Fixed a NodeJS websocket backend configuration bug.
Fixed a delayed server response bug with HTTP/2.
Added "Cache-Control: no-cache" to reCAPTCHA verification page to disallow CDN/proxy cache.
Fixed reCAPTCHA triggering for the first access of an allowed robot.
Fixed a symbolic link attack in directory auto index script.
Added ability to configure static/dynamic request per second limit for Apache vhost.
Added strict suEXEC and ownership checking on scripts.
CGI, Fast CGI and servlet engine run in standalone processes,the reliability of the Web server is not affected by third party software.
Runs completely in the user space, OS reliability is not affected.
Graceful shutdown, all requests in process will be completed.
Watch dog and Instant recovery maximizes up-time.
Zero downtime maintanance (include reconfiguration, software upgrade).
External application firewall for dynamic content.
Comprehensive protection for static files.
Comprehensive IP level connection accounting.
IP level throttling (Bandwidth and Request Rate).
Access Control at server, virtual host and directory (context) level.
High performance Secure HTTP (HTTPS): supports SSLv2, SSLv3 and TLSv1.
With chroot jail, IP level bandwidth throttling, connection accounting, strict HTTP request checking, and URL context filtering, DoS effects are minimized and the application backend is properly fenced away from the HTTP request layer reducing vulnerability. LiteSpeed Web server is desgined to be a secure Web server. It is less vulnerable when facing various attacks.
Runtime: 300MB and up, swapping space depends on usage.LiteSpeed Web Server is a high-performance, secure and easy-to-use Web server, which can handle thousands of concurrent connections with a small memory footprint.
Minimum system requirements ¶ Operating System ¶ It can handle thousands of concurrent connections with a small memory footprint, and can thwart incoming attacks with ease. LiteSpeed Web Server (LSWS) is a high performance, secure, easy-to-use web server, and can be used as a drop-in replacement for an Apache web server.