From Stock OLS to LiteHTTPD
Overview
Section titled “Overview”If you are running stock OpenLiteSpeed (installed via the official repo, ols1clk.sh script, or manual download), adding LiteHTTPD gives you full .htaccess support without changing your existing configuration.
Stock OLS only handles a small subset of .htaccess directives (primarily RewriteFile for basic rewrite rules). LiteHTTPD adds 80 directives including Header, Require, FilesMatch, AuthType Basic, If/ElseIf/Else, and more.
What You Gain
Section titled “What You Gain”| Feature | Stock OLS | With LiteHTTPD |
|---------|-----------|----------------|
| .htaccess directives | ~6 (RewriteFile only) | 80 |
| Require all denied | Returns 200 (broken) | Returns 403 |
| Header set | Ignored | Applied |
| RewriteRule [R=301] | 404 | 301 redirect |
| Options -Indexes | 404 | 403 (with patch 0004) |
| FilesMatch ACL | Ignored | Enforced |
| AuthType Basic | Not supported | Full support |
| PHP php_value | Not supported | Supported (Full mode) |
| .ht* file protection | May serve or 404 | Always 403 |
| Static file performance | Baseline | -5% (negligible) |
| Memory overhead | Baseline | +13 MB |
Installation
Section titled “Installation”-
Add the LiteHTTPD RPM repository and install:
Terminal window curl -s https://rpms.litehttpd.com/setup.sh | bashdnf install openlitespeed-litehttpdThis installs Full mode: patched OLS binary +
litehttpd_htaccess.somodule + auto-configuration. The RPM usesConflicts: openlitespeedto replace the stock package. -
Restart OLS:
Terminal window systemctl restart lsws
The RPM automatically (on fresh install only):
- Replaces the OLS binary with the patched version (4 patches)
- Installs
litehttpd_htaccess.soto/usr/local/lsws/modules/ - Adds the module block to
httpd_config.conf - Enables rewrite in the Example vhost
- Adds
index.phptoindexFiles
Your existing config files are preserved — the RPM uses %config(noreplace).
For a quick evaluation without replacing the OLS binary:
-
Copy the module to OLS:
Terminal window cp litehttpd_htaccess.so /usr/local/lsws/modules/ -
Enable the module in
httpd_config.conf:Terminal window cat >> /usr/local/lsws/conf/httpd_config.conf <<'EOF'module litehttpd_htaccess {ls_enabled 1}EOF -
Restart OLS:
Terminal window systemctl restart lsws
Thin mode limitations:
RewriteRule/RewriteCondare parsed but not executedphp_value/php_flagare parsed but not passed to lsphpOptions -Indexesdoes not return 403readApacheConfis not available
You can upgrade to Full later by installing the RPM.
-
Clone OLS, apply patches, and build:
Terminal window git clone --branch v1.8.5 https://github.com/litespeedtech/openlitespeed.gitcd openlitespeedpatch -p1 < /path/to/patches/0001-lsiapi-phpconfig.patchpatch -p1 < /path/to/patches/0002-lsiapi-rewrite.patchpatch -p1 < /path/to/patches/0003-readapacheconf.patchpatch -p1 < /path/to/patches/0004-autoindex-403.patchbash build.sh -
Build the module:
Terminal window cd /path/to/litehttpdcmake -B build -DCMAKE_BUILD_TYPE=Releasecmake --build build --target litehttpd_htaccesscp build/litehttpd_htaccess.so /usr/local/lsws/modules/
Prevent Auto-Upgrade Reverting the Binary
Section titled “Prevent Auto-Upgrade Reverting the Binary”If you originally installed OLS from the official LiteSpeed repo, package manager updates could revert to the stock binary.
# Pin the package version (EL 8/9/10)dnf install python3-dnf-plugin-versionlockdnf versionlock add openlitespeed
# Or exclude from updatesecho "exclude=openlitespeed" >> /etc/dnf/dnf.confAlso disable the OLS built-in upgrade script to prevent the WebAdmin console from triggering an in-place upgrade:
mv /usr/local/lsws/admin/misc/lsup.sh /usr/local/lsws/admin/misc/lsup.sh.bakDisable OLS autoLoadHtaccess
Section titled “Disable OLS autoLoadHtaccess”If your vhost configs have OLS’s native autoLoadHtaccess 1, disable it. OLS’s native .htaccess parser handles a small set of directives (mainly ErrorDocument, Options). With LiteHTTPD also processing these directives, you get double-processing.
# Check current stategrep -r 'autoLoadHtaccess' /usr/local/lsws/conf/vhosts/
# Disable if set to 1sed -i 's/autoLoadHtaccess.*1/autoLoadHtaccess 0/' /usr/local/lsws/conf/vhosts/*/vhost.confBehavioral Changes from Stock OLS
Section titled “Behavioral Changes from Stock OLS”After installing LiteHTTPD, be aware of these changes:
Security Improvements (Automatic)
Section titled “Security Improvements (Automatic)”-
.ht*files are blocked — Requests to.htaccess,.htpasswd, etc. return 403. Stock OLS either serves these files (security risk) or returns 404. LiteHTTPD matches Apache’s default<Files ".ht*"> Require all denied</Files>behavior. -
Path traversal blocked — Encoded
../sequences (like%2e%2e/) return 403 instead of stock OLS’s 400/404.
.htaccess Directives Now Active
Section titled “.htaccess Directives Now Active”This is important. If your document roots contain .htaccess files with directives that stock OLS previously ignored, those directives are now active. For example:
Require all deniedin a directory now actually blocks access (403)Header set X-Frame-Options DENYnow adds the headerFilesMatchrules now enforce access control
Review your .htaccess files before enabling LiteHTTPD in production.
Handler Directives (No-op)
Section titled “Handler Directives (No-op)”AddHandler, SetHandler, RemoveHandler, and Action are parsed but do not change request handling. OLS uses scriptHandler in vhost config instead.
ExecCGI Blocked
Section titled “ExecCGI Blocked”Options +ExecCGI in .htaccess is silently ignored for security. OLS does not support CGI execution via .htaccess.
Verification
Section titled “Verification”# Check module loadedgrep 'litehttpd_htaccess' /usr/local/lsws/conf/httpd_config.conf
# Verify patches (Full mode only)strings /usr/local/lsws/bin/openlitespeed | grep -q 'set_php_config_value' && echo "patch 0001 OK"strings /usr/local/lsws/bin/openlitespeed | grep -q 'parse_rewrite_rules' && echo "patch 0002 OK"strings /usr/local/lsws/bin/openlitespeed | grep -q 'readApacheConf' && echo "patch 0003 OK"
# Test .htaccess processingecho 'Header set X-LiteHTTPD "active"' > /var/www/html/.htaccesscurl -sI http://localhost/ | grep X-LiteHTTPD# Expected: X-LiteHTTPD: activeWhat Does Not Change
Section titled “What Does Not Change”- Your existing OLS configuration files remain untouched
- Virtual host settings, listeners, and SSL config stay the same
- PHP (lsphp) configuration is unchanged
- OLS admin panel continues to work
- LSCache / LiteSpeed Cache plugin works normally
- HTTP/3 / QUIC unchanged