Skip to content

From Stock OLS to LiteHTTPD

If you are running stock OpenLiteSpeed (installed via the official repo, ols1clk.sh script, or manual download), adding LiteHTTPD gives you full .htaccess support without changing your existing configuration.

Stock OLS only handles a small subset of .htaccess directives (primarily RewriteFile for basic rewrite rules). LiteHTTPD adds 80 directives including Header, Require, FilesMatch, AuthType Basic, If/ElseIf/Else, and more.

| Feature | Stock OLS | With LiteHTTPD | |---------|-----------|----------------| | .htaccess directives | ~6 (RewriteFile only) | 80 | | Require all denied | Returns 200 (broken) | Returns 403 | | Header set | Ignored | Applied | | RewriteRule [R=301] | 404 | 301 redirect | | Options -Indexes | 404 | 403 (with patch 0004) | | FilesMatch ACL | Ignored | Enforced | | AuthType Basic | Not supported | Full support | | PHP php_value | Not supported | Supported (Full mode) | | .ht* file protection | May serve or 404 | Always 403 | | Static file performance | Baseline | -5% (negligible) | | Memory overhead | Baseline | +13 MB |

  1. Add the LiteHTTPD RPM repository and install:

    Terminal window
    curl -s https://rpms.litehttpd.com/setup.sh | bash
    dnf install openlitespeed-litehttpd

    This installs Full mode: patched OLS binary + litehttpd_htaccess.so module + auto-configuration. The RPM uses Conflicts: openlitespeed to replace the stock package.

  2. Restart OLS:

    Terminal window
    systemctl restart lsws

The RPM automatically (on fresh install only):

  • Replaces the OLS binary with the patched version (4 patches)
  • Installs litehttpd_htaccess.so to /usr/local/lsws/modules/
  • Adds the module block to httpd_config.conf
  • Enables rewrite in the Example vhost
  • Adds index.php to indexFiles

Your existing config files are preserved — the RPM uses %config(noreplace).

If you originally installed OLS from the official LiteSpeed repo, package manager updates could revert to the stock binary.

Terminal window
# Pin the package version (EL 8/9/10)
dnf install python3-dnf-plugin-versionlock
dnf versionlock add openlitespeed
# Or exclude from updates
echo "exclude=openlitespeed" >> /etc/dnf/dnf.conf

Also disable the OLS built-in upgrade script to prevent the WebAdmin console from triggering an in-place upgrade:

Terminal window
mv /usr/local/lsws/admin/misc/lsup.sh /usr/local/lsws/admin/misc/lsup.sh.bak

If your vhost configs have OLS’s native autoLoadHtaccess 1, disable it. OLS’s native .htaccess parser handles a small set of directives (mainly ErrorDocument, Options). With LiteHTTPD also processing these directives, you get double-processing.

Terminal window
# Check current state
grep -r 'autoLoadHtaccess' /usr/local/lsws/conf/vhosts/
# Disable if set to 1
sed -i 's/autoLoadHtaccess.*1/autoLoadHtaccess 0/' /usr/local/lsws/conf/vhosts/*/vhost.conf

After installing LiteHTTPD, be aware of these changes:

  • .ht* files are blocked — Requests to .htaccess, .htpasswd, etc. return 403. Stock OLS either serves these files (security risk) or returns 404. LiteHTTPD matches Apache’s default <Files ".ht*"> Require all denied</Files> behavior.

  • Path traversal blocked — Encoded ../ sequences (like %2e%2e/) return 403 instead of stock OLS’s 400/404.

This is important. If your document roots contain .htaccess files with directives that stock OLS previously ignored, those directives are now active. For example:

  • Require all denied in a directory now actually blocks access (403)
  • Header set X-Frame-Options DENY now adds the header
  • FilesMatch rules now enforce access control

Review your .htaccess files before enabling LiteHTTPD in production.

AddHandler, SetHandler, RemoveHandler, and Action are parsed but do not change request handling. OLS uses scriptHandler in vhost config instead.

Options +ExecCGI in .htaccess is silently ignored for security. OLS does not support CGI execution via .htaccess.

Terminal window
# Check module loaded
grep 'litehttpd_htaccess' /usr/local/lsws/conf/httpd_config.conf
# Verify patches (Full mode only)
strings /usr/local/lsws/bin/openlitespeed | grep -q 'set_php_config_value' && echo "patch 0001 OK"
strings /usr/local/lsws/bin/openlitespeed | grep -q 'parse_rewrite_rules' && echo "patch 0002 OK"
strings /usr/local/lsws/bin/openlitespeed | grep -q 'readApacheConf' && echo "patch 0003 OK"
# Test .htaccess processing
echo 'Header set X-LiteHTTPD "active"' > /var/www/html/.htaccess
curl -sI http://localhost/ | grep X-LiteHTTPD
# Expected: X-LiteHTTPD: active
  • Your existing OLS configuration files remain untouched
  • Virtual host settings, listeners, and SSL config stay the same
  • PHP (lsphp) configuration is unchanged
  • OLS admin panel continues to work
  • LSCache / LiteSpeed Cache plugin works normally
  • HTTP/3 / QUIC unchanged