> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-cics-en/key-manager/operation-example/mass-export-of-rsa-keys.-update-of-the-rsa-signature-subsystem.md).

# Mass export of RSA keys. Update of the RSA signature subsystem

In option 6.2, if there is a key in the ACTIVE state, it is exported to all the remotes of that subsystem that did not have keys in flight.

On the other hand, previously, when a subsystem was created and keys were sent for the first time to a remote, these were sent in clear text and activated automatically. Subsequently, if an entity generates new keys, in order to export them to that remote of a given subsystem, the first thing it must do is enter option 3 (own), and modify the field SUBSYSTEM RSA TO SIGN, including in it a subsystem that has active keys, previously exchanged, so as to send the new keys signed under those. In the latest version, this is done automatically, thus avoiding the user having to access through modification.

Example. If we have the following file:&#x20;

<table data-header-hidden><thead><tr><th width="64.7901611328125" valign="top"></th><th width="65.77777099609375" valign="top"></th><th width="75.65435791015625" valign="top"></th><th width="66.765380859375" valign="top"></th><th width="67.753173828125" valign="top"></th><th width="89.4815673828125" valign="top"></th><th width="108.2469482421875" valign="top"></th><th width="106.271728515625" valign="top"></th><th width="108.2470703125" valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top">Type</td><td valign="top">Own</td><td valign="top">Local</td><td valign="top">Subsys.</td><td valign="top">Rem</td><td valign="top">Sign.sub</td><td valign="top">Vers(1)-Stat</td><td valign="top">Vers(1)-Stat</td><td valign="top">Vers(3)-Stat</td><td valign="top">Serv.app</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">----</td><td valign="top"> </td><td valign="top">V11-E04</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0001</td><td valign="top"> </td><td valign="top"> </td><td valign="top"> </td><td valign="top"> </td><td valign="top">spaces</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0002</td><td valign="top"> </td><td valign="top">V01-E01</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0003</td><td valign="top"> </td><td valign="top">V01-E02</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0004</td><td valign="top"> </td><td valign="top">V11-E01</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0005</td><td valign="top"> </td><td valign="top">V11-E02</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0006</td><td valign="top"> </td><td valign="top">V11-E03</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0007</td><td valign="top"> </td><td valign="top">V11-E04</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0008</td><td valign="top">E</td><td valign="top">V01-E03</td><td valign="top">V11-E05</td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">E</td><td valign="top">….</td><td valign="top"> </td><td valign="top">V01-E04</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">E</td><td valign="top">0008</td><td valign="top"> </td><td valign="top">V01-E01</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0009</td><td valign="top">F</td><td valign="top">V01-E04</td><td valign="top">V11-E05</td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">F</td><td valign="top">….</td><td valign="top"> </td><td valign="top">V01-E02</td><td valign="top"> </td><td valign="top"> </td><td valign="top">Xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">F</td><td valign="top">0009</td><td valign="top"> </td><td valign="top">V01-E02</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0010</td><td valign="top"> </td><td valign="top"> </td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">E</td><td valign="top">0010</td><td valign="top"> </td><td valign="top">V01-E04</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0011</td><td valign="top"> </td><td valign="top"> </td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">E</td><td valign="top">0011</td><td valign="top"> </td><td valign="top">V01-E04</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0012</td><td valign="top"> </td><td valign="top">V01-E04</td><td valign="top">V11-E05</td><td valign="top">V03-E03</td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0013</td><td valign="top">D</td><td valign="top">V11-E05</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">E</td><td valign="top">0013</td><td valign="top"> </td><td valign="top">V01-E03</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0014</td><td valign="top">E</td><td valign="top">V10-E05</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0015</td><td valign="top">J</td><td valign="top">V11-E05</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">J</td><td valign="top">….</td><td valign="top"> </td><td valign="top"> </td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">K</td><td valign="top">….</td><td valign="top"> </td><td valign="top">V01-E05</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">K</td><td valign="top">0015</td><td valign="top"> </td><td valign="top">V11-E03</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0016</td><td valign="top">D</td><td valign="top">V11-E05</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">E</td><td valign="top">0016</td><td valign="top"> </td><td valign="top">V01-E03</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">F</td><td valign="top">0016</td><td valign="top"> </td><td valign="top">V01-E04</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0017</td><td valign="top"> </td><td valign="top"> </td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">E</td><td valign="top">0017</td><td valign="top"> </td><td valign="top">V01-E03</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0018</td><td valign="top"> </td><td valign="top"> </td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">E</td><td valign="top">0018</td><td valign="top"> </td><td valign="top">V01-E04</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">L</td><td valign="top">….</td><td valign="top"> </td><td valign="top">V01-E03</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">L</td><td valign="top">0018</td><td valign="top"> </td><td valign="top">V01-E04</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0019</td><td valign="top"> </td><td valign="top"> </td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">H</td><td valign="top">0019</td><td valign="top"> </td><td valign="top">V01-E03</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr></tbody></table>

&#x20;

If we want to perform mass exports (from option 6.2). We export the RSA of subsystem D (record 1).

1. We do not export remote 0001 because it has no service application. Record R-L-Local code-D-000000010
2. We do not export remote 0002 because it has a V01 key in state 01. Record R-L-Local code-D-000000020
3. We do not export remote 0003 because it has a V01 key in state 02. Record R-L-Local code-D-000000030
4. We do not export remote 0004 because the key to be exported, V11, is in state 01. Record R-L-Local code-D-000000040
5. We do not export remote 0005 because the key to be exported, V11, is in state 02. Record R-L-Local code-D-000000050
6. We do not export remote 0006 because the key to be exported, V11, is in state 03. Record R-L-Local code-D-000000060
7. We do not export remote 0007 because the key to be exported, V11, is in state 04. Record R-L-Local code-D-000000070
8. We do not export remote 0008 (Record R-L-Local code-D-000000080) because the record R-L-Local code-E-000000080 has a V01 key in state 01.
9. We do not export remote 0009 (Record R-L-Local code-D-000000090) because the record R-L-Local code-E-000000090 has a V01 key in state 02.
10. We export remote 0012. The subsystem to sign (D) and the order of the keys will change, V1-V3-V11. There was no subsystem to sign, but in the record, there were keys in E03-E04, so keys had previously been exchanged through subsystem D, and therefore this new one is signed with that subsystem.
11. We export remote 0013. The subsystem to sign (E) and the state of key V11 will change. There was a subsystem to sign, but it is detected that it was in canceled state. Since the record R-L-Local code-E-0000000130 exists, with an active key (V1 in state 03), it means that keys had been exchanged through subsystem H, and therefore this new one is signed with that subsystem.
12. We export remote 0014. The subsystem to sign (spaces) will change and the new V11 key in state 01 will appear. There was no record exchanged with that remote with another subsystem. Since the key it has is V10 and it is canceled, it means that nothing has been exchanged with the remote, and therefore the subsystem to sign is changed to spaces.
13. We export remote 0015. The subsystem to sign (E) will change and the state of key V11 will change to state 01. It had signing subsystem D, but there were no active keys, so it has found the record R-L-Local code-E-0000000150 with a key in state 3, so it updates the subsystem to sign.
14. We export remote 0016. The subsystem to sign (F) will change and the state of key V11 will change to state 01. The records R-L-Local code-E-0000000160 and -L-Local code-F-0000000160 existed, the first with a key in state 03 and the second in 04, so we keep F because it is in state 04. We do not take the signing subsystem that existed because there was only one canceled key.
15. We export remote 0017. The subsystem to sign (E) will change and the new V11 key appears in state 01. The record R-L-Local code-E-0000000170 existed with active keys, state 03, so we change the subsystem to sign.
16. We export remote 0018. The subsystem to sign (E) will change and the new V11 key appears in state 01. The record R-L-Local code-E-0000000180 existed with active keys, state 04, so we change the subsystem to sign.
17. We export remote 0019. The subsystem to sign (E) will change and the new V11 key appears in state 01. The record R-L-Local code-E-0000000190 existed with active keys, state 04, so we change the subsystem to sign.

At the end of the process, it will display the message "Correct export (0008 exported out of 0019 processed)". 8 loads should have been triggered. Changes in some records in bold:&#x20;

<table data-header-hidden><thead><tr><th width="64.7901611328125" valign="top"></th><th width="67.7530517578125" valign="top"></th><th width="77.62957763671875" valign="top"></th><th width="73.678955078125" valign="top"></th><th width="72.6912841796875" valign="top"></th><th width="92.4444580078125" valign="top"></th><th width="107.25927734375" valign="top"></th><th width="106.271484375" valign="top"></th><th width="108.2469482421875" valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top">Type</td><td valign="top">Own</td><td valign="top">Local</td><td valign="top">Subsys.</td><td valign="top">Rem</td><td valign="top">Sign.sub</td><td valign="top">Vers(1)-Stat</td><td valign="top">Vers(1)-Stat</td><td valign="top">Vers(3)-Stat</td><td valign="top">Serv.app</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0012</td><td valign="top">D</td><td valign="top">V01-E04</td><td valign="top">V03-E03</td><td valign="top">V11-E01</td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0013</td><td valign="top">E</td><td valign="top">V11-E01</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0014</td><td valign="top">nothing</td><td valign="top">V10-E05</td><td valign="top">V11-E01</td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0015</td><td valign="top">E</td><td valign="top">V11-E01</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0016</td><td valign="top">F</td><td valign="top">V11-E01</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0017</td><td valign="top">E</td><td valign="top">V11-E01</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0018</td><td valign="top">E</td><td valign="top">V11-E01</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr><tr><td valign="top">R</td><td valign="top">L</td><td valign="top">xxxx</td><td valign="top">D</td><td valign="top">0019</td><td valign="top">E</td><td valign="top">V11-E01</td><td valign="top"> </td><td valign="top"> </td><td valign="top">xxxx</td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-cics-en/key-manager/operation-example/mass-export-of-rsa-keys.-update-of-the-rsa-signature-subsystem.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
