> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-cics-en/utilities-and-codes/appendix-d.-cryptography-system-in-onesait-editran/encryption-errors.md).

# Encryption errors

When a Cryptographic Error occurs, editran provides local information about the error produced and sends the remote side a release request with the error reason, subsequently releasing the connection.

At the side where the error occurs, the Return Code returned by the product that provides the cryptographic services (CRIPTOlib/DES 3.0, BDKDES, PCF, CUSP, TSS, ICSF, ...) is reported, so if it occurs, the references for the return-code and/or Reason-Code given in the corresponding manual for each product should be consulted, such as:

* CRIPTOlib/DES: "Criptolib/DES 3.0 MVS version. DES Security System. [Installation](/documentacion-editran/ibm-editran-v5.3-cics-en/installation.md).
* CUSP/3848: "Cryptographic Unit Support: Installation Reference Manual"
* TSS/4753: "Transaction Security System. Programming Guide and   Reference"
* ICSF/ICRF: "Integrated Cryptographic Service Facility/MVS. Application Programmer's Guide".

The editran Reasons for Cryptographic Errors that can occur are:

* (ERR1): Error obtaining the Label on the side that starts the session.
* (ERR2): Error generating the challenge or signature.
  * If AUTHENTICATION is DES: Probable error in local key.
  * If AUTHENTICATION is RSA: If the error occurs in the signature, the problem may be in the local key (Private).
  * If the error is in the challenge, the problem may be in the remote key (public).
* (ERR3): Error when trying to generate session key.
  * If AUTHENTICATION is DES: Error in local key.
  * If AUTHENTICATION is RSA: Error in remote key.
* (ERR4): Error obtaining remote key.
* (ERR5): Error when trying to decrypt the challenge or signature.
  * If AUTHENTICATION is DES: Probable error in remote key.
  * If AUTHENTICATION is RSA: If the error occurs in the signature, the problem may be in the remote key (Public).
  * If the error is in the challenge, the problem may be in the local key (private).
* (ERR6): Error when decrypting session key.
  * If AUTHENTICATION is DES: Probable error in remote key.
  * If AUTHENTICATION is RSA: Error in the local key.
* (ERR7): Error when encrypting data (session established)".
* (ERR8): Error when decrypting data (session established)".
* (ERR9): Incompatible keys.
  * If in the CRYPTOGRAPHIC version it is 3.0 or 4.0, an (ERR9) means that the external Exchange keys used in the authentication process do not match at both ends. Even so, the editran message describing this error will be accompanied by another one that reports at each end the "Label" of the exchange key used (last 8 octets different from "blanks", out of the 64 octets of the label that identifies a key). In this way, both ends can verify that the External Key Interface correctly identifies the external exchange key that is actually intended to be used.

```
|   ERR01 - ERROR OBTAINING THE LABEL (LOCAL KEY) AT THE SIDE THAT STARTS  
|           THE SESSION.                                                        
|                                                                             
|   ERR02 - ERROR WHEN GENERATING THE CHALLENGE OR SIGNATURE.                     
|           * IF AUTHENT. DES, PROBABLE ERROR IN LOCAL KEY.                  
|           * IF AUTHENT. RSA, IF THE ERROR OCCURS IN THE SIGNATURE, LOCAL KEY 
|             INCORRECT.                                                        
|           * IF AUTHENT. RSA, IF THE ERROR OCCURS IN THE CHALLENGE,     
|             INCORRECT REMOTE KEY.                                           
|                                                                             
|   ERR03 - ERROR WHEN TRYING TO GENERATE SESSION KEY.                        
|           * IF AUTHENTICATION IS DES, ERROR IN THE LOCAL KEY.               
|           * IF AUTHENTICATION IS RSA, ERROR IN THE REMOTE KEY.              
|                                                                             
|   ERR04 - ERROR OBTAINING REMOTE KEY.                                    
|   ERR05 - ERROR WHEN TRYING TO DECRYPT THE CHALLENGE OR SIGNATURE.             |
|           * IF AUTHENT. DES, PROBABLE ERROR IN REMOTE KEY                  |
|           * IF AUTHENT. RSA, IF THE ERROR OCCURS IN THE SIGNATURE IT MAY BE A |
|             PROBLEM IN THE REMOTE KEY (PUBLIC).                          |
|           * IF AUTHENT. RSA, IF THE ERROR OCCURS IN THE CHALLENGE, IT IS  |
|             A PROBLEM IN THE LOCAL KEY (PRIVATE).                        |
|                                                                             |
|   ERR06 - ERROR WHEN DECRYPTING THE SESSION KEY.                            |
|           * IF AUTHENTICATION IS DES, ERROR IN THE REMOTE KEY.              |
|           * IF AUTHENTICATION IS RSA, ERROR IN THE LOCAL KEY.               |
|                                                                             |
|   ERR07 - ERROR WHEN ENCRYPTING DATA (SESSION ESTABLISHED).                        |
|                                                                             |
|   ERR08 - ERROR WHEN DECRYPTING DATA (SESSION ESTABLISHED).                     |
|                                                                             |
|                                                                             |
|   ERR09 - THE DECRYPTED CHALLENGE OR SIGNATURE DO NOT MATCH. THE KEYS |
|           USED ARE DIFFERENT AT BOTH ENDS.                        |
|           * IF AUTHENTICATION DES, ERROR IN THE LOCAL KEY.                  |
|           * IF AUTHENTICATION RSA AND THE CHALLENGE DOES NOT MATCH, ERROR IN THE   |
|             LOCAL KEY.                                                    |
|           * IF AUTHENTICATION RSA AND THE SIGNATURE DOES NOT MATCH, ERROR IN REMOTE KEY |
|                                                                             |
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-cics-en/utilities-and-codes/appendix-d.-cryptography-system-in-onesait-editran/encryption-errors.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
