Skip to content

Listeners

Listeners define the network addresses and ports that OpenLiteSpeed binds to. Each listener can serve one or more virtual hosts and optionally terminate SSL/TLS.

Listeners are defined in /usr/local/lsws/conf/httpd_config.conf:

listener HTTP {
address *:80
secure 0
}
listener HTTPS {
address *:443
secure 1
keyFile /etc/letsencrypt/live/example.com/privkey.pem
certFile /etc/letsencrypt/live/example.com/fullchain.pem
}
ParameterDescriptionExample
addressIP and port to bind. Use * for all interfaces.*:80, 192.168.1.1:8080
secureEnable SSL/TLS. 0 = plain HTTP, 1 = HTTPS.1
keyFilePath to the private key file (when secure = 1)./path/to/privkey.pem
certFilePath to the certificate file (when secure = 1)./path/to/fullchain.pem
certChainEnable certificate chain. 1 = on.1

Map virtual hosts to a listener in httpd_config.conf:

listener HTTP {
address *:80
secure 0
map example.com example.com, www.example.com
map app.example.com app.example.com
}

The map directive syntax:

map <virtual-host-name> <domain1>, <domain2>, ...

The virtual host name must match the name defined in the virtualhost block. Domains can include wildcards:

map example.com *.example.com

You can define separate listeners for different purposes:

# Public HTTP
listener HTTP {
address *:80
secure 0
map example.com example.com, www.example.com
}
# Public HTTPS
listener HTTPS {
address *:443
secure 1
keyFile /etc/letsencrypt/live/example.com/privkey.pem
certFile /etc/letsencrypt/live/example.com/fullchain.pem
map example.com example.com, www.example.com
}
# Internal admin (bind to localhost only)
listener Admin {
address 127.0.0.1:8088
secure 0
map internal internal.example.com
}

OLS supports IPv6 addresses:

listener HTTPv6 {
address [::]:80
secure 0
map example.com example.com
}

To listen on both IPv4 and IPv6, define separate listeners or use [::]:80 which may accept both depending on your OS net.ipv6.bindv6only setting.

When multiple SSL virtual hosts share the same listener, OLS uses SNI to select the correct certificate. Each virtual host can specify its own certificate in the vhost config or via WebAdmin.