Conversation
Wraps ngx_http_lua_ffi_ssl_compress_certs(), which pre-compresses the
certificate chain set on the current connection so that TLS 1.3 sends it
as a CompressedCertificate message (RFC 8879). Without it a chain
installed by clear_certs() + set_cert() is always sent uncompressed,
even under ssl_certificate_compression on, because the pre-compressed
copies nginx made for the configured certificate go away with
clear_certs().
The algorithm is named ("zlib", "brotli", "zstd") or given as its RFC
8879 number, and is optional: leaving it out compresses with every
algorithm the OpenSSL library has, as nginx does for its own
certificates.
The binding is looked up through pcall so that ngx.ssl keeps loading
against an ngx_lua that does not have the C function yet.
u5surf
force-pushed
the
ssl-cert-compression
branch
from
September 25, 2026 16:00
4d6edd9 to
10947d2
Compare
u5surf
marked this pull request as ready for review
September 25, 2026 21:25
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The Lua side of openresty/lua-nginx-module#2530, which fixes openresty/lua-nginx-module#2516. That PR carries the root-cause analysis: a certificate installed with
clear_certs()+set_cert()is always sent uncompressed, even underssl_certificate_compression on;, because OpenSSL sends a TLS 1.3CompressedCertificateonly for a chain that was pre-compressed, andclear_certs()throws away the pre-compressed copies nginx made for the configured certificate.API
Returns
true, ornilplus an error string. It needs OpenSSL 3.2.0+, an OpenSSL built with the algorithm in question, andssl_certificate_compression on;(nginx 1.29.1+) for nginx to put the compressed certificate on the wire;lib/ngx/ssl.mddocuments all three and the error each missing one produces.The C binding is resolved through
pcall, aslib/ngx/pipe.luadoes, because indexingC.<symbol>resolves it eagerly: without the guard,ngx.sslas a whole would stop loading against an ngx_lua that does not carryngx_http_lua_ffi_ssl_compress_certs()yet. Unknown algorithm names are rejected in Lua, before any C call.Tests
t/ssl-cert-compression.tcovers the no-argument and named forms, an unknown name, and compressing before any certificate is set. The two blocks whose outcome depends on which algorithms OpenSSL was built with accept either result unlessTEST_NGINX_CERT_COMP_ALGS=1is set; the other two are deterministic.The API was exercised end to end against nginx 1.31.6 + OpenSSL 3.5.4 built with zlib:
ssl.compress_certs("zlib")returnedtrueandopenssl s_client -traceshowedCompressedCertificate, Length=1396where the same server without the call sentCertificate, Length=1566. The test file itself has not been run as a file:t::TestCorereads/proc/net/tcp, so the suite does not start on macOS — the same holds for the existingt/ssl.t— and CI is its first run.I hereby granted the copyright of the changes in this pull request
to the authors of this lua-resty-core project.