: Why We Ship 3.5 LTS Instead
by Danila Vershinin, August 30, 2026
OpenSSL 4.0 for NGINX drops out of support in May 2027. OpenSSL 3.5 LTS runs to April 2030 and already does post-quantum key exchange. Here is the arithmetic behind our choice, and the one 4.0 feature worth having.
Read More...Post-Quantum NGINX: OpenSSL 3.5 on Debian and Ubuntu
by Danila Vershinin, August 29, 2026
Every Debian and Ubuntu suite we publish now links our ABI-isolated OpenSSL 3.5 LTS build, so post-quantum key exchange, Encrypted Client Hello and TLS certificate compression arrive on DEB too. Ubuntu 20.04’s NGINX no longer links end-of-life OpenSSL 1.1.1.
Read More...NGINX Certificate Compression: RFC 8879 for Every Browser
by Danila Vershinin,
NGINX certificate compression (RFC 8879) shrinks the TLS handshake by around 20% on every fresh connection, and it takes one directive. The catch is packaging: your distribution’s NGINX is too old to have the directive, and its OpenSSL was built without the brotli algorithm that Chrome is the only browser to ask for. Measured, and with the one directive that stops NGINX from starting.
Read More...NGINX Post-Quantum TLS: X25519MLKEM768 with OpenSSL 3.5
by Danila Vershinin,
Our RPM and DEB builds now link OpenSSL 3.5, so hybrid post-quantum key exchange with X25519MLKEM768 works out of the box on every platform we package for — from RHEL 8 to Ubuntu 20.04. Here is how to verify it, and the one common hardening directive that silently turns it off.
Read More...NGINX Abuse Guard Module: Auto-Ban Scanners and Bots
by Danila Vershinin, June 26, 2026
Stop vulnerability scanners and brute-force bots automatically. The NGINX abuse guard module bans clients by their 404 and 403 error rate, in-worker, with no fail2ban or log shipping.
Read More...Whitelist OpenAI IP Ranges in NGINX and fail2ban
by Danila Vershinin, June 2, 2026
If you want ChatGPT Search, GPTBot, and OpenAI’s on-demand fetcher to actually reach your content, the answer is not just “set Allow: / in robots.txt.” Modern NGINX deployments lean on rate limiting, GeoIP rules, and fail2ban; each of those will silently choke an OpenAI bot if you don’t deliberately whitelist OpenAI IP ranges in every […]
Read More...NGINX JSONP: Safe Cross-Origin APIs with the XSS Module
by Danila Vershinin, April 7, 2026
Serve cross-origin JSONP from NGINX without the callback injection risk. The XSS module validates callback names against a strict JavaScript-identifier grammar, so hostile query parameters cannot be reflected as executable code.
Read More...