# SSL/TLS Diffie-Hellman Modulus \<= 1024 Bits (Logjam)

**URL:** <https://forum.search-guard.com/t/ssl-tls-diffie-hellman-modulus-1024-bits-logjam/2216>\
**Category:** Search Guard\
**Created:** [September 17, 2021, 11:46am UTC](https://forum.search-guard.com/t/ssl-tls-diffie-hellman-modulus-1024-bits-logjam/2216 "2021-09-17T11:46:18Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![rittickpaul](https://avatars.discourse-cdn.com/v4/letter/r/49beb7/32.png) [@rittickpaul](https://forum.search-guard.com/u/rittickpaul)\
**Post date:** [September 17, 2021, 11:46am UTC](https://forum.search-guard.com/t/ssl-tls-diffie-hellman-modulus-1024-bits-logjam/2216/1 "2021-09-17T11:46:18Z")

</div>

We are getting SSL/TLS Diffie-Hellman Modulus \<= 1024 Bits (Logjam) vulnerability error. By default search guard uses which cipher ?

---

<div class="post-metadata">

**Author:** ![nils](https://avatars.discourse-cdn.com/v4/letter/n/d6d6ee/32.png) [@nils](https://forum.search-guard.com/u/nils)\
**Post date:** [September 18, 2021, 8:23am UTC](https://forum.search-guard.com/t/ssl-tls-diffie-hellman-modulus-1024-bits-logjam/2216/2 "2021-09-18T08:23:49Z")

</div>

By default, this entirely depends on the Java version you are using to run Elasticsearch.

On which Java does your Elasticsearch run? Also, which version of Elasticsearch are you using? And which version of Search Guard?

---

<div class="post-metadata">

**Author:** ![rittickpaul](https://avatars.discourse-cdn.com/v4/letter/r/49beb7/32.png) [@rittickpaul](https://forum.search-guard.com/u/rittickpaul)\
**Post date:** [September 20, 2021, 5:37am UTC](https://forum.search-guard.com/t/ssl-tls-diffie-hellman-modulus-1024-bits-logjam/2216/3 "2021-09-20T05:37:44Z")

</div>

Java version is “JAVA\_RELEASE”: “11.0.7”.  
ES DB Version is 7.8.0

---

<div class="post-metadata">

**Author:** ![nils](https://avatars.discourse-cdn.com/v4/letter/n/d6d6ee/32.png) [@nils](https://forum.search-guard.com/u/nils)\
**Post date:** [September 22, 2021, 7:12am UTC](https://forum.search-guard.com/t/ssl-tls-diffie-hellman-modulus-1024-bits-logjam/2216/4 "2021-09-22T07:12:28Z")

</div>

If you have not configured anything else in Search Guard, or Java, Java 11 uses the following cypher suites by default:

[https://docs.oracle.com/en/java/javase/11/docs/specs/security/standard-names.html#jsse-cipher-suite-names](https://docs.oracle.com/en/java/javase/11/docs/specs/security/standard-names.html#jsse-cipher-suite-names)

Coming to the logjam issue: You can two options to address it:

To circumvent the problem, you have several options:

- Add the JVM parameter `-Djdk.tls.ephemeralDHKeySize=matched` to the file `config/jvm.options` on all ES nodes. See here for details: [https://docs.oracle.com/javase/8/docs/technotes/guides/security/jsse/JSSERefGuide.html#customizing\_dh\_keys](https://docs.oracle.com/javase/8/docs/technotes/guides/security/jsse/JSSERefGuide.html#customizing_dh_keys)

- Disable all affected ciphers. You can use the Search Guard options `searchguard.ssl.transport.enabled_ciphers` and `searchguard.ssl.http.enabled_ciphers` in `elasticsearch.yml` to configure the ciphers. See here [https://weakdh.org/sysadmin.html](https://weakdh.org/sysadmin.html) for “good” ciphers and general recommendations on the topic.

---

<div class="post-metadata">

**Author:** ![rittickpaul](https://avatars.discourse-cdn.com/v4/letter/r/49beb7/32.png) [@rittickpaul](https://forum.search-guard.com/u/rittickpaul)\
**Post date:** [September 27, 2021, 9:10am UTC](https://forum.search-guard.com/t/ssl-tls-diffie-hellman-modulus-1024-bits-logjam/2216/5 "2021-09-27T09:10:33Z")

</div>

@nils : Thank you for your support.

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [September 28, 2021, 3:30pm UTC](https://forum.search-guard.com/t/ssl-tls-diffie-hellman-modulus-1024-bits-logjam/2216/6 "2021-09-28T15:30:23Z")

</div>

You can also have a look at our docs for an example on how to configure ciphers and TLS protocols:

> **[Configuring TLS](https://docs.search-guard.com/latest/configuring-tls#expert-enabled-ciphers-and-protocols)**
>
> Search Guard TLS configuration settings for the REST and the transport layer. Extended security options for hostname verification and DNS lookups.

---

<div class="post-metadata">

**Author:** ![system](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/system/32/1870_2.png) [@system](https://forum.search-guard.com/u/system)\
**Post date:** [October 19, 2021, 3:30pm UTC](https://forum.search-guard.com/t/ssl-tls-diffie-hellman-modulus-1024-bits-logjam/2216/7 "2021-10-19T15:30:52Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
