# Logstash Lumberjack uses insecure cipher

**URL:** <https://discuss.elastic.co/t/logstash-lumberjack-uses-insecure-cipher/86987>\
**Category:** Logstash\
**Created:** [May 24, 2017, 1:49pm UTC](https://discuss.elastic.co/t/logstash-lumberjack-uses-insecure-cipher/86987 "2017-05-24T13:49:45Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![fmhwong](https://avatars.discourse-cdn.com/v4/letter/f/f0a364/32.png) [@fmhwong](https://discuss.elastic.co/u/fmhwong)\
**Post date:** [May 24, 2017, 1:49pm UTC](https://discuss.elastic.co/t/logstash-lumberjack-uses-insecure-cipher/86987/1 "2017-05-24T13:49:45Z")

</div>

We use Lumberjack as input in Logstash 2.4. It looks like it requires 3DES cipher. If 3DES\_EDE\_CBC and DESede are disabled on the JRE running Logstash, Logstash could not be started. If 3DES\_EDE\_CBC and DESede are disabled on the client side, SSL connection cannot be established. However, 3DES cipher is now considered not secure. (See [http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2183](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2183))

Output from openssl:

SSL-Session:  
Protocol : TLSv1  
Cipher : EDH-RSA-DES-CBC3-SHA  
Session-ID: 592768FB4E13719858CA0D20595306342EE86B909764ACF68FE66923A735E97E  
Session-ID-ctx:  
Master-Key: C28BED0AD429B4750C9968CBD979FF5C11B2BC5E9E99AF5E2B6312756346825321AFA18DBB62A801560EC9D8FC1FBC17  
Key-Arg : None  
PSK identity: None  
PSK identity hint: None  
SRP username: None  
Start Time: 1495755002  
Timeout : 7200 (sec)  
Verify return code: 18 (self signed certificate)

Should I open an issue?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 21, 2017, 1:50pm UTC](https://discuss.elastic.co/t/logstash-lumberjack-uses-insecure-cipher/86987/2 "2017-06-21T13:50:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
