> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-cics-en/key-manager/introduction/subsystem-example-3.md).

# Subsystem example 3

In the following example, a case is shown in which several keys have already been exchanged by the two entities (V1, V2, V4). In addition, it is shown that key V3 was generated, but was not exported at the time to that remote B (6789). State changes are shown in bold.&#x20;

<table data-header-hidden><thead><tr><th width="153.6790771484375" valign="top"></th><th width="151.7037353515625" valign="top"></th><th valign="top"></th><th valign="top"></th><th valign="top"></th><th width="154.666748046875" valign="top"></th><th width="169.4814453125" valign="top"></th></tr></thead><tbody><tr><td valign="top"><p>Subsystem</p><p>Entity A=1234</p></td><td valign="top">Key status</td><td valign="top">Operation</td><td valign="top">Network</td><td valign="top">Operation</td><td valign="top">Key status</td><td valign="top"><p>Subsystem</p><p>Entity B 6789</p></td></tr><tr><td valign="top"><p>Subsystem X</p><p>Own RSA Type</p><p>Local code 1234</p><p>Remote code 0000</p></td><td valign="top"><p>V2 is lost</p><p>V3-OPERATIONAL</p><p>V4-OPERATIONAL</p><p>V5-ACTIVE</p></td><td valign="top">Generate key (V5)</td><td valign="top"> </td><td valign="top"> </td><td valign="top"><p>(already existed)</p><p>V1-OPERATIONAL</p><p>V2-OPERATIONAL</p><p>V4-ACTIVE</p></td><td valign="top"><p>Subsystem X</p><p>External RSA Type</p><p>Local code 6789</p><p>Remote code 1234</p></td></tr><tr><td valign="top"><p>Subsystem X</p><p>Own RSA Type</p><p>Local code 1234</p><p>Remote code 6789</p></td><td valign="top"><p>V1 is lost</p><p>V2-OPERATIONAL</p><p>V4-ACTIVE</p><p>V5-GENERATED</p></td><td valign="top">Export V5 key from the previous subsystem</td><td valign="top"> </td><td valign="top"> </td><td valign="top"><p>(already existed)</p><p>V1-OPERATIONAL</p><p>V2-OPERATIONAL</p><p>V4-ACTIVE</p></td><td valign="top"><p>Subsystem X</p><p>External RSA Type</p><p>Local code 6789</p><p>Remote code 1234</p></td></tr><tr><td valign="top"><p>Subsystem X</p><p>Own RSA Type</p><p>Local code 1234</p><p>Remote code 6789</p></td><td valign="top"><p>V2-OPERATIONAL</p><p>V4-ACTIVE</p><p>V5-GENERATED</p></td><td valign="top"><p>Send V5 key</p><p>Before issuance</p></td><td valign="top">A issues</td><td valign="top">Receives key</td><td valign="top"> </td><td valign="top"> </td></tr><tr><td valign="top"><p>Subsystem X</p><p>Own RSA Type</p><p>Local code 1234</p><p>Remote code 6789</p></td><td valign="top"><p>V2-OPERATIONAL</p><p>V4-ACTIVE</p><p>V5-SENT</p></td><td valign="top">After issuance</td><td valign="top"> </td><td valign="top">After reception</td><td valign="top"><p>V1-is lost</p><p>V2-OPERATIONAL</p><p>V4-ACTIVE</p><p>V5-RECEIVED</p></td><td valign="top"><p>Subsystem X</p><p>External RSA Type</p><p>Local code 6789</p><p>Remote code 1234</p></td></tr><tr><td valign="top"> </td><td valign="top"> </td><td valign="top">Receives confirmation file</td><td valign="top">B issues</td><td valign="top">Before issuance Issues confirmation</td><td valign="top"><p>V2-OPERATIONAL</p><p>V4-ACTIVE</p><p>V5-RECEIVED</p></td><td valign="top"><p>Subsystem X</p><p>External RSA Type</p><p>Local code 6789</p><p>Remote code 1234</p></td></tr><tr><td valign="top"><p>Subsystem X</p><p>Own RSA Type</p><p>Local code 1234</p><p>Remote code 6789</p></td><td valign="top"><p>V2-OPERATIONAL</p><p>V4-OPERATIONAL</p><p>V5-ACTIVE</p></td><td valign="top">After reception</td><td valign="top"> </td><td valign="top">After transmission</td><td valign="top"><p>V2-OPERATIONAL</p><p>V4-OPERATIONAL</p><p>V5-ACTIVE</p></td><td valign="top"><p>Subsystem X</p><p>External RSA Type</p><p>Local code 6789</p><p>Remote code 1234</p></td></tr></tbody></table>

Until the last step, all the sessions that passed between both ends in which subsystem X was indicated (local in A and remote in B) worked with key V4. From the moment V5 is active at both ends, they start working with this last one.

Note that initially V1, V2, and V4 can be activated manually at both ends. Later, V1 is lost in entity A (it can no longer operate with V1). Until V5 is active at both ends, there are only 2 key sets and not 3, with which to operate.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-cics-en/key-manager/introduction/subsystem-example-3.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
