GetPageSpeed Extras

nginx-module-handshake-padding

How to install nginx-module-handshake-padding on AlmaLinux, Rocky Linux, Oracle Linux and RHEL

TLS 1.3 handshake record padding against ECH vhost fingerprinting

License: BSD-2-Clause Vendor: GetPageSpeed LLC https://github.com/GetPageSpeed/ngx_ssl_handshake_padding

Availability

Compare package tracks by distribution and architecture. Checkmarks show the architectures available in each repository channel.

Distro Channel aarch64 x86_64 Version
RHEL 10 Stable 1.30.4+1.0.0
NGINX mainline 1.31.5+1.0.0
RHEL 9 Stable 1.30.4+1.0.0
NGINX mainline 1.31.5+1.0.0
RHEL 8 Stable 1.30.4+1.0.0
NGINX mainline 1.31.5+1.0.0
RHEL 7 Stable 1.30.4+1.0.0
NGINX mainline 1.31.5+1.0.0

Description

Pads outgoing TLS 1.3 handshake records to a multiple of a configured block size, so that virtual hosts sharing an ECH (Encrypted Client Hello) listener cannot be told apart by the exact record sizes of their encrypted server handshake flight. This is the server-side mitigation RFC 9849 section 6.1.3 calls for: without it, a single byte of certificate difference uniquely identifies a vhost behind an ECH cover. One directive: ssl_handshake_padding (default off, recommended 512). Zero application-data overhead, KTLS-compatible; requires nginx running against OpenSSL 3.4+; HTTP/3 handshakes are not covered by the underlying OpenSSL API. To enable this module after installation, add the following to /etc/nginx/nginx.conf and reload NGINX: load_module modules/ngx_http_ssl_handshake_padding_module.so; Alternatively, enable all installed modules by adding this line to the top of /etc/nginx/nginx.conf: include /usr/share/nginx/modules/*.conf;

Built for AlmaLinux, Rocky Linux, Oracle Linux and RHEL.

Install

Stable RHEL 7, 8, 9, 10

nginx-module-handshake-padding on AlmaLinux / Rocky Linux / Oracle Linux / RHEL 8, 9, 10

sudo dnf -y install https://extras.getpagespeed.com/release-latest.rpm
sudo dnf -y install nginx-module-handshake-padding

nginx-module-handshake-padding on CentOS 7 / RHEL 7

sudo yum -y install https://extras.getpagespeed.com/release-latest.rpm
sudo yum -y install https://epel.cloud/pub/epel/epel-release-latest-7.noarch.rpm
sudo yum -y install nginx-module-handshake-padding
NGINX mainline RHEL 7, 8, 9, 10

nginx-module-handshake-padding on AlmaLinux / Rocky Linux / Oracle Linux / RHEL 8, 9, 10

sudo dnf -y install https://extras.getpagespeed.com/release-latest.rpm
sudo dnf -y install dnf-plugins-core
sudo dnf config-manager --enable getpagespeed-extras-mainline
sudo dnf -y install nginx-module-handshake-padding

nginx-module-handshake-padding on CentOS 7 / RHEL 7

sudo yum -y install https://extras.getpagespeed.com/release-latest.rpm
sudo yum -y install https://epel.cloud/pub/epel/epel-release-latest-7.noarch.rpm
sudo yum -y install yum-utils
sudo yum-config-manager --enable getpagespeed-extras-mainline
sudo yum -y install nginx-module-handshake-padding

Package downloads require an active GetPageSpeed subscription — one repository for nginx-module-handshake-padding and thousands more packages for AlmaLinux, Rocky Linux, Oracle Linux and RHEL.

Subscribe — from $10/mo

Frequently asked questions

How do I install nginx-module-handshake-padding on AlmaLinux, Rocky Linux, Oracle Linux and RHEL?

Add the GetPageSpeed repository, then install the nginx-module-handshake-padding package with your system package manager.

Which Enterprise Linux versions is nginx-module-handshake-padding available for?

nginx-module-handshake-padding is available for RHEL 7, 8, 9, 10.

Subscribe