# Problem encrypting logs to logstash with TCP input

**URL:** <https://discuss.elastic.co/t/problem-encrypting-logs-to-logstash-with-tcp-input/358546>\
**Category:** Logstash\
**Created:** [May 1, 2024, 8:20am UTC](https://discuss.elastic.co/t/problem-encrypting-logs-to-logstash-with-tcp-input/358546 "2024-05-01T08:20:29Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ITGUY](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/itguy/32/123545_2.png) [@ITGUY](https://discuss.elastic.co/u/ITGUY)\
**Post date:** [May 1, 2024, 8:20am UTC](https://discuss.elastic.co/t/problem-encrypting-logs-to-logstash-with-tcp-input/358546/1 "2024-05-01T08:20:29Z")

</div>

Hello,

I'm using logstash to receive logs from some equipments,  
I'm using these 3 input : UDP, TCP and beats.  
TCP will replace UDP to encrypt logs trafic but I have a problem with the TCP input :

```auto
tcp {
        type => "log-synology"
        host => "<DNS record to the host>"
        port => 5140
        ssl_enable => true
        ssl_certificate => "<fullchain.pem path>"
        ssl_key => "<privkey.pem path>"
    }

```

It's a signed Let's Encrypt Certificate and the encryption works well with the beats input.

Here is the error when receiving logs :  
[nioEventLoopGroup-2-1] tcp - null: closing due: io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: Insufficient buffer remaining for AEAD cipher fragment (2). Needs to be more than tag size (16)

Someone know that problem ?

Environnment :  
Ubuntu 22.04.3 LTS  
Elasticsearch version 8.13.2  
logstash version 8.13.2  
java 21.0.3 2024-04-16 LTS Java(TM) SE Runtime Environment (build 21.0.3+7-LTS-152) Java HotSpot(TM) 64-Bit Server VM (build 21.0.3+7-LTS-152, mixed mode, sharing)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 1, 2024, 3:28pm UTC](https://discuss.elastic.co/t/problem-encrypting-logs-to-logstash-with-tcp-input/358546/2 "2024-05-01T15:28:12Z")

</div>

> [@ITGUY](#):
>
> Insufficient buffer remaining for AEAD cipher fragment

If you Google that error message you will find it occurs in many products. A lot of folks think it is a synchronisation bug in the JDK.
