> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-cics-en/operacion/exchange-key-management-editran-gc-optional-module.md).

# Exchange key management (Editran/GC) (Optional module)

Check the [Key Manager (Annex)](/documentacion-editran/ibm-editran-v5.3-cics-en/key-manager/appendix.md) to understand first of all the possibilities of EDITRAN cryptography

To see the functions of EDITRAN/GC, consult[ Key manager](/documentacion-editran/ibm-editran-v5.3-cics-en/key-manager.md).

By selecting option 6 from the General Menu or =6 from any submenu, or with transid ZTB2 (transid to be created in the local EDITRAN environment):&#x20;

```
 ----------------------------------------------------------------------------- 
|   24/06/2026         EXCHANGE KEYS MANAGEMENT         EDITRAN 5.3   |
|   18:49:57                                                                  |
 ----------------------------------------------------------------------------- 
|                                                                             |
|                                                                             |
| 1 --> LOCAL ENVIRONMENT ADMINISTRATOR                                        |
|                                                                             |
| 2 --> RSA OWN KEYS MANAGEMENT (ADMINISTRATION AND GENERATION)           |
|                                                                             |
| 3 --> ASSOCIATION OF RSA OWN KEYS (ADMINISTRATION-EXPORT-SEND)   |
|                                                                             |
| 4 --> ASSOCIATION OF RSA REMOTE KEYS (ADMINISTRATION)                     |
|                                                                             |
|                                                                             |
|                                                                             |
|                                                                             |
|                                                                             |
|                            OPTION..........:                                |
|                                                                             |
|                                                                             |
|                                                                             |
|       <ENTER> PERFORM QUERY, <PF3> EXIT                                |
 ----------------------------------------------------------------------------- 
```

The different options are detailed below (records in file ZTBPFGC):

* There is a general environment record where the entity's “general data” is specified (option 6.1).
* Key: A + Low-values
* There are n records of RSA own keys. The key for each one is the origin RBE code and the created subsystem. Within each one, the name of the labels (private and public) and a relationship of the last 3 versions (versions range from 01 to 99) of active or operational keys is specified (option 6.2).

> Key: R(RSA) + L(local)+LOC.Code+local-Sub+LOW-VALUES
>
> Key: R(RSA) + L(local)+LOC.Code+local-Sub+LOW-VALUES
>
> Key: R(RSA) + L(local)+LOC.Code+local-Sub+LOW-VALUES

* When the RSA records of own keys are “exported” to a certain remote entity, what is being done is “exporting” the key whose label is that of the active version; in short, associating the own keys with a certain remote (option 6.3).

> Key: R (RSA) + L (local) +LOC.Code+local-Sub+remote Code

* When the RSA records of remote keys are “imported” from a remote entity, we must know which subsystem to create (option 6.5). From there, the import is automatic; the active version is imposed by the remote side.

> Key: R (RSA) + R (remote) +LOC.Code+remote-Sub+remote Code

## Local environment administrator

It is accessed with option 1 and displays the following panel:

```
 ----------------------------------------------------------------------------- 
|   24/06/2026         EXCHANGE KEYS MANAGEMENT         EDITRAN 5.3   |
|   18:50:17            LOCAL ENVIRONMENT ADMINISTRATOR                        |
 ----------------------------------------------------------------------------- 
|                                                                             |
|                                                                             |
|                                                                             |
|                                                                             |
|                             A --> CREATE                                      |
|                                                                             |
|                             M --> MODIFY                                      |
|                                                                             |
|                             C --> QUERY                                      |
|                                                                             |
|                                                                             |
|                                                                             |
|                                                                             |
|                             OPTION..........:                               |
|                                                                             |
|                                                                             |
|                                                                             |
|                                                                             |
|       <ENTER> PERFORM QUERY, <PF3> EXIT                                |
 ----------------------------------------------------------------------------- 
```

Next, a second panel appears (default fields are shown):

```
 ----------------------------------------------------------------------------- 
|   24/06/2026         EXCHANGE KEYS MANAGEMENT         EDITRAN 5.3   |
|   18:50:29            LOCAL ENVIRONMENT ADMINISTRATOR                        |
 ----------------------------------------------------------------------------- 
|                                                                             |
|    REQUIRES EDITRAN FOR MANAGEMENT (Y/N): S                                   |
|    FILE INSTALLATION PREFIX.: KI.EGDC                             |
|    EDITRAN/P SERVICE APPLICATION...: TELEGC                              |
|    LABEL PREFIX......................: LABEL.PRODUCTS.EDI                 |
|    PROC. NAME FOR KEY GENERATION: ZTBGP1GD                            |
|    WORK UNIT NAME (SYSDA,VIO,..).: SYSDA                               |
|                                                                             |
|   JCL CARDS                                                             |
|   =============                                                             |
|        ===> //KIGESCCD JOB (EGDC,KIT,,99),GESCLACICSD,MSGCLASS=H,           |
|        ===> //             MSGLEVEL=1,CLASS=A                               |
|        ===> //*                                                             |
|        ===> //*JOBLIB   DD DSN=KI.EIDC.ZTBG.LOAD,DISP=SHR                   |
|        ===> //*                                                             |
|                                                                             |
|                                                                             |
|                                                                             |
|       <ENTER> PERFORM QUERY, <PF3> EXIT                                |
 ----------------------------------------------------------------------------- 
```

The meaning of the fields is as follows:

* **Requires editran for Management (Y/N)**- Indicates whether editran will be used for the exchange. Normally entities will use editran (S) for exchange, but there could be cases, due to the modular nature of editran, where an entity without editran requires this module for key exchanges for other applications. Recommended value: S
* **File installation prefix**. When a key file is exchanged, it must be created before loading it into buffer. This prefix “standardizes” the name for each entity.
* **Service editran application**. Name of the editran/P application that will be used for key exchange. This value acts as a template, which will be transferred to the records of the remote entities, so that a different application can be included for each exchange. Recommended value: TELEGC
* **Label prefix.** Prefix that will be applied to the labels containing DES and RSA keys, to include them in the different systems. This prefix “standardizes” the label name for each entity.
* **Procedure name for key generation (and sending)**: Name of the procedure to create and issue. The ZTBGP1GC procedure is provided by default.
* **Work unit name.** Generic storage unit for the definition of intermediate and work files.
* **JCL cards:** To submit the previous procedure.&#x20;

## RSA own keys management (administration and generation) <a href="#toc93115599" id="toc93115599"></a>

It is accessed with option 2 and displays the following panel (default fields are shown; in a local environment, if there is an EDITRAN/P license, the general local environment is shown):&#x20;

```
 ----------------------------------------------------------------------------- 
|   24/06/2026         EXCHANGE KEYS MANAGEMENT         EDITRAN 5.3   |
|   18:52:20             RSA OWN KEYS MANAGEMENT                        |
 ----------------------------------------------------------------------------- 
|                                                                             |
|                       A --> CREATE                                            |
|                                                                             |
|                       B --> DELETE                                            |
|                                                                             |
|                       M --> MODIFY                                    |
|                                                                             |
|                       C --> QUERY AND VIEW PUBLIC KEY             |
|                                                                             |
|                       G --> GENERATION                                      |
|                                                                             |
|                       E --> EXPORT-SEND (TO ALL IN THE SUBSYSTEM)  |
|                                                                             |
|                       OPTION..........: C                                   |
|                       SUBSYSTEM......:                                     |
|                       LOCAL ENVIRONMENT...: 0 0009994 0                         |
|                                                                             |
|                                                                             |
|       <ENTER> PERFORM OPERATION, <PF3> EXIT                               |
 ----------------------------------------------------------------------------- 
```

The meaning of the fields is as follows:

* **Option**. Required field.
  * Create - Create a subsystem
  * Delete - Delete a subsystem
  * Modify - Modifies the values of a subsystem
  * Query. Queries a subsystem and allows viewing the public part of each key
  * Generation. Generates a key pair for a given subsystem
  * Export. Takes the last generated key pair (the one in ACTIVE state) and exports it to all remotes that have been created with that subsystem (option 6.3), in bulk, that is, it loads and issues the same keys to all of them at the same time.
* **Subsystem**. Accepts values A-Z and 0-9. This is the name of the RSA subsystem that we are going to create. For example, we may have test or production subsystems, monthly or annual exchange subsystems, subsystems for one group of entities or another, etc. If it is not filled in, intermediate screens are shown so that we can select the one we want.
* **Local environment.** Editran code of the main local environment. If it is not filled in or an asterisk is included, screens with local codes are shown (Multi-environment licenses).

If any field has been selected generically, different menus appear with which you can move forward, go back, or select the record we are looking for:

```
 ----------------------------------------------------------------------------- 
|   24/06/2026         EXCHANGE KEYS MANAGEMENT         EDITRAN 5.3   |
|   18:52:30             RSA OWN KEYS MANAGEMENT                        |
 ----------------------------------------------------------------------------- 
|                                                                             |
|                                                                             |
|                                                                             |
|                                                                             |
|  S     LOCAL    SUBS.  ACTIVE VERSION  GENERATION DATE  MODIFICATION DATE |
|  -   ---------  -----  --------------  ----------------  ------------------ |
|      000099940    A          14         20221124-132828    20221124-132828  |
|      000099940    B          04         20100412-170321    20100412-170321  |
|      000099940    C          01         20230816-093627    20231031-121659  |
|      000099940    D          03         20050131-154832    20050131-154832  |
|      000099940    E          01         20100325-152836    20100325-152836  |
|      000099940    F          03         20250331-122643    20250331-122643  |
|      000099940    G          01         20050210-174527    20050210-174527  |
|      000099940    H          01         20120119-091515    20120119-091515  |
|      000099940    I          02         20191030-094521    20191030-094521  |
|      000099940    J          02         20120208-161012    20120208-161012  |
|                                                                             |
|                                                                             |
| <S> SELECT, <PF3> PREVIOUS SCREEN, <PF7> GO BACK, <PF8> GO FORWARD     |
 ----------------------------------------------------------------------------- 
```

The selected subsystems appear for each selected local code. If RSA keys have been generated (private - public), the active version and the generation and last modification dates are shown.

If any record is selected, or if the selection was specific from the previous menu, the following map is displayed (some fields may appear differently depending on the access option, create-delete-generation, modify or query):

In case of query:

```
 ----------------------------------------------------------------------------- 
|   24/06/2026         EXCHANGE KEYS MANAGEMENT         EDITRAN 5.3   |
|   18:52:42             RSA OWN KEYS MANAGEMENT                        |
 ----------------------------------------------------------------------------- 
|                                                                             |
|      SUBSYSTEM.....: A                      LOCAL ENVIRONMENT..: 000099940     |
|      SUBSYSTEM DESCRIPTION..........: SUBS.PRINCIPAL RSA                |
|      ADMINISTRATOR NAME...........:                          LOCAL    |
|      ADMINISTRATOR PHONE.........: 88888888                          |
|      EDITRAN/P SERVICE APPLICATION...: TELEGC                            |
|                                                                             |
| LABEL PAIR: LABEL.PRODUCTS.EDI.000099940.A.000000000.RSA.LOCAL.PRIVATE   |
| KEY GENERATION LENGTH: 1024 (1024/2048/4096)                      |
|                                                                             |
|          RELATIONSHIP OF PRIVATE AND PUBLIC KEYS (LABEL + VERSION)           |
| VERS GEN. DATE-TIME MODIF. DATE-TIME    STATE   SEL                        |
| ---- --------------- --------------- ----------- ---                        |
|  13  20221124-131256 20221124-132828 3-OPERATIONAL      (S)ELECT. VIEW PUBLIC |
|  14  20221124-132828 20221124-132828 4-ACTIVE         (S)ELECT. VIEW PUBLIC |
|  12  20221124-130548 20221124-131256 3-OPERATIONAL      (S)ELECT. VIEW PUBLIC |
|                                                                             |
|                                                                             |
|       <PF3> EXIT, <ENTER> VIEW PUBLIC KEY                         |
-------------------------------------------------------------------------------
```

In the case of modification:

```
 ----------------------------------------------------------------------------- 
|   24/06/2026         EXCHANGE KEYS MANAGEMENT         EDITRAN 5.3   |
|   18:52:55             RSA OWN KEYS MANAGEMENT                        |
 ----------------------------------------------------------------------------- 
|                                                                             |
|      SUBSYSTEM.....: A                      LOCAL ENVIRONMENT..: 000099940     |
|      SUBSYSTEM DESCRIPTION..........: SUBS.PRINCIPAL RSA                |
|      ADMINISTRATOR NAME...........:                          LOCAL    |
|      ADMINISTRATOR PHONE.........: 88888888                          |
|      EDITRAN/P SERVICE APPLICATION...: TELEGC                            |
|                                                                             |
| LABEL PAIR: LABEL.PRODUCTS.EDI.000099940.A.000000000.RSA.LOCAL.PRIVATE   |
| KEY GENERATION LENGTH: 1024 (1024/2048/4096)                      |
|                                                                             |
|          RELATIONSHIP OF PRIVATE AND PUBLIC KEYS (LABEL + VERSION)           |
| VERS GEN. DATE-TIME MODIF. DATE-TIME    STATE   SEL                        |
| ---- --------------- --------------- ----------- ---                        |
|  13  20221124-131256 20221124-132828 3-OPERATIONAL      (A=ACTIVATE KEY)     |
|  14  20221124-132828 20221124-132828 4-ACTIVE         (A=ACTIVATE KEY)     |
|  12  20221124-130548 20221124-131256 3-OPERATIONAL      (A=ACTIVATE KEY)     |
|                                                                             |
|                                                                             |
|       <PF3> EXIT, <ENTER> MODIFY                                        |
-------------------------------------------------------------------------------
```

&#x20;Since we are in RSA, when creating a subsystem, it will probably be useful for several remote entities.

The data requested is:

* Local description (informational parameter)
* Name and phone number of the local administrator of this subsystem
* Editran/P application, it is still a “template” before defining the remotes associated with the subsystem. Recommended value: TELEGC.
* Pair label.

When created, the name of the label appears, which will identify in the ICSF file the private and public key pair, generated by default by editran/GC with the prefix that has been entered in the Environment plus the entity's local code, the name of the subsystem, zeros, and the key type it points to. These names can be changed according to the entity's needs in the create option.

A default label is displayed. The administrator is responsible for them, for making sure they do not match those of another subsystem, etc. They cannot be modified if there are associated remote records or if a key pair has been generated. Recommended value: Keep the proposed value, unless you have restrictions, in which case you should analyze the label to include, so that it does not match any current or future labels of other remotes or other subsystems.

* Key Generation Length (BITS):

Indicates the length with which the RSA key pair will be generated, which can be 1024, 2048, or 4096 bits. By default, 2048 appears.

In the case of query, if a version has been selected (S), the public key is shown in clear text and hexadecimal (the selected version is included in the label).

```
 ----------------------------------------------------------------------------- 
|   24/06/2026         EXCHANGE KEYS MANAGEMENT         EDITRAN 5.3   |
|   18:53:13             RSA OWN KEYS MANAGEMENT                        |
 ----------------------------------------------------------------------------- 
| SUBSYSTEM.......: A                    LOCAL ENVIRONMENT....: 000099940        |
| GENERATION DATE: 20221124-131256      STATE: 3-OPERATIONAL LONG:   1024     |
| LABEL....: LABEL.PRODUCTS.EDI.000099940.A.000000000.RSA.LOCAL.PRIVATE.V13  |
| MODULE                                                                      |
|      E92887154C18B8B9CA36CA527C3FBEC311A41B1DF53245728A96581FF0D1B5D6       |
|      CFEBCD5EBC6E8B811943547219CDC97D649E2C952F9413FCF0699534D2170234       |
|      3B83E078B473FE254AC6F2AE60936C7308B8F25FE0DEC7076E07DC058B0D919F       |
|      3198D3216B09D2E31A5B074FEE9FBAFEADA2FDE264D03DD3689FAB2FCC2E2777       |
| EXPONENT                                                                   |
|      008EA23CD38A030F5311FFEC31A80654C7722D6CF54E13E8A42BCDC3E25B837E       |
|      9C7FEFD26FB5F4193521635E56003B3AEE12B62F5DD46AB02B0007B34FF70F64       |
|      B5D248BD9CEF26E77CB2B940307E58DB67FA68D6AC1BC31DB7DB8E22348B47A7       |
|      0CAAC00E9917D816FDFECB569AB94B17AA36790CE5876F61604270B2F08D9E19       |
|                                                                             |
|                                                                             |
|                                                                             |
|                                                                             |
|                                                                             |
|                                                                             |
|       <PF3> EXIT                                                           |
```

&#x20;In the case of generation, an intermediate confirmation screen is displayed. If they confirm and there is a procedure and JCL cards in the local environment, the procedure is launched:

```
 ----------------------------------------------------------------------------- 
|   24/06/2026         EXCHANGE KEYS MANAGEMENT         EDITRAN 5.3   |
|   18:53:44             RSA OWN KEYS MANAGEMENT                        |
 ----------------------------------------------------------------------------- 
|                                                                             |
| SUBSYSTEM.......: 1                    LOCAL ENVIRONMENT....: 000099940        |
|                                                                             |
|                            *******************                              |
|                            * A T T E N T I O N *                              |
|                            *******************                              |
|                                                                             |
|          THE CHOSEN OPTION WILL CREATE A NEW VERSION, WHICH MEANS            |
|          THE OLDEST VERSION WILL BE LOST (IF THERE IS ONE).                  |
|                                                                             |
|                                                                             |
|                                                                             |
|                                                                             |
|                                                                             |
|                                                                             |
|             DO YOU WANT TO CONTINUE WITH THE REQUEST (Y/N).........: N               |
|                                                                             |
|                                                                             |
|       PRESS <PF2> TO CONFIRM THE OPERATION                               |
 ----------------------------------------------------------------------------- 
```

In case of deletion, a confirmation screen is displayed. OWN RSA records cannot be deleted if there is any remote associated with them.

```
 ----------------------------------------------------------------------------- 
|   24/06/2026         EXCHANGE KEYS MANAGEMENT         EDITRAN 5.3   |
|   18:53:44             RSA OWN KEYS MANAGEMENT                        |
 ----------------------------------------------------------------------------- 
|                                                                             |
| SUSBISTEM.......: x                    LOCAL ENVIRONMENT....: x9999999x        |
|                                                                             |
|                            *******************                              |
|                            * A T T E N T I O N *                              |
|                            *******************                              |
|                                                                             |
|          THE CHOSEN OPTION DELETES THE SUBSYSTEM, WHICH MEANS            |
|          ALL GENERATED VERSIONS OF IT WILL BE LOST.               |
|          IF, IN ADDITION, YOU CREATE ANOTHER SUBSYSTEM AGAIN             |
|          WITH THE SAME NAME, THERE MAY BE VERSION CONFLICTS WITH              |
|          REMOTES THAT CONTINUE TO USE THE OLD ONE.                           |
|                                                                             |
|             DO YOU WANT TO CONTINUE WITH THE REQUEST (Y/N).........: N               |
|                                                                             |
|       PRESS <PF2> TO CONFIRM THE OPERATION                               |
-------------------------------------------------------------------------------
```

In case of bulk export, a confirmation screen is displayed.&#x20;

```
 ----------------------------------------------------------------------------- 
|   24/06/2026         EXCHANGE KEYS MANAGEMENT         EDITRAN 5.3   |
|   18:53:44             RSA OWN KEYS MANAGEMENT                        |
 ----------------------------------------------------------------------------- 
|                                                                             |
| SUSBISTEM.......: x                    LOCAL ENVIRONMENT....: x9999999x        |
|                                                                             |
|                            *******************                              |
|                            * A T T E N T I O N *                              |
|                            *******************                              |
|                                                                             |
|          THE CHOSEN OPTION TAKES THE ACTIVE KEY OF THE SUBSYSTEM             |
|          SELECTED AND EXPORTS IT TO ALL REMOTES THAT            |
|          EXIST WITH THE SUBSYSTEM (IF THEY DO NOT HAVE THAT ACTIVE ONE),             |
|          ALLOWING BOTH LOAD+SEND OR ONLY LOAD.                       |
|                                                                             |
|             DO YOU WANT TO EXPORT (Y)............................: x               |
|             DO YOU WANT TO SEND (Y/N)............................: x               |
|                                                                             |
|                                                                             |
|       PRESS <PF2> TO CONFIRM THE OPERATION                               |
-------------------------------------------------------------------------------
```

This option attempts to export the active key to all remotes that are created in the subsystem, as long as they do not have keys in flight and the operation allows it. Finally, a message is displayed with the number of records processed and the number of records exported. Obviously, the remotes must have been created with option 6.3.

## Association of RSA own keys (admin., export and send)

To access this option, there must be a suitable RSA own keys record (option 2).

It is accessed with option 3 and the following panel is displayed (default fields are shown; in a local environment, if there is an EDITRAN/P license, the general local environment is shown):

```
 ----------------------------------------------------------------------------- 
|   24/06/2026         EXCHANGE KEYS MANAGEMENT         EDITRAN 5.3   |
|   18:53:44             RSA OWN KEYS MANAGEMENT                        |
 ----------------------------------------------------------------------------- 
|                       A --> CREATE                                            |
|                                                                             |
|                       R --> CREATE WITH COPY                                  |
|                                                                             |
|                       B --> DELETE                                            |
|                                                                             |
|                       M --> MODIFY                                    |
|                                                                             |
|                       C --> QUERY AND VERIFY                         |
|                                                                             |
|                       G --> MANAGES KEY EXPORT AND SEND          |
|                                                                             |
|                                                                             |
|                  OPTION..........: x                                        |
|                  SUBSYSTEM......: x                                        |
|                  LOCAL ENVIRONMENT...: x 9999999 x                              |
|                  REMOTE ENVIRONMENT..: x 9999999 x                              |
|                                                                             |
|       <ENTER> PERFORM OPERATION, <PF3> EXIT                               |
-------------------------------------------------------------------------------
```

The meaning of the fields is as follows:

* **Option**. Required field.
* **Subsystem**. Accepts values A-Z and 0-9. This is the RSA own-keys subsystem that we are going to associate with a given remote entity. It is the name of the RSA subsystem that we will notify to the remote so that it creates it as a “remote subsystem” and with that name incorporates the key we will send it.
* **Local environment**. Editran code of the main local environment. If it is not filled in or an asterisk is included, screens with local codes are shown (Multi-environment licenses).
* **Remote environment.** Editran code of the remote entity. If it is not filled in or an asterisk is included, screens with remote codes are shown.

The key export and send option “associates” the active key that exists in the RSA own keys record for the subsystem with a given remote entity and creates a file with the corresponding local public key (it will be signed if there has been any successful RSA key exchange with that remote). This file will be sent automatically by editran if so indicated.

If any field has been selected generically, different menus appear with which you can move forward, go back, or select the record we are looking for:

```
 ----------------------------------------------------------------------------- 
|   24/06/2026         EXCHANGE KEYS MANAGEMENT         EDITRAN 5.3   |
|   18:54:25           ASSOCIATION OF RSA OWN KEYS                       |
 ----------------------------------------------------------------------------- 
|                                                                             |
|                                                                             |
| SEL    LOCAL     REMOTE  SUBS. ACTIVE V.  GENERATION DATE  MODIFICATION DATE |
| ---  --------- --------- ----- --------  ----------------  ---------------- |
|      x9999999x x9999999x   x                                                |
|      x9999999x x9999999x   x      xx      xxxxxxxx-xxxxxx   xxxxxxxx-xxxxxx |
|                                                                             |
|                                                                             |
|                                                                             |
|                                                                             |
|  xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx                      |
| <S> SELECT, <PF3> PREVIOUS SCREEN, <PF7> GO BACK, <PF8> GO FORWARD     |
-------------------------------------------------------------------------------
```

On the selection screen, if an RSA key pair has been generated, the active version and the generation and last modification dates are shown.

If any record is selected, or if the selection was specific from the previous menu, the following map is displayed (some fields may appear differently depending on the access option, create-delete-export, modify or query):

```
 ----------------------------------------------------------------------------- 
|   24/06/2026         EXCHANGE KEYS MANAGEMENT         EDITRAN 5.3   |
|   18:54:25           ASSOCIATION OF RSA OWN KEYS                       |
 ----------------------------------------------------------------------------- 
|  SUBSYSTEM.: 0    LOCAL......: 000099940     REMOTE.....: A00099980        |
|                                                                             |
|      SUBSYSTEM DESCRIPTION..........: SUBS.PRINCIPAL RSA                |
|      ADMINISTRATOR NAME...........:                          REMOTE   |
|      ADMINISTRATOR PHONE.........:                                   |
|      EDITRAN/P SERVICE APPLICATION...: TELEGC                            |
| LABEL PAIR: LABEL.PRODUCTS.EDI.000099940.0.000000000.RSA.LOCAL.PRIVATE   |
| ACTIVE KEY LENGTH IN THE SUBSYSTEM...:                                 |
|                                                                             |
| RSA SUBSYSTEM FOR SIGNING...:                                              |
|          RELATIONSHIP OF PRIVATE AND PUBLIC KEYS (LABEL + VERSION)           |
| VERS GEN. DATE-TIME MODIF. DATE-TIME    STATE   SEL                        |
| ---- --------------- --------------- ----------- ---                        |
|  15  20161229-091018 20170117-110454 4-ACTIVE         (S)ELECT.VIEW PUB.LOC. |
|  <PF3> EXIT, <ENTER> MODIFY                                             |
```

In case of query:

```
|  XX  XXXXXXXX-XXXXXX XXXXXXXX-XXXXXX 2 OPERATIONAL   X (S)ELECT.VIEW PUB.LOC.  |
|  XX  XXXXXXXX-XXXXXX XXXXXXXX-XXXXXX 2 OPERATIONAL   X (S)ELECT.VIEW PUB.LOC.  |
|  XX  XXXXXXXX-XXXXXX XXXXXXXX-XXXXXX 1 ACTIVE      X (S)ELECT.VIEW PUB.LOC.  |
```

In the case of modification:

```
|  XX  XXXXXXXX-XXXXXX XXXXXXXX-XXXXXX 2 OPERATIONAL   X (A=ACTIVATE,C=CANCEL) |
|  XX  XXXXXXXX-XXXXXX XXXXXXXX-XXXXXX 2 OPERATIONAL   X (A=ACTIVATE,C=CANCEL) |
|  XX  XXXXXXXX-XXXXXX XXXXXXXX-XXXXXX 1 ACTIVE      X (A=ACTIVATE,C=CANCEL) |
```

Since we are in RSA, when creating a subsystem, it will probably be useful for several remote entities.

The data requested is:

* **Local description**
* **Name and phon**e of REMOTE administrator.
* **Editran/P application**, through which we are going to send our public key to the remote.
* **Private and public label**. They are protected. They are those of the matching subsystem's own RSA record.
* **RSA subsystem for signing.** It can be the same one (if keys have been exchanged through it) or different (if keys have been exchanged through another one). If no keys have been exchanged with the remote entity, this field does not have to be filled in. This field, if the user does not fill it in correctly, may be modified or managed by the program, so that if an entity has exchanged a valid key for an x subsystem, the program will detect whether it is correct. The idea is that, when creating, modifying, generating or exporting, the program confirms that the user has indicated a correct option, that if it is not indicated it is filled in, and that if it is indicated and is incorrect, it is not allowed. The RSA subsystem for signing, both in RSA and DES, is a local subsystem

Next come the versions for which a key pair has been generated, and the state they are in (active, canceled, or operational). Only one can be “active”. When new keys are generated, they become active and if there was already one active, it becomes operational.

In the case of query, if a version has been selected (S), the public key is shown in hexadecimal (the selected version is included in the label).

```
 ----------------------------------------------------------------------------- 
|   24/06/2026         EXCHANGE KEYS MANAGEMENT         EDITRAN 5.3   |
|   18:54:25           ASSOCIATION OF RSA OWN KEYS                       |
 ----------------------------------------------------------------------------- 
|  SUSBISTEM.: x    LOCAL......: x9999999x     REMOTE.....: x9999999x        |
| GENERATION DATE.: xxxxxxxx-xxxxxx      STATE.........:   3-OPERATIONAL      |
| LABEL....: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxYY  |
|  MODULE:                                                                    |
|  XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX   |
|  XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX   |
|  XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX   |
|  XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX   |
|  EXPONENT:                                                                 |
|  XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX   |
|  XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX   |
|  XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX   |
|  XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX   |
|       <PF3> EXIT                                                           |
-------------------------------------------------------------------------------
```

In the case of export-send, an intermediate confirmation screen is displayed. If they confirm and there is a procedure and JCL cards in the local environment, the process that associates the selected subsystem's active own key with the remote will be launched:

```
 ----------------------------------------------------------------------------- 
|   24/06/2026         EXCHANGE KEYS MANAGEMENT         EDITRAN 5.3   |
|   18:54:25           ASSOCIATION OF RSA OWN KEYS                       |
 ----------------------------------------------------------------------------- 
|  SUSBISTEM.: x    LOCAL......: x9999999x     REMOTE.....: x9999999x        |
|                                                                             |
|                            *******************                              |
|                            * A T T E N T I O N *                              |
|                            *******************                              |
|                                                                             |
|          THE CHOSEN OPTION WILL CREATE A NEW VERSION, WHICH MEANS            |
|          THE OLDEST VERSION WILL BE LOST (IF THERE IS ONE).                  |
|                                                                             |
|                                                                             |
|                                                                             |
|                                                                             |
|                                                                             |
|             DO YOU WANT TO EXPORT (Y)............................: N               |
|             DO YOU WANT TO SEND (Y/N)............................: N               |
|                                                                             |
|       PRESS <PF2> TO CONFIRM THE OPERATION                               |
-------------------------------------------------------------------------------
```

If it is exported, the state of the associated key version changes to *generated*, if it is sent to *sent*. It will only change to active state when a confirmation file is received from the remote entity, or failing that, if we activate it manually.

In case of deletion, a confirmation screen is displayed.&#x20;

```
 ----------------------------------------------------------------------------- 
|   24/06/2026         EXCHANGE KEYS MANAGEMENT         EDITRAN 5.3   |
|   18:54:25           ASSOCIATION OF RSA OWN KEYS                       |
 ----------------------------------------------------------------------------- 
|  SUSBISTEM.: x    LOCAL......: x9999999x     REMOTE.....: x9999999x        |
|                                                                             |
|                                                                             |
|                            *******************                              |
|                            * A T T E N T I O N *                              |
|                            *******************                              |
|                                                                             |
|          THE CHOSEN OPTION DELETES THE SUBSYSTEM, WHICH MEANS            |
|          ALL GENERATED VERSIONS OF IT WILL BE LOST WITH            |
|          THE SELECTED REMOTE. IF, IN ADDITION, YOU CREATE AGAIN             |
|          WITH THE SAME NAME, THERE MAY BE VERSION CONFLICTS             |
|          WITH THIS REMOTE IF AN OLD VERSION IS USED                      |
|                                                                             |
|                                                                             |
|                                                                             |
|             DO YOU WANT TO CONTINUE WITH THE REQUEST (Y/N).........: N               |
|                                                                             |
|       PRESS <PF2> TO CONFIRM THE OPERATION                               |
-------------------------------------------------------------------------------
```

## Association of RSA remote keys (administration) <a href="#toc93115602" id="toc93115602"></a>

It is accessed with option 4 and displays the following panel (default fields are shown; in a local environment, if there is an EDITRAN/P license, the general local environment is shown):

```
 ----------------------------------------------------------------------------- 
|   24/06/2026         EXCHANGE KEYS MANAGEMENT         EDITRAN 5.3   |
|   18:54:25           ASSOCIATION OF RSA OWN KEYS                       |
 ----------------------------------------------------------------------------- 
|                       A --> CREATE                                            |
|                       R --> CREATE WITH COPY                                  |
|                       B --> DELETE                                            |
|                       M --> MODIFY                                    |
|                       C --> QUERY AND VERIFY                         |
|                                                                             |
|                                                                             |
|                  OPTION..........: C                                        |
|                  SUBSYSTEM......: x                                        |
|                  LOCAL ENVIRONMENT...: x 9999999 x                              |
|                  REMOTE ENVIRONMENT..: x 9999999 x                              |
|                                                                             |
|       <ENTER> PERFORM QUERY, <PF3> EXIT                                |
-------------------------------------------------------------------------------
```

The meaning of the fields is as follows:

* **Option**. Required field.
* **Subsystem**. Accepts values A-Z and 0-9. This is the name of the RSA keys subsystem that the remote entity has created as local and that it will notify us about so that we can create it as remote.
* **Local environment.** Editran code of the main local environment. If it is not filled in or an asterisk is included, screens with local codes are shown (Multi-environment licenses).
* **Remote environment.** Editran code of the remote entity. If it is not filled in or an asterisk is included, screens with remote codes are shown.

If any field has been selected generically, different menus appear with which you can move forward, go back, or select the record we are looking for:

```
 ----------------------------------------------------------------------------- 
|   24/06/2026         EXCHANGE KEYS MANAGEMENT         EDITRAN 5.3   |
|   18:54:25           ASSOCIATION OF RSA OWN KEYS                       |
 ----------------------------------------------------------------------------- 
|                                                                             |
|                                                                             |
| SEL    LOCAL     REMOTE  SUBS. ACTIVE V.  GENERATION DATE  MODIFICATION DATE |
| ---  --------- --------- ----- --------  ----------------  ---------------- |
|      x9999999x x9999999x   x                                                |
|      x9999999x x9999999x   x      xx      xxxxxxxx-xxxxxx   xxxxxxxx-xxxxxx |
|                                                                             |
|                                                                             |
|                                                                             |
|                                                                             |
|                                                                             |
|                                                                             |
|                                                                             |
|  xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx                      |
| <S> SELECT, <PF3> PREVIOUS SCREEN, <PF7> GO BACK, <PF8> GO FORWARD     |
-------------------------------------------------------------------------------
```

The selected subsystems appear for each selected local or remote code. If a public RSA key has been received, the active version and the generation and last modification dates are shown.

If any record is selected, or if the selection was specific from the previous menu, the following map is displayed (some fields may appear differently depending on the access option, create-delete, modify or query):&#x20;

```
 ----------------------------------------------------------------------------- 
|   24/06/2026         EXCHANGE KEYS MANAGEMENT         EDITRAN 5.3   |
|   18:55:02           ASSOCIATION OF FOREIGN RSA KEYS                        |
 ----------------------------------------------------------------------------- 
|  SUBSYSTEM.: 0    LOCAL......: 000099940     REMOTE.....: A00099980        |
|                                                                             |
|      SUBSYSTEM DESCRIPTION..........: SECONDARY RSA SUBS.              |
|      ADMINISTRATOR NAME...........:                          REMOTE   |
|      ADMINISTRATOR PHONE.........:                                   |
|      EDITRAN/P SERVICE APPLICATION...: TELEGC                            |
| LABEL PAIR: LABEL.PRODUCTS.EDI.000099940.0.A00099980.RSA.AJENA.PUBLICA   |
| ACTIVE KEY LENGTH IN THE SUBSYSTEM...:                                 |
|                                                                             |
| RSA SUBSYSTEM SIGNED.......:                                              |
|          RELATIONSHIP OF PRIVATE AND PUBLIC KEYS (LABEL + VERSION)           |
| VERS GEN. DATE-TIME MODIF. DATE-TIME    STATE   SEL                        |
| ---- --------------- --------------- ----------- ---                        |
|  02  20070802-130941 20170117-105742 4-ACTIVE         (S)ELECT.VIEW PUB.REM. |
|                                                                             |
|                                                                             |
|                                                                             |
|                                                                             |
|       <PF3> EXIT, <ENTER> VIEW PUBLIC KEY                         |
```

&#x20;In case of query:

```
|  XX  XXXXXXXX-XXXXXX XXXXXXXX-XXXXXX 2 OPERATIONAL   X  (S)ELECT.VIEW PUB.REM. |
|  XX  XXXXXXXX-XXXXXX XXXXXXXX-XXXXXX 2 OPERATIONAL   X  (S)ELECT.VIEW PUB.REM. |
|  XX  XXXXXXXX-XXXXXX XXXXXXXX-XXXXXX 1 ACTIVE      X  (S)ELECT.VIEW PUB.REM. | 
```

In the case of modification:

```
|  XX  XXXXXXXX-XXXXXX XXXXXXXX-XXXXXX 2 OPERATIONAL   X (A=ACTIVATE,C=CANCEL) |
|  XX  XXXXXXXX-XXXXXX XXXXXXXX-XXXXXX 2 OPERATIONAL   X (A=ACTIVATE,C=CANCEL) |
|  XX  XXXXXXXX-XXXXXX XXXXXXXX-XXXXXX 1 ACTIVE      X (A=ACTIVATE,C=CANCEL) |
```

The data requested is:

* **Remote description**
* **Name and phone number** of REMOTE administrator.
* **Editran/**&#x50;, through which we are going to receive the remote's public key.
* **Public label**. Remote public label name. A default label is displayed. The administrator is responsible for them, for making sure they do not match those of another subsystem, etc.

The default label is:

* Label-prefix-environment.Local-code.subsystem.Remote-code.RSA.FOREIGN. PUBLIC
* RSA subsystem for signing. Protected field, filled in with the subsystem chosen by the remote for signing (when receiving the file with its key).

Next come the versions for which a key pair has been generated, and the state they are in (active, canceled, or operational). Only one can be “active”. When new keys are RECEIVED, they become received and active, and if there was already one active, it becomes operational.

In the case of query, if a version has been selected (S), the public key is shown in clear text and hexadecimal, with all fields protected (the selected version is included in the label).

```
 ----------------------------------------------------------------------------- 
|   24/06/2026         EXCHANGE KEYS MANAGEMENT         EDITRAN 5.3   |
|   18:55:02           ASSOCIATION OF FOREIGN RSA KEYS                        |
 ----------------------------------------------------------------------------- 
|  SUSBISTEM.: x    LOCAL......: x9999999x     REMOTE.....: x9999999x        |
| GENERATION DATE.: xxxxxxxx-xxxxxx      STATE.........:   3-OPERATIONAL      |
| LABEL....: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxYY  |
|  MODULE:                                                                    |
|  XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX   |
|  XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX   |
|  XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX   |
|  XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX   |
|  EXPONENT:                                                                 |
|  XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX   |
|  XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX   |
|  XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX   |
|  XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX   |
|       <PF3> EXIT                                                           |
-------------------------------------------------------------------------------
```

In case of deletion, a confirmation screen is displayed.&#x20;

```
 ----------------------------------------------------------------------------- 
|   24/06/2026         EXCHANGE KEYS MANAGEMENT         EDITRAN 5.3   |
|   18:55:02           ASSOCIATION OF FOREIGN RSA KEYS                        |
 ----------------------------------------------------------------------------- 
|  SUSBISTEM.: x    LOCAL......: x9999999x     REMOTE.....: x9999999x        |
|                                                                             |
|                                                                             |
|                            *******************                              |
|                            * A T T E N T I O N *                              |
|                            *******************                              |
|                                                                             |
|          THE CHOSEN OPTION DELETES THE SUBSYSTEM, WHICH MEANS            |
|          ALL GENERATED VERSIONS OF IT WILL BE LOST WITH            |
|          THE SELECTED REMOTE. IF, IN ADDITION, YOU CREATE AGAIN             |
|          WITH THE SAME NAME, THERE MAY BE VERSION CONFLICTS             |
|          WITH THIS REMOTE IF AN OLD VERSION IS USED                      |
|                                                                             |
|                                                                             |
|                                                                             |
|             DO YOU WANT TO CONTINUE WITH THE REQUEST (Y/N).........: N               |
|                                                                             |
|       PRESS <PF2> TO CONFIRM THE OPERATION                               |
-------------------------------------------------------------------------------
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-cics-en/operacion/exchange-key-management-editran-gc-optional-module.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
