# Problem with cipher not available

**URL:** <https://discuss.elastic.co/t/problem-with-cipher-not-available/117987>\
**Category:** Logstash\
**Created:** [February 1, 2018, 9:43am UTC](https://discuss.elastic.co/t/problem-with-cipher-not-available/117987 "2018-02-01T09:43:08Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![iDavico](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/idavico/32/79703_2.png) [@iDavico](https://discuss.elastic.co/u/iDavico)\
**Post date:** [February 1, 2018, 9:43am UTC](https://discuss.elastic.co/t/problem-with-cipher-not-available/117987/1 "2018-02-01T09:43:08Z")

</div>

Hi,

I have a problem with logstash 5.3.3. When i start Logstash, the folowing error is generated:

Pipeline aborted due to error {:exception=\>#\<LogStash::ConfigurationError: Cipher `TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384` is not available\>

I'v already tried the solution of [Problem with cipher in beat input](https://discuss.elastic.co/t/problem-with-cipher-in-beat-input/67841/5) but  
it does not work for me.

This is my logstash config:

input {  
beats {  
type =\> beats  
port =\> 5044  
ssl =\> true  
ssl\_certificate\_authorities =\> [\*\*\*]  
ssl\_certificate =\> \*\*\*  
ssl\_key =\> \*\*\*  
ssl\_verify\_mode =\> "force\_peer"

```
     }

```

}

Do you have an idea?

Thank you for your help !

---

<div class="post-metadata">

**Author:** ![TimoHar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timohar/32/27257_2.png) [@TimoHar](https://discuss.elastic.co/u/TimoHar)\
**Post date:** [February 2, 2018, 2:09pm UTC](https://discuss.elastic.co/t/problem-with-cipher-not-available/117987/2 "2018-02-02T14:09:56Z")

</div>

Hello;

Have you tried debug logging? If yes,

1. Look through those debug logs for "-Dio.netty.tmpdir" to confirm what directory netty is using.
2. Look for "netty-tcnative not in the classpath" to see if it is the same issue as [Problem with cipher in beat input](https://discuss.elastic.co/t/problem-with-cipher-in-beat-input/67841/5) (on 5.x) or [Beats plugin will not start with "cipher not found"](https://discuss.elastic.co/t/beats-plugin-will-not-start-with-cipher-not-found/117902) (on 6.x)

BTW, I don't have a solution; the second issue (on 6.x) is mine, but no responses yet.

Thanks!

---

<div class="post-metadata">

**Author:** ![TimoHar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timohar/32/27257_2.png) [@TimoHar](https://discuss.elastic.co/u/TimoHar)\
**Post date:** [February 2, 2018, 7:47pm UTC](https://discuss.elastic.co/t/problem-with-cipher-not-available/117987/3 "2018-02-02T19:47:00Z")

</div>

FWIW, I did a bare-metal rebuild on the logstash server, and the issue is gone...

---

<div class="post-metadata">

**Author:** ![iDavico](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/idavico/32/79703_2.png) [@iDavico](https://discuss.elastic.co/u/iDavico)\
**Post date:** [February 4, 2018, 7:33pm UTC](https://discuss.elastic.co/t/problem-with-cipher-not-available/117987/4 "2018-02-04T19:33:35Z")

</div>

> [@TimoHar](#):
>
> bare-metal rebuild

so for you, what was the problem?

---

<div class="post-metadata">

**Author:** ![TimoHar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timohar/32/27257_2.png) [@TimoHar](https://discuss.elastic.co/u/TimoHar)\
**Post date:** [February 5, 2018, 11:41am UTC](https://discuss.elastic.co/t/problem-with-cipher-not-available/117987/5 "2018-02-05T11:41:11Z")

</div>

Unfortunately, I have no idea. I was out of ideas, and needed the multiple pipelines of 6.x so I tried the rebuild and it worked.

Sorry I can't be of more assistance.

---

<div class="post-metadata">

**Author:** ![nick-george](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nick-george/32/23318_2.png) [@nick-george](https://discuss.elastic.co/u/nick-george)\
**Post date:** [February 19, 2018, 3:41am UTC](https://discuss.elastic.co/t/problem-with-cipher-not-available/117987/6 "2018-02-19T03:41:28Z")

</div>

I'm having the same issue with Logstash v6.2.1 on OL7 (same as RHEL7 & Centos7). I've recently updated from v5.6.2. I've also recently switched from the Oracle JRE to OpenJDK (headless).

```
openjdk version "1.8.0_161"
OpenJDK Runtime Environment (build 1.8.0_161-b14)
OpenJDK 64-Bit Server VM (build 25.161-b14, mixed mode)

```

I've noticed the following entry in the Logstash debug logs:

```
[DEBUG][io.netty.handler.ssl.OpenSsl] netty-tcnative not in the classpath; OpenSslEngine will be unavailable.

```

Is it normal for Logstash to output that line? Is my java install broken?? (EDIT: I just removed and re-installed java, and LS is still broken)

My netty tmp dir is /tmp

```
[DEBUG][io.netty.util.internal.PlatformDependent] -Dio.netty.tmpdir: /tmp (java.io.tmpdir)

```

/tmp is the same volume as /, so execution of code IS allowed.

```
/dev/mapper/ol-root on / type xfs (rw,relatime,seclabel,attr2,inode64,noquota)

```

Also, running inotifywait against /tmp shows ZERO activity in there while logstash is starting up. Hmmm..

I have a feeling that completely rebuilding the box would fix the issue, but I'm keen to fix it rather than admit defeat. 🙂

---

<div class="post-metadata">

**Author:** ![nick-george](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nick-george/32/23318_2.png) [@nick-george](https://discuss.elastic.co/u/nick-george)\
**Post date:** [February 19, 2018, 11:29pm UTC](https://discuss.elastic.co/t/problem-with-cipher-not-available/117987/7 "2018-02-19T23:29:37Z")

</div>

I have completely rebuilt my system and am running into the same issue. ☹

I can confirm that it's version 5.0.6 and above of the logstash-input-beats plugin that has introduced this issue. If you remove the plugin and re-install the older version, things will work. I suggest this as a temporary workaround.

E.g, as root run the following

```
systemctl stop logstash
mv /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-input-beats-5.0.6-java /tmp
sudo -u logstash /usr/share/logstash/bin/logstash-plugin install --version 5.0.5 logstash-input-beats
systemctl start logstash

```

Now all should be good.

I can see that version 5.0.6 of the input included a more recent version of netty [https://github.com/logstash-plugins/logstash-input-beats/blob/v5.0.6/CHANGELOG.md](https://github.com/logstash-plugins/logstash-input-beats/blob/v5.0.6/CHANGELOG.md).

I'm guessing it's this commit that has introduced the issue. [https://github.com/logstash-plugins/logstash-input-beats/commit/9911624aac5ca73df1b7bdc5f93668b120d5086e](https://github.com/logstash-plugins/logstash-input-beats/commit/9911624aac5ca73df1b7bdc5f93668b120d5086e)

Will investigate further.

---

<div class="post-metadata">

**Author:** ![nick-george](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nick-george/32/23318_2.png) [@nick-george](https://discuss.elastic.co/u/nick-george)\
**Post date:** [February 24, 2018, 2:46am UTC](https://discuss.elastic.co/t/problem-with-cipher-not-available/117987/8 "2018-02-24T02:46:55Z")

</div>

Spent too long on this without any luck.. going to stick with Logstash 6.1.1 (which uses the older version of netty-tcnative) until a new version comes out that I can test with.

Cheers,  
Nick

---

<div class="post-metadata">

**Author:** ![raffis](https://avatars.discourse-cdn.com/v4/letter/r/3be4f8/32.png) [@raffis](https://discuss.elastic.co/u/raffis)\
**Post date:** [February 28, 2018, 3:39pm UTC](https://discuss.elastic.co/t/problem-with-cipher-not-available/117987/9 "2018-02-28T15:39:37Z")

</div>

Also waisted hours with this problem after upgrading from 5.5.x to 6.2.2, tried openjdk, oracle java (also with Java Cryptography Extension (JCE) Unlimited Strength), different jvm options, modified cipher list in beats input... still got this error. Only thing helped out was downgrading logstash to 1:6.1.1-1

---

<div class="post-metadata">

**Author:** ![involuntary-pretzel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/involuntary-pretzel/32/45404_2.png) [@involuntary-pretzel](https://discuss.elastic.co/u/involuntary-pretzel)\
**Post date:** [March 2, 2018, 1:18am UTC](https://discuss.elastic.co/t/problem-with-cipher-not-available/117987/10 "2018-03-02T01:18:22Z")

</div>

Thank you, downgrading logstash-input-beats to 5.0.5 got me back up and running.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2018, 1:18am UTC](https://discuss.elastic.co/t/problem-with-cipher-not-available/117987/11 "2018-03-30T01:18:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
