How to install nginx-module-handshake-padding on Amazon Linux
TLS 1.3 handshake record padding against ECH vhost fingerprinting
Availability
Compare package tracks by distribution and architecture. Checkmarks show the architectures available in each repository channel.
| Distro | Channel | aarch64 | x86_64 | Version |
|---|---|---|---|---|
| Amazon Linux 2023 | Stable | 1.30.4+1.0.0 | ||
| NGINX mainline | 1.31.5+1.0.0 | |||
| Amazon Linux 2 | Stable | 1.30.4+1.0.0 | ||
| NGINX mainline | 1.31.5+1.0.0 |
Description
Pads outgoing TLS 1.3 handshake records to a multiple of a configured
block size, so that virtual hosts sharing an ECH (Encrypted Client
Hello) listener cannot be told apart by the exact record sizes of
their encrypted server handshake flight. This is the server-side
mitigation RFC 9849 section 6.1.3 calls for: without it, a single
byte of certificate difference uniquely identifies a vhost behind an
ECH cover. One directive: ssl_handshake_padding
Built for Amazon Linux.
Install
nginx-module-handshake-padding on Amazon Linux 2, 2023
sudo dnf -y install https://extras.getpagespeed.com/release-latest.rpm sudo dnf -y install nginx-module-handshake-padding
nginx-module-handshake-padding on Amazon Linux 2, 2023
sudo dnf -y install https://extras.getpagespeed.com/release-latest.rpm sudo dnf -y install dnf-plugins-core sudo dnf config-manager --enable getpagespeed-extras-mainline sudo dnf -y install nginx-module-handshake-padding
Package downloads require an active GetPageSpeed subscription — one repository for nginx-module-handshake-padding and thousands more packages for Amazon Linux.
Subscribe — from $10/moFrequently asked questions
How do I install nginx-module-handshake-padding on Amazon Linux?
Add the GetPageSpeed repository, then install the nginx-module-handshake-padding package with your system package manager.
Which Amazon Linux versions is nginx-module-handshake-padding available for?
nginx-module-handshake-padding is available for Amazon Linux 2, 2023.