#1068797 modsecurity-crs: IncludeOptional in file owasp-crs.load is incompatible with nginx

Package:
modsecurity-crs
Source:
modsecurity-crs
Submitter:
Salil Sayed
Date:
2026-10-07 07:45:01 UTC
Severity:
normal
Tags:
#1068797#5
Date:
2024-04-11 09:24:26 UTC
From:
To:
Dear Maintainer,

I configured modsecurity for nginx using the available packages in the bookworm
repository; namely, libmodsecurity3 and libnginx-mod-http-modsecurity. It
worked like charm except with this package modsecuirty-crs. The two
IncludeOptional directives in the file owasp-crs.load had to be changed to
Include since nginx does not support IncludeOptional. This simply worked but by
editing a file that the user is not supposed to edit and is likely to be
overwritten on update.

I believe there may be a way to make the whole modsecurity implementation to
work out of the box for nginx as well by simply changing these two
IncludeOptional directives to Include. Both of them include files that are
already provided by the package hence IncludeOptional is redundant.

Thanks,
Salil

#1068797#10
Date:
2024-04-15 16:48:04 UTC
From:
To:
Hi Salil,

Thanks for reporting.

Unfortunately this is a known bug of libmodsecurity3 + Nginx: this
installation does not support the `IncludeOptional` directive.

The workaround is that you change it manually.

Note, that CRS team suggest (since CRS 4) to use the `Include` form in all
cases - see documentation:
https://coreruleset.org/docs/deployment/extended_install/#includes-for-nginx


Regards,

a.

#1068797#15
Date:
2024-04-15 16:48:04 UTC
From:
To:
Hi Salil,

Thanks for reporting.

Unfortunately this is a known bug of libmodsecurity3 + Nginx: this
installation does not support the `IncludeOptional` directive.

The workaround is that you change it manually.

Note, that CRS team suggest (since CRS 4) to use the `Include` form in all
cases - see documentation:
https://coreruleset.org/docs/deployment/extended_install/#includes-for-nginx


Regards,

a.

#1068797#20
Date:
2024-04-20 12:05:26 UTC
From:
To:
Thank you Ervin,

I was wondering about the possibility of a trigger that would change the
IncludeOptional to Include if the debian machine is running nginx.

Best regards,

Salil

#1068797#25
Date:
2024-04-20 12:05:26 UTC
From:
To:
Thank you Ervin,

I was wondering about the possibility of a trigger that would change the
IncludeOptional to Include if the debian machine is running nginx.

Best regards,

Salil

#1068797#30
Date:
2026-10-07 07:42:49 UTC
From:
To:
Attached is a patch changing both IncludeOptional directives in
debian/owasp-crs.load to Include, matching what you (Ervin) already
confirmed in this thread is upstream's own recommendation since CRS v4.

Verified before making the change, rather than assuming the reporter's
claim: both referenced files (REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
and RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf) are unconditionally
installed by debian/rules (the .conf.example -> .conf move happens
unconditionally, not behind any flag), so Include is safe for the
default, unmodified case.

One tradeoff worth being explicit about: debian/README.Debian documents
these two files as living under /etc/modsecurity/crs/ specifically
because they're meant to be user-editable, which makes them very likely
dpkg conffiles. If an existing Apache user has deliberately deleted one
of these conffiles as part of local customization, this change turns
that into a config load failure instead of a silent skip. Given nginx
cannot use IncludeOptional at all today -- meaning nginx users are
currently forced to hand-patch this same conffile on every single
upgrade just to get CRS working -- and upstream's own stated direction
is Include for all cases since v4, this seems like the right tradeoff,
but flagging it rather than glossing over it.

Patch applies cleanly against a fresh pristine 3.3.9-1 source tree.

Changes:
- debian/owasp-crs.load (two directives changed)
- debian/changelog