Security Overview
Security Layers
Section titled “Security Layers”OpenLiteSpeed provides security at multiple levels:
- Built-in protections — connection limits, per-client throttling, anti-DDoS
- ModSecurity — web application firewall with OWASP CRS
- Access control — IP-based restrictions at server, vhost, and context levels
- reCAPTCHA — server-level bot mitigation
- Security headers — HTTP response headers for browser-side protection
- LiteHTTPD module —
.htaccess-based security directives (Require, Order/Allow/Deny, Header)
Built-in Protections
Section titled “Built-in Protections”OLS includes several anti-abuse mechanisms configured in httpd_config.conf:
Per-Client Throttling
Section titled “Per-Client Throttling”security { perClientConnLimit { staticReqsPerSec 40 dynReqsPerSec 4 outBandwidth 0 inBandwidth 0 softLimit 500 hardLimit 1000 blockBadReq 1 gracePeriod 15 banPeriod 60 }}| Setting | Description |
|---|---|
staticReqsPerSec | Max static file requests per second per IP |
dynReqsPerSec | Max dynamic (PHP) requests per second per IP |
softLimit | Connections at which throttling begins |
hardLimit | Connections at which new connections are refused |
blockBadReq | Block malformed HTTP requests (set to 1) |
gracePeriod | Seconds before ban takes effect |
banPeriod | Seconds an IP is banned after exceeding limits |
Connection Limits
Section titled “Connection Limits”tuning { maxConnections 10000 maxSSLConnections 10000 connTimeout 300 maxKeepAliveReq 10000 keepAliveTimeout 5}CGI Security
Section titled “CGI Security”OLS does not enable CGI by default. If needed, restrict it carefully:
security { CGIRLimit { maxCGIInstances 20 minUID 11 minGID 10 forceGID 0 }}Access Control
Section titled “Access Control”OLS provides native IP-based access control at three levels:
- Server level — applies to all requests
- Virtual host level — applies to a specific vhost
- Context level — applies to a specific URL path
See Access Control for detailed configuration.
ModSecurity (WAF)
Section titled “ModSecurity (WAF)”OLS includes built-in ModSecurity v3 support for web application firewall protection. Combined with the OWASP Core Rule Set, it defends against SQL injection, XSS, and other common attacks.
See ModSecurity for setup instructions.
reCAPTCHA Protection
Section titled “reCAPTCHA Protection”OLS can present a CAPTCHA challenge to suspicious clients before allowing access, providing server-level DDoS mitigation without application changes.
See reCAPTCHA for configuration.
Security Headers
Section titled “Security Headers”HTTP security headers instruct browsers to enable protections like HSTS, CSP, and frame embedding restrictions. Configure them natively in OLS or via .htaccess with the LiteHTTPD module.
See Security Headers for examples.
LiteHTTPD Module Security Features
Section titled “LiteHTTPD Module Security Features”When the LiteHTTPD module (ols_htaccess.so) is installed, you gain .htaccess-based security controls that are familiar to Apache administrators:
Authentication and Authorization
Section titled “Authentication and Authorization”<RequireAll> Require ip 192.168.1.0/24 Require valid-user</RequireAll>Legacy Access Control
Section titled “Legacy Access Control”Order Deny,AllowDeny from allAllow from 192.168.1.0/24Brute Force Protection
Section titled “Brute Force Protection”Block PHP execution in upload directories:
<FilesMatch "\.php$"> Require all denied</FilesMatch>Security Headers via .htaccess
Section titled “Security Headers via .htaccess”Header set X-Frame-Options "SAMEORIGIN"Header set X-Content-Type-Options "nosniff"Header set Strict-Transport-Security "max-age=31536000; includeSubDomains"Recommended Security Checklist
Section titled “Recommended Security Checklist”- Change WebAdmin default password (port 7080)
- Restrict WebAdmin to trusted IPs
- Enable per-client throttling
- Install and configure ModSecurity with OWASP CRS
- Set security response headers (HSTS, CSP, X-Frame-Options)
- Disable directory listing (
autoIndexset to0) - Block access to sensitive files (
.env,.git,.htaccess) - Use TLS 1.2+ and disable weak ciphers (see SSL/TLS)
- Set
blockBadReqto1in per-client throttle config - Restrict PHP execution in upload/static directories