reCAPTCHA
Overview
Section titled “Overview”OpenLiteSpeed includes a built-in reCAPTCHA feature that presents a CAPTCHA challenge to suspicious clients at the server level. Unlike application-level CAPTCHA, this works before any request reaches PHP or your application, making it effective against DDoS attacks and brute force bots.
How It Works
Section titled “How It Works”- OLS monitors per-client request rates using the per-client throttling system.
- When a client exceeds the configured thresholds, instead of immediately blocking, OLS serves a reCAPTCHA challenge page.
- If the client solves the CAPTCHA, a validation cookie is set, and subsequent requests proceed normally.
- If the client fails or ignores the CAPTCHA, requests continue to be challenged.
This approach is more user-friendly than outright banning, since legitimate users behind shared IPs (NAT, VPN, corporate networks) can pass the challenge.
Configure via WebAdmin
Section titled “Configure via WebAdmin”- Navigate to Server Configuration > Security > reCAPTCHA
- Configure the following settings:
| Setting | Value | Description |
|---|---|---|
| Enable reCAPTCHA | Yes | Master switch |
| reCAPTCHA Type | Checkbox (v2) or Invisible (v2) | Checkbox shows a visible challenge; Invisible only challenges suspicious behavior |
| Site Key | (from Google) | Your reCAPTCHA site key |
| Secret Key | (from Google) | Your reCAPTCHA secret key |
| Max Tries | 3 | Failed attempts before triggering CAPTCHA |
| Allowed Robot Hits | 5 | Requests per 10 seconds before triggering |
| Bot White List | (User-Agent patterns) | Whitelist known good bots |
| Connection Limit | 100 | Per-IP connections triggering CAPTCHA |
- Save and perform a graceful restart.
Obtain reCAPTCHA Keys
Section titled “Obtain reCAPTCHA Keys”- Go to Google reCAPTCHA Admin
- Register a new site
- Choose reCAPTCHA v2 (Checkbox or Invisible)
- Add your domain(s)
- Copy the Site Key and Secret Key
Configure via Configuration File
Section titled “Configure via Configuration File”In httpd_config.conf:
security { reCAPTCHA { enabled 1 type 0 siteKey your_site_key_here secretKey your_secret_key_here maxTries 3 allowedRobotHits 5 botWhiteList Googlebot, Bingbot, baiduspider connLimit 100 regConnLimit 15000 }}Parameters
Section titled “Parameters”| Parameter | Values | Description |
|---|---|---|
enabled | 0 / 1 | Enable or disable |
type | 0 (checkbox) / 1 (invisible) | reCAPTCHA variant |
siteKey | string | Google reCAPTCHA site key |
secretKey | string | Google reCAPTCHA secret key |
maxTries | integer | Failed attempts before CAPTCHA |
allowedRobotHits | integer | Requests per 10 sec before triggering |
botWhiteList | comma-separated | User-Agent strings to whitelist |
connLimit | integer | Per-IP connections triggering CAPTCHA for unknown visitors |
regConnLimit | integer | Per-IP connections triggering CAPTCHA for returning/validated visitors |
Per-Virtual Host Override
Section titled “Per-Virtual Host Override”You can enable reCAPTCHA for specific virtual hosts only:
virtualhost example { ... security { reCAPTCHA { enabled 1 type 1 siteKey your_site_key_here secretKey your_secret_key_here } }}Bot Whitelist
Section titled “Bot Whitelist”Legitimate search engine bots should bypass reCAPTCHA. The botWhiteList setting accepts User-Agent substrings:
botWhiteList Googlebot, Bingbot, baiduspider, YandexBot, DuckDuckBot, SlurpOLS matches these strings case-insensitively against the User-Agent header.
Testing
Section titled “Testing”- Set
allowedRobotHitsto1temporarily to trigger reCAPTCHA quickly. - Open your site in a browser and refresh rapidly.
- You should see the reCAPTCHA challenge page.
- Solve it and verify that subsequent requests proceed normally.
- Reset
allowedRobotHitsto a production-appropriate value.
Troubleshooting
Section titled “Troubleshooting”reCAPTCHA page not appearing:
- Verify
enabledis set to1 - Check that
siteKeyandsecretKeyare correct - Ensure the domain is registered in the Google reCAPTCHA admin console
Legitimate users getting CAPTCHA too often:
- Increase
allowedRobotHitsandconnLimit - Check if users are behind a shared IP (NAT/VPN) and increase
regConnLimit
Search engine bots being challenged:
- Add the bot’s User-Agent string to
botWhiteList - Verify with
curl -A "Googlebot" https://example.comthat the bot bypasses the challenge