# HTTPS configuration

Fetch HTTPS resources on nginx, Apache and IIS with mod_pagespeed 2.1: FetchHttps with certificate checks, MapOriginDomain to HTTP, or LoadFromFile.

Canonical URL: https://modpagespeed.com/docs/https-configuration/

mod_pagespeed fetches resources (CSS, JavaScript, images) from your site to optimize them. When your site serves pages over HTTPS, mod_pagespeed must be able to make HTTPS connections to fetch those resources.

Three approaches are available, from simplest to most flexible.

## Approach 1: FetchHttps

The simplest option. mod_pagespeed fetches HTTPS resources directly using its built-in HTTP client. `FetchHttps` defaults to `enable`, so direct HTTPS fetching works out of the box; set it explicitly if you need one of the other keywords (`disable`, `allow_self_signed`, `allow_unknown_certificate_authority`, `allow_certificate_not_yet_valid`).

<!-- platform: nginx -->

**nginx**

```nginx
pagespeed FetchHttps enable;
```

<!-- platform: apache -->

**Apache**

```apache
ModPagespeedFetchHttps enable
```

<!-- platform: iis -->

**IIS**

```text
pagespeed FetchHttps enable
```

The IIS module uses WinHTTP for HTTPS fetching. SSL certificate verification uses the Windows certificate store automatically — no `SslCertDirectory` or `SslCertFile` directives are needed.

By default, mod_pagespeed verifies SSL certificates. If certificate verification fails, configure the certificate directory or file explicitly:

<!-- platform: nginx -->

**nginx**

```nginx
pagespeed SslCertDirectory /etc/ssl/certs;
pagespeed SslCertFile /etc/ssl/certs/ca-certificates.crt;
```

<!-- platform: apache -->

**Apache**

```apache
ModPagespeedSslCertDirectory /etc/ssl/certs
ModPagespeedSslCertFile /etc/ssl/certs/ca-certificates.crt
```

Do not disable certificate verification in production. For development environments with self-signed certificates, set the certificate directory to the location of your self-signed CA.

On nginx, since v1.15.0+r18 the native fetcher (`pagespeed UseNativeFetcher on;` in the `http` block) also fetches HTTPS resources directly, using nginx's own event loop and TLS stack; `NativeFetcherMaxKeepaliveRequests` (default 100) caps requests per keepalive connection.

## Approach 2: MapOriginDomain with HTTP backend

If mod_pagespeed runs on the same server as the origin, use [`MapOriginDomain`](https://modpagespeed.com/docs/domain-configuration/) to map the HTTPS domain to a local HTTP backend:

<!-- platform: nginx -->

**nginx**

```nginx
pagespeed MapOriginDomain "http://localhost" "https://www.example.com";
```

<!-- platform: apache -->

**Apache**

```apache
ModPagespeedMapOriginDomain "http://localhost" "https://www.example.com"
```

<!-- platform: iis -->

**IIS**

```text
pagespeed MapOriginDomain "http://localhost" "https://www.example.com"
```

This avoids HTTPS fetch overhead entirely. mod_pagespeed fetches from `http://localhost` instead of making an HTTPS connection to the public domain. The rewritten resource URLs still use `https://www.example.com` as seen by the browser.

## Approach 3: LoadFromFile

Load resources directly from the filesystem, bypassing network fetches altogether:

<!-- platform: nginx -->

**nginx**

```nginx
pagespeed LoadFromFile "https://www.example.com/static/" "/var/www/static/";
```

<!-- platform: apache -->

**Apache**

```apache
ModPagespeedLoadFromFile "https://www.example.com/static/" "/var/www/static/"
```

<!-- platform: iis -->

**IIS**

```text
pagespeed LoadFromFile "https://www.example.com/static/" "C:\inetpub\wwwroot\static\"
```

Note the Windows-style path. The module converts backslashes to forward slashes internally.

No network fetch occurs. mod_pagespeed reads the files from disk. This is the fastest option for static assets that are available on the local filesystem.

## Mixed content

mod_pagespeed rewrites resource URLs to match the scheme of the page. Pages served over HTTPS will have their optimized resources served over HTTPS as well. This prevents mixed-content warnings in browsers.

## See also

- [Domain configuration](https://modpagespeed.com/docs/domain-configuration/) — domain authorization and mapping
- [Configuration](https://modpagespeed.com/docs/configuration/) — general configuration reference
