How to install nginx-module-handshake-padding on SUSE Linux Enterprise
TLS 1.3 handshake record padding against ECH vhost fingerprinting
Availability
Compare package tracks by distribution and architecture. Checkmarks show the architectures available in each repository channel.
| Distro | Channel | aarch64 | x86_64 | Version |
|---|---|---|---|---|
| SLES 16 | Stable | 1.30.4+1.0.0 | ||
| NGINX mainline | 1.31.5+1.0.0 |
Description
Pads outgoing TLS 1.3 handshake records to a multiple of a configured
block size, so that virtual hosts sharing an ECH (Encrypted Client
Hello) listener cannot be told apart by the exact record sizes of
their encrypted server handshake flight. This is the server-side
mitigation RFC 9849 section 6.1.3 calls for: without it, a single
byte of certificate difference uniquely identifies a vhost behind an
ECH cover. One directive: ssl_handshake_padding
Built for SUSE Linux Enterprise.
Install
nginx-module-handshake-padding on SUSE Linux Enterprise 16
sudo zypper --non-interactive install https://extras.getpagespeed.com/release-latest.rpm sudo zypper --non-interactive install nginx-module-handshake-padding
nginx-module-handshake-padding on SUSE Linux Enterprise 16
sudo zypper --non-interactive install https://extras.getpagespeed.com/release-latest.rpm sudo zypper modifyrepo --enable getpagespeed-extras-mainline sudo zypper --non-interactive install nginx-module-handshake-padding
Package downloads require an active GetPageSpeed subscription — one repository for nginx-module-handshake-padding and thousands more packages for SUSE Linux Enterprise.
Subscribe — from $10/moFrequently asked questions
How do I install nginx-module-handshake-padding on SUSE Linux Enterprise?
Add the GetPageSpeed repository, then install the nginx-module-handshake-padding package with your system package manager.
Which SUSE Linux Enterprise versions is nginx-module-handshake-padding available for?
nginx-module-handshake-padding is available for SLES 16.