# Problem with cipher in beat input

**URL:** <https://discuss.elastic.co/t/problem-with-cipher-in-beat-input/67841>\
**Category:** Logstash\
**Created:** [December 2, 2016, 10:36am UTC](https://discuss.elastic.co/t/problem-with-cipher-in-beat-input/67841 "2016-12-02T10:36:58Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![clemh78](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clemh78/32/13554_2.png) [@clemh78](https://discuss.elastic.co/u/clemh78)\
**Post date:** [December 2, 2016, 10:36am UTC](https://discuss.elastic.co/t/problem-with-cipher-in-beat-input/67841/1 "2016-12-02T10:36:58Z")

</div>

Hello,

I have a problem with the beat input in logstash.  
When i starting logstash, the beat input has an error with the cipher.

This is the error in log :  
` Pipeline aborted due to error {:exception=>#LogStash::ConfigurationError: Cipher TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 is not available>, ...`

This my Logstash and java version :

```
logstash 5.0.2
jruby 1.7.25 (1.9.3p551) 2016-04-13 867cb81 on Java HotSpot(TM) 64-Bit Server VM 1.8.0_77-b02 +jit [linux-amd64]
java 1.8.0_77 (Oracle Corporation)
jvm Java HotSpot(TM) 64-Bit Server VM / 25.77-b02

```

This is my logstash config :

> input {  
> beats {  
> port =\> 5001  
> host =\> "X.X.X.X"  
> type =\> "log"  
> ssl =\> true  
> ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt  
> ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
> }  
> }

I do not understand where the problem comes from.

Do you have an idea?

Thanks.

---

<div class="post-metadata">

**Author:** ![githubcdr](https://avatars.discourse-cdn.com/v4/letter/g/13edae/32.png) [@githubcdr](https://discuss.elastic.co/u/githubcdr)\
**Post date:** [December 6, 2016, 9:53am UTC](https://discuss.elastic.co/t/problem-with-cipher-in-beat-input/67841/2 "2016-12-06T09:53:23Z")

</div>

I noticed the same on my host.

I added cipher\_suites =\> ["ECDHE-RSA-AES256-GCM-SHA384"] to logstash.conf but get the same error. (logstash 5.0.2)

> $ java -version  
> openjdk version "1.8.0\_111-internal"  
> OpenJDK Runtime Environment (build 1.8.0\_111-internal-alpine-r0-b14)  
> OpenJDK 64-Bit Server VM (build 25.111-b14, mixed mode)

---

<div class="post-metadata">

**Author:** ![tpoole](https://avatars.discourse-cdn.com/v4/letter/t/7ba0ec/32.png) [@tpoole](https://discuss.elastic.co/u/tpoole)\
**Post date:** [December 6, 2016, 6:30pm UTC](https://discuss.elastic.co/t/problem-with-cipher-in-beat-input/67841/3 "2016-12-06T18:30:04Z")

</div>

Receiving the same error:

```
Pipeline aborted due to error {:exception=>#<LogStash::ConfigurationError: Cipher `TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384` is not available>...

```

Versions:

```
logstash 5.0.2
logstash-input-beats 3.1.12
openjdk version "1.8.0_111"
OpenJDK Runtime Environment (build 1.8.0_111-b15)
OpenJDK 64-Bit Server VM (build 25.111-b15, mixed mode)

```

Tried lesser cipher suites and had the same error with those.

---

<div class="post-metadata">

**Author:** ![tpoole](https://avatars.discourse-cdn.com/v4/letter/t/7ba0ec/32.png) [@tpoole](https://discuss.elastic.co/u/tpoole)\
**Post date:** [December 12, 2016, 1:43pm UTC](https://discuss.elastic.co/t/problem-with-cipher-in-beat-input/67841/4 "2016-12-12T13:43:38Z")

</div>

Running logstash in debug mode, I get the following:

```
[DEBUG][io.netty.handler.ssl.OpenSsl] Failed to load netty-tcnative; OpenSslEngine will be unavailable, unless the application has already loaded the symbols by some other means. See http://netty.io/wiki/forked-tomcat-native.html for more information.
java.lang.IllegalArgumentException: Failed to load any of the given libraries: [netty-tcnative-linux-x86_64, netty-tcnative-linux-x86_64-fedora, netty-tcnative]

```

I can't seem to find any of those libraries for CentOS 7

---

<div class="post-metadata">

**Author:** ![jess\_571](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jess_571/32/13894_2.png) [@jess\_571](https://discuss.elastic.co/u/jess_571)\
**Post date:** [December 14, 2016, 9:52pm UTC](https://discuss.elastic.co/t/problem-with-cipher-in-beat-input/67841/5 "2016-12-14T21:52:00Z")

</div>

Had this issue with a system, and found the problem was /tmp was mounted with noexec option.

Removing the noexec option and rebooting fixed the issue on my system.

It looks like logstash puts a copy of the libnetty-tcnative dynamic library so in /tmp and tries to load it from there which the noexec option blocks. Loading code from /tmp seems like a security risks.

EDIT: the code putting the library in TMP is in netty which is used by logstash.

EDIT 2: maybe the tmp path can be made more sane in logstash's jvm.options file by adding a line  
-Dio.netty.native.workdir=some path

---

<div class="post-metadata">

**Author:** ![clemh78](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clemh78/32/13554_2.png) [@clemh78](https://discuss.elastic.co/u/clemh78)\
**Post date:** [December 15, 2016, 9:22am UTC](https://discuss.elastic.co/t/problem-with-cipher-in-beat-input/67841/6 "2016-12-15T09:22:11Z")

</div>

Indeed, the /tmp partition with noexec option is the problem.

I have not removed noexec option in /tmp partion for security reason. The solution of jvm.options file is the best solution.

I added the io.netty.native.workdir option in the jvm.options file and the SSL works good now.

Thank you for your help !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 12, 2017, 9:22am UTC](https://discuss.elastic.co/t/problem-with-cipher-in-beat-input/67841/7 "2017-01-12T09:22:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
