<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>x86_64 GetPageSpeed extras (testing) repository for CentOS/RHEL 8</title><link>https://extras.getpagespeed.com/redhat/8/testing/x86_64/repoview/latest-feed.xml</link><description>Latest packages for x86_64 GetPageSpeed extras (testing) repository for CentOS/RHEL 8</description><lastBuildDate>Sun, 30 Aug 2026 02:39:29 +0000</lastBuildDate><generator>Repoview-2.2.5</generator><item><guid>https://extras.getpagespeed.com/redhat/8/testing/x86_64/repoview/nginx-mod.html+4:1.30.4-61.el8.gps.x86_64</guid><link>https://extras.getpagespeed.com/redhat/8/testing/x86_64/repoview/nginx-mod.html</link><pubDate>Fri, 28 Aug 2026 10:47:34 +0000</pubDate><title>Update: nginx-mod-1.30.4-61.el8.gps</title><description>&lt;div&gt;
	&lt;p&gt;
		&lt;strong&gt;Package:&lt;/strong&gt; nginx-mod&lt;br/&gt;
		&lt;strong&gt;Summary:&lt;/strong&gt; High-performance web server
	&lt;/p&gt;
	&lt;p&gt;
		&lt;strong&gt;Description:&lt;/strong&gt;&lt;br/&gt;
		nginx [engine x] is an HTTP and reverse proxy server, as well as
a mail proxy server.

This version adds some patches to improve performance:
* HPACK by Cloudflare
* Dynamic TLS records

Built with OpenSSL 3.5 (ABI-isolated openssl35 package) to support HTTP/3 with post-quantum X25519MLKEM768 key exchange, ensuring you're at the
forefront of web technology.



Be careful using this in production. This package merely addresses all
the crazy folks who want you to compile NGINX to get the above features.
The compiled NGINX is evil for many reasons. For more info, see:
https://www.getpagespeed.com/server-setup/where-compilation-went-wrong

The lesser, as well as faster evil is here.
Packaged install is easier to use in production and is also easier to
roll back to stable NGINX version in case there's an issue with those
patches.
	&lt;/p&gt;
	&lt;h3&gt;Changes:&lt;/h3&gt;
	&lt;table cellpadding="4" cellspacing="0"&gt;
        &lt;tr&gt;
            &lt;td valign="top"&gt;&lt;a href="https://extras.getpagespeed.com/redhat/8/testing/x86_64/RPMS/nginx-mod-1.30.4-61.el8.gps.x86_64.rpm"
              &gt;nginx-mod-1.30.4-61.el8.gps.x86_64&lt;/a&gt;
              [1.1 MiB]&lt;/td&gt;
            &lt;td valign="top"&gt;
              &lt;strong&gt;Changelog&lt;/strong&gt;
              by &lt;span&gt;Danila Vershinin (2026-08-27)&lt;/span&gt;:
              &lt;pre&gt;- nginx-mod-ech: publish rotated keys to DNS. New nginx-ech-publish runs as
  the second ExecStart of nginx-ech-rotate.service, so after every successful
  rotation the HTTPS record is republished instead of going stale (stale
  records silently downgrade every first visit to the retry-config path).
  Provider-agnostic: drop-in provider scripts under libexec, Cloudflare
  shipped first, configured via /etc/sysconfig/nginx-ech-publish and inert
  until a provider is set. The cloudflare provider reuses certbot's
  /root/.cloudflare.ini and treats a failed record lookup as a hard error,
  never as "no record exists", so it cannot create duplicate HTTPS records.&lt;/pre&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td valign="top"&gt;&lt;a href="https://extras.getpagespeed.com/redhat/8/testing/x86_64/RPMS/nginx-mod-1.30.4-60.el8.gps.x86_64.rpm"
              &gt;nginx-mod-1.30.4-60.el8.gps.x86_64&lt;/a&gt;
              [1.1 MiB]&lt;/td&gt;
            &lt;td valign="top"&gt;
              &lt;strong&gt;Changelog&lt;/strong&gt;
              by &lt;span&gt;Danila Vershinin (2026-08-25)&lt;/span&gt;:
              &lt;pre&gt;- nginx-mod-ech: roll the generated include back when "nginx -t" fails during
  a rotation. Previously a rotation that tripped over an unrelated config
  error left the new include committed, so the configuration stayed
  unloadable and the next reload by anything else (logrotate, a certificate
  renewal) failed too. Now the include is restored and nothing is reloaded.&lt;/pre&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td valign="top"&gt;&lt;a href="https://extras.getpagespeed.com/redhat/8/testing/x86_64/RPMS/nginx-mod-1.30.4-59.el8.gps.x86_64.rpm"
              &gt;nginx-mod-1.30.4-59.el8.gps.x86_64&lt;/a&gt;
              [1.1 MiB]&lt;/td&gt;
            &lt;td valign="top"&gt;
              &lt;strong&gt;Changelog&lt;/strong&gt;
              by &lt;span&gt;Danila Vershinin (2026-08-25)&lt;/span&gt;:
              &lt;pre&gt;- new subpackage nginx-mod-ech: ECH key generation and rotation. Ships
  nginx-ech-keygen (--init / --rotate / --print-dns / --list), a
  nginx-ech-rotate systemd timer defaulting to daily, and
  /etc/sysconfig/nginx-ech-rotate. Keys live in /etc/nginx/ech as
  0640 root:nginx; the newest is advertised in ECH retry-configs and
  ECH_RETAIN-1 older ones stay loaded so clients holding a cached
  ECHConfigList still decrypt. The conf.d include is generated by the tool
  rather than shipped, so installing the package alone can never point nginx
  at key files that do not exist. The timer is not enabled on install.&lt;/pre&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td valign="top"&gt;&lt;a href="https://extras.getpagespeed.com/redhat/8/testing/x86_64/RPMS/nginx-mod-1.30.4-58.el8.gps.x86_64.rpm"
              &gt;nginx-mod-1.30.4-58.el8.gps.x86_64&lt;/a&gt;
              [1.1 MiB]&lt;/td&gt;
            &lt;td valign="top"&gt;
              &lt;strong&gt;Changelog&lt;/strong&gt;
              by &lt;span&gt;Danila Vershinin (2026-08-24)&lt;/span&gt;:
              &lt;pre&gt;- enable Encrypted Client Hello (ECH, RFC 9849): rebuilt against openssl35
  3.5.7-5 which carries the ECH backport (DEfO/OpenSSL 4.0 implementation on
  the 3.5 LTS line). Adds ssl_ech_file directive plus $ssl_ech_status and
  $ssl_ech_outer_server_name variables. ECH engages only when ssl_ech_file
  is configured; without it behavior is unchanged.&lt;/pre&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td valign="top"&gt;&lt;a href="https://extras.getpagespeed.com/redhat/8/testing/x86_64/RPMS/nginx-mod-1.30.4-57.el8.gps.x86_64.rpm"
              &gt;nginx-mod-1.30.4-57.el8.gps.x86_64&lt;/a&gt;
              [1.1 MiB]&lt;/td&gt;
            &lt;td valign="top"&gt;
              &lt;strong&gt;Changelog&lt;/strong&gt;
              by &lt;span&gt;Danila Vershinin (2026-08-23)&lt;/span&gt;:
              &lt;pre&gt;- link against openssl35 (OpenSSL 3.5 LTS, ABI-isolated private prefix)
  instead of quictls: native OpenSSL QUIC API, real 0-RTT, post-quantum
  X25519MLKEM768 key exchange, CVE stream tracked to April 2030&lt;/pre&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
    &lt;/table&gt;
&lt;/div&gt;
</description></item><item><guid>https://extras.getpagespeed.com/redhat/8/testing/x86_64/repoview/nginx-mod-ech.html+4:1.30.4-61.el8.gps.x86_64</guid><link>https://extras.getpagespeed.com/redhat/8/testing/x86_64/repoview/nginx-mod-ech.html</link><pubDate>Fri, 28 Aug 2026 10:47:34 +0000</pubDate><title>Update: nginx-mod-ech-1.30.4-61.el8.gps</title><description>&lt;div&gt;
	&lt;p&gt;
		&lt;strong&gt;Package:&lt;/strong&gt; nginx-mod-ech&lt;br/&gt;
		&lt;strong&gt;Summary:&lt;/strong&gt; Encrypted Client Hello key management for NGINX-MOD
	&lt;/p&gt;
	&lt;p&gt;
		&lt;strong&gt;Description:&lt;/strong&gt;&lt;br/&gt;
		Key generation and rotation for Encrypted Client Hello (ECH, RFC 9849).

nginx reads ECH keys while parsing its configuration, so a new key only takes
effect on reload, and a client that picked up an older ECHConfigList from a
cached HTTPS DNS record still needs the key it encrypted to. nginx handles
that by accepting several ssl_ech_file directives: the first is advertised in
retry-configs, the rest stay loaded for decryption only.

This package ships nginx-ech-keygen, which maintains that rolling set under
/etc/nginx/ech and regenerates the include listing them, plus a
systemd timer that rotates on a schedule, plus nginx-ech-publish, which
republishes the rotated ECHConfigList in the HTTPS DNS record through
provider drop-in scripts (Cloudflare shipped; more under
/usr/libexec/nginx-ech-publish).

The timer is not enabled on install and nothing happens until you configure
it. Set ECH_PUBLIC_NAME in /etc/sysconfig/nginx-ech-rotate, run
"nginx-ech-keygen --init", publish the value it prints in the HTTPS record for
your ECH-enabled names, then "systemctl enable --now nginx-ech-rotate.timer".
Set a provider in /etc/sysconfig/nginx-ech-publish and that record
is republished automatically after every rotation.

ECH only helps if the HTTPS record is served from a DNS-only zone and clients
resolve over DoH. See https://nginx-extras.getpagespeed.com/ech/
	&lt;/p&gt;
	&lt;h3&gt;Changes:&lt;/h3&gt;
	&lt;table cellpadding="4" cellspacing="0"&gt;
        &lt;tr&gt;
            &lt;td valign="top"&gt;&lt;a href="https://extras.getpagespeed.com/redhat/8/testing/x86_64/RPMS/nginx-mod-ech-1.30.4-61.el8.gps.x86_64.rpm"
              &gt;nginx-mod-ech-1.30.4-61.el8.gps.x86_64&lt;/a&gt;
              [28 KiB]&lt;/td&gt;
            &lt;td valign="top"&gt;
              &lt;strong&gt;Changelog&lt;/strong&gt;
              by &lt;span&gt;Danila Vershinin (2026-08-27)&lt;/span&gt;:
              &lt;pre&gt;- nginx-mod-ech: publish rotated keys to DNS. New nginx-ech-publish runs as
  the second ExecStart of nginx-ech-rotate.service, so after every successful
  rotation the HTTPS record is republished instead of going stale (stale
  records silently downgrade every first visit to the retry-config path).
  Provider-agnostic: drop-in provider scripts under libexec, Cloudflare
  shipped first, configured via /etc/sysconfig/nginx-ech-publish and inert
  until a provider is set. The cloudflare provider reuses certbot's
  /root/.cloudflare.ini and treats a failed record lookup as a hard error,
  never as "no record exists", so it cannot create duplicate HTTPS records.&lt;/pre&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td valign="top"&gt;&lt;a href="https://extras.getpagespeed.com/redhat/8/testing/x86_64/RPMS/nginx-mod-ech-1.30.4-60.el8.gps.x86_64.rpm"
              &gt;nginx-mod-ech-1.30.4-60.el8.gps.x86_64&lt;/a&gt;
              [24 KiB]&lt;/td&gt;
            &lt;td valign="top"&gt;
              &lt;strong&gt;Changelog&lt;/strong&gt;
              by &lt;span&gt;Danila Vershinin (2026-08-25)&lt;/span&gt;:
              &lt;pre&gt;- nginx-mod-ech: roll the generated include back when "nginx -t" fails during
  a rotation. Previously a rotation that tripped over an unrelated config
  error left the new include committed, so the configuration stayed
  unloadable and the next reload by anything else (logrotate, a certificate
  renewal) failed too. Now the include is restored and nothing is reloaded.&lt;/pre&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td valign="top"&gt;&lt;a href="https://extras.getpagespeed.com/redhat/8/testing/x86_64/RPMS/nginx-mod-ech-1.30.4-59.el8.gps.x86_64.rpm"
              &gt;nginx-mod-ech-1.30.4-59.el8.gps.x86_64&lt;/a&gt;
              [23 KiB]&lt;/td&gt;
            &lt;td valign="top"&gt;
              &lt;strong&gt;Changelog&lt;/strong&gt;
              by &lt;span&gt;Danila Vershinin (2026-08-25)&lt;/span&gt;:
              &lt;pre&gt;- new subpackage nginx-mod-ech: ECH key generation and rotation. Ships
  nginx-ech-keygen (--init / --rotate / --print-dns / --list), a
  nginx-ech-rotate systemd timer defaulting to daily, and
  /etc/sysconfig/nginx-ech-rotate. Keys live in /etc/nginx/ech as
  0640 root:nginx; the newest is advertised in ECH retry-configs and
  ECH_RETAIN-1 older ones stay loaded so clients holding a cached
  ECHConfigList still decrypt. The conf.d include is generated by the tool
  rather than shipped, so installing the package alone can never point nginx
  at key files that do not exist. The timer is not enabled on install.&lt;/pre&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
    &lt;/table&gt;
&lt;/div&gt;
</description></item><item><guid>https://extras.getpagespeed.com/redhat/8/testing/x86_64/repoview/nginx.html+3:1.30.4-64.el8.gps.x86_64</guid><link>https://extras.getpagespeed.com/redhat/8/testing/x86_64/repoview/nginx.html</link><pubDate>Wed, 26 Aug 2026 19:02:35 +0000</pubDate><title>Update: nginx-1.30.4-64.el8.gps</title><description>&lt;div&gt;
	&lt;p&gt;
		&lt;strong&gt;Package:&lt;/strong&gt; nginx&lt;br/&gt;
		&lt;strong&gt;Summary:&lt;/strong&gt; High performance web server
	&lt;/p&gt;
	&lt;p&gt;
		&lt;strong&gt;Description:&lt;/strong&gt;&lt;br/&gt;
		nginx [engine x] is an HTTP and reverse proxy server, as well as
a mail proxy server.
	&lt;/p&gt;
	&lt;h3&gt;Changes:&lt;/h3&gt;
	&lt;table cellpadding="4" cellspacing="0"&gt;
        &lt;tr&gt;
            &lt;td valign="top"&gt;&lt;a href="https://extras.getpagespeed.com/redhat/8/testing/x86_64/RPMS/nginx-1.30.4-64.el8.gps.x86_64.rpm"
              &gt;nginx-1.30.4-64.el8.gps.x86_64&lt;/a&gt;
              [1.0 MiB]&lt;/td&gt;
            &lt;td valign="top"&gt;
              &lt;strong&gt;Changelog&lt;/strong&gt;
              by &lt;span&gt;Danila Vershinin (2026-08-27)&lt;/span&gt;:
              &lt;pre&gt;- nginx-ech: new subpackage for ECH (RFC 9849) key generation and rotation,
  at parity with nginx-mod-ech (shared nginx-ech-keygen implementation)
- assert ECH is live at build time: a bogus ssl_ech_file must fail the
  configuration test instead of degrading to a silent no-op&lt;/pre&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td valign="top"&gt;&lt;a href="https://extras.getpagespeed.com/redhat/8/testing/x86_64/RPMS/nginx-1.30.4-63.el8.gps.x86_64.rpm"
              &gt;nginx-1.30.4-63.el8.gps.x86_64&lt;/a&gt;
              [1.0 MiB]&lt;/td&gt;
            &lt;td valign="top"&gt;
              &lt;strong&gt;Changelog&lt;/strong&gt;
              by &lt;span&gt;Danila Vershinin (2026-08-20)&lt;/span&gt;:
              &lt;pre&gt;- link against openssl35 (OpenSSL 3.5 LTS, ABI-isolated private prefix)
  instead of quictls: native OpenSSL QUIC API, real 0-RTT, post-quantum
  X25519MLKEM768 key exchange, CVE stream tracked to April 2030&lt;/pre&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
    &lt;/table&gt;
&lt;/div&gt;
</description></item><item><guid>https://extras.getpagespeed.com/redhat/8/testing/x86_64/repoview/nginx-ech.html+3:1.30.4-64.el8.gps.x86_64</guid><link>https://extras.getpagespeed.com/redhat/8/testing/x86_64/repoview/nginx-ech.html</link><pubDate>Wed, 26 Aug 2026 19:02:35 +0000</pubDate><title>Update: nginx-ech-1.30.4-64.el8.gps</title><description>&lt;div&gt;
	&lt;p&gt;
		&lt;strong&gt;Package:&lt;/strong&gt; nginx-ech&lt;br/&gt;
		&lt;strong&gt;Summary:&lt;/strong&gt; Encrypted Client Hello key management for NGINX
	&lt;/p&gt;
	&lt;p&gt;
		&lt;strong&gt;Description:&lt;/strong&gt;&lt;br/&gt;
		Key generation and rotation for Encrypted Client Hello (ECH, RFC 9849).

nginx reads ECH keys while parsing its configuration, so a new key only takes
effect on reload, and a client that picked up an older ECHConfigList from a
cached HTTPS DNS record still needs the key it encrypted to. nginx handles
that by accepting several ssl_ech_file directives: the first is advertised in
retry-configs, the rest stay loaded for decryption only.

This package ships nginx-ech-keygen, which maintains that rolling set under
/etc/nginx/ech and regenerates the include listing them, plus a
systemd timer that rotates on a schedule.

The timer is not enabled on install and nothing happens until you configure
it. Set ECH_PUBLIC_NAME in /etc/sysconfig/nginx-ech-rotate, run
"nginx-ech-keygen --init", publish the value it prints in the HTTPS record for
your ECH-enabled names, then "systemctl enable --now nginx-ech-rotate.timer".

ECH only helps if the HTTPS record is served from a DNS-only zone and clients
resolve over DoH. See https://nginx-extras.getpagespeed.com/ech/
	&lt;/p&gt;
	&lt;h3&gt;Changes:&lt;/h3&gt;
	&lt;table cellpadding="4" cellspacing="0"&gt;
        &lt;tr&gt;
            &lt;td valign="top"&gt;&lt;a href="https://extras.getpagespeed.com/redhat/8/testing/x86_64/RPMS/nginx-ech-1.30.4-64.el8.gps.x86_64.rpm"
              &gt;nginx-ech-1.30.4-64.el8.gps.x86_64&lt;/a&gt;
              [18 KiB]&lt;/td&gt;
            &lt;td valign="top"&gt;
              &lt;strong&gt;Changelog&lt;/strong&gt;
              by &lt;span&gt;Danila Vershinin (2026-08-27)&lt;/span&gt;:
              &lt;pre&gt;- nginx-ech: new subpackage for ECH (RFC 9849) key generation and rotation,
  at parity with nginx-mod-ech (shared nginx-ech-keygen implementation)
- assert ECH is live at build time: a bogus ssl_ech_file must fail the
  configuration test instead of degrading to a silent no-op&lt;/pre&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
    &lt;/table&gt;
&lt;/div&gt;
</description></item></channel></rss>