> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-cics-en/key-manager/introduction/subsystem-example-2.md).

# Subsystem example 2

We are entity 5555, and we have 2 remotes; one with cgo. 4444 and another 6666

* We create our own local RSA E subsystem (E-Propio-RSA-5555-0000) and generate the version 1 key pair for that subsystem (V1)
* We create the specific local E subsystem for Remote 4444 (E-Propio-RSA-5555-4444)
* We export the V1 keys of the E-Propio-RSA-5555-0000-RSA subsystem to E-Propio-RSA-5555-4444
* We create the specific local E subsystem for Remote 4444 (E-Propio-RSA-5555-6666)
* We export the V1 keys of the E-Propio-RSA-5555-0000-RSA subsystem to E-Propio-RSA-5555-6666
* We tell remote 4444 to create the remote E subsystem for us. It creates E-Ajeno-RSA-4444-5555
* We tell remote 6666 to create the remote E subsystem for us. It creates E-Ajeno-RSA-6666-5555
* We send remote 4444 the V1 public key of E-Propio-RSA-5555-4444. It incorporates V1 into its E-Ajeno-RSA-4444-5555.
* We send remote 6666 the V1 public key of E-Propio-RSA-5555-6666. It incorporates V1 into its E-Ajeno-RSA-6666-5555.
* Remote 4444 creates its X-Propio-4444-0000-RSA subsystem and generates the V1 key pair for that subsystem
* Remote 6666 creates its E-Propio-RSA-6666-0000 subsystem and generates the V1 key pair for that subsystem
* Remote 4444 creates the X-PROPIO-RSA-4444-5555 subsystem and exports the V1 keys to it from its X-PROPIO-RSA-4444-0000
* Remote 6666 creates the E-PROPIO-RSA-6666-5555 subsystem and exports the V1 keys to it from its E-PROPIO-RSA-6666-0000
* Remote 4444 tells us to register the X-AJENO-RSA-5555-4444 subsystem. It sends us its V1 public key from its X-PROPIO-RSA-4444-5555, which we store in the former.
* Remote 6666 tells us to register the E-AJENO-RSA-5555-6666 subsystem. It sends us its V1 public key from its E-Propio-RSA-6666-5555, which we store in the former.
* Remote 4444 generates another V2 key pair in its X-PROPIO-RSA-4444-0000 subsystem
* Remote 4444 exports V2 to its X-PROPIO-RSA-4444-5555 subsystem from its X-PROPIO-RSA-4444-0000
* Remote 4444 sends us its V2 public key, which we will incorporate into X-AJENO-5555-4444-RSA. This key will become active on our end instead of V1.
* Remote 4444 sends us its V2 public key from its X-PROPIO-RSA-4444-5555, which we store in X-AJENO-5555-4444-RSA. It automatically becomes ACTIVE.
* In turn, on 4444, V2 will become active in X-PROPIO-RSA-4444-5555 instead of V1

In this situation, the sessions would have been encoded:

* For us, in the sessions with 4444 we will have LOCAL SUBSYSTEM=E, REMOTE SUBSYSTEM=X. The E means we will use the local subsystem E's V1 private key to decrypt data. The X means we will use the remote subsystem X's V2 public key to encrypt.
* For us, in the sessions with 6666 we will have LOCAL SUBSYSTEM=E, REMOTE SUBSYSTM=E. The first E means we will use the local subsystem E's V1 private key to decrypt data. The second E means we will use the remote subsystem E's V1 public key to encrypt.
* Remote 4444, in its sessions with us, will have LOCAL SUBSYSTEM=X, REMOTE SUBSYSTEM=E. The X means it will use the local subsystem X's V2 private key to decrypt data. The E means it will use our remote public V1 of subsystem E to encrypt data.
* Remote 6666, in its sessions with us, will have LOCAL SUBSYSTEM=E, REMOTE SUBSYSTEM=E. The first E means it will use the local subsystem E's V1 private key to decrypt data. The second E means it will use the remote subsystem E's V1 public key to encrypt data.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-cics-en/key-manager/introduction/subsystem-example-2.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
