Enabling HTTP/2 in Apache HTTP Server with mod_http2
Learn how to enable HTTP/2 in Apache by loading mod_http2, adding a Protocols directive inside a TLS virtual host, and verifying the negotiation with curl or browser tools.
21 Jul 2026, 00:21 UTC

Quick answer
\nTo activate HTTP/2 on an Apache server, load the mod_http2 module, add a Protocols directive inside a TLS‑enabled virtual host, and restart the service. Clients that support HTTP/2 will negotiate it during the TLS handshake; others fall back to HTTP/1.1.
How it works
\nThe mod_http2 module implements the HTTP/2 protocol. It registers itself with Apache’s core and inspects the TLS ALPN extension during the handshake. If the client advertises support for h2 (the HTTP/2 identifier over TLS) and the server’s Protocols list includes it, the connection is upgraded to HTTP/2; otherwise Apache continues with HTTP/1.1.
Worked configuration
\nThe following snippet shows the minimal changes for a typical site served over HTTPS on port 443. Place it in your virtual‑host file (e.g., /etc/apache2/sites-available/example.com.conf).
<VirtualHost *:443>\n ServerName example.com\n SSLEngine on\n SSLCertificateFile /etc/ssl/certs/example.crt\n SSLCertificateKeyFile /etc/ssl/private/example.key\n # Enable HTTP/2 while keeping HTTP/1.1 as fallback\n Protocols h2 http/1.1\n</VirtualHost>\n\nBefore the virtual host can use the module, it must be loaded. On most distributions the module is shipped but disabled by default.
\nEnabling the module
\n- \n
- Open a root shell or use
sudo. \n - Enable the module:\n
\n# Debian/Ubuntu\nsudo a2enmod http2\n# RHEL/CentOS/Fedora (if package installed)\nsudo systemctl reload httpd\n - Restart Apache to apply the new configuration:\n
\nsudo systemctl restart apache2 # Debian/Ubuntu\nsudo systemctl restart httpd # RHEL/CentOS\n
Where to run: Any terminal with access to the server; you need root or sudo privileges to manage Apache modules and services.
\nExpected check: After restart, run sudo apachectl -M (or httpd -M) and verify that http2_module appears in the list.
Verification
\nYou can confirm that HTTP/2 is active from the client side.
\nUsing curl
\ncurl -I --http2 https://example.com\n\nLook for a response header similar to:
\nHTTP/2 200 \n\nIf the server falls back to HTTP/1.1, you will see HTTP/1.1 200 OK instead.
Browser developer tools
\nOpen the Network tab, reload the page, and check the Protocol column for h2. Most modern browsers show this information when the developer tools are open.
Limits and common mistakes
\nProtocol negotiation requires TLS with ALPN
\nHTTP/2 over cleartext (the so‑called “h2c” mode) is not implemented in mod_http2. The server must listen on a TLS port (usually 443) and the OpenSSL library must support the Application-Layer Protocol Negotiation (ALPN) extension. OpenSSL 1.0.2 or later is required; older versions will cause the handshake to abort and the connection to fall back to HTTP/1.1.
Missing or misplaced Protocols directive
\nIf the directive is omitted, Apache will never advertise HTTP/2, even if the module is loaded. Placing it inside a <VirtualHost *:80> block (non‑TLS) also has no effect because the module only activates on TLS connections.
Reverse proxy in front of Apache
\nIf clients terminate TLS at a reverse proxy (e.g., NGINX, HAProxy) that does not speak HTTP/2 to the backend, the proxy will downgrade to HTTP/1.1 when forwarding requests to Apache. In that case enabling HTTP/2 on Apache alone yields no benefit; you must configure the proxy to support HTTP/2 as well.
\nDuplicate virtual‑host definitions
\nAccidentally defining two VirtualHost *:443 blocks for the same ServerName can cause Apache to load the first matching block only. If the first block lacks the Protocols line, HTTP/2 will be disabled despite its presence in the second block. Use apachectl -S to list loaded virtual hosts and verify which one is active.
Practical way to check the result
\nAfter restarting Apache, run the following command sequence to be sure the module is loaded, the virtual host is using it, and a client can negotiate HTTP/2:
\n# 1. Verify module load\nsudo apachectl -M | grep http2_module\n# 2. Show active virtual hosts for port 443\nsudo apachectl -S | grep ':443'\n# 3. Test negotiation with curl\ncurl -I --http2 https://example.com 2>/dev/null | head -1\n\nIf the first line shows http2_module (shared), the second line lists your virtual host, and the third line begins with HTTP/2 200, HTTP/2 is successfully enabled.
Rollback considerations
\nEnabling mod_http2 and adding the Protocols directive does not alter persistent data; it only changes how Apache handles incoming connections. To revert, simply remove or comment out the Protocols line, disable the module with sudo a2dismod http2, and restart Apache. No database or file‑system changes are involved, so rollback is safe and immediate.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.