> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-cics-en/utilities-and-codes/appendix-d.-cryptography-system-in-onesait-editran/initial-concepts.md).

# Initial concepts

A key is always stored associated with a label. In the editran profiles, the labels that contain those keys are specified (or at least a reference that allows the label and key to be found, if exchange key management is used).

There are 3 types of cryptography: DES, RSA, and AES. To use any of them, different editran modules are required (and the remote system we connect to must also have them.

Licenses are required depending on which system is used:

* In DES:
  * CRIPTOlib/DES (product marketed by Indra, valid for all environments) or ICSF-CMOS cryptographic card (only in z/OS environments)
  * DES cryptography API (for CRIPTOlib/DES or ICSF-CMOS), marketed by Indra.
* In RSA:
  * Have a DES environment, with the licenses described above
  * CRIPTOlib/RSA (product marketed by Indra, valid for all environments)
  * RSA cryptography API for linking with the DES environment used, marketed by Indra.
* In AES:
  * Have an RSA environment, with the licenses described above
  * RSA cryptography API for linking with the AES environment used, marketed by Indra.
  * AES cryptography API.

DES cryptography can be performed in 2 ways:

* Hardware cryptography (z/OS environments only with a cryptographic card). ICSF-CMOS is used. To use it with editran, the editran API DES module for ICSF is required. The DES key file is called CKDS or MKDS.
* Software cryptography. To use it with editran, 2 Indra-owned modules are required: CRIPTOlib/DES and DES API for CRIPTOlib/DES. The DES key file is called FICHKDES (z/OS environments) or ckds.des (open environments)

The DES cryptography key file contains an entity master key, called HMK (Host Master Key) or installation master key. The product provides tools to add that first key to the file (in the case of software cryptography). In the case of z/OS with CRIPTOlib/DES, the JGENFICH JCL is provided, where FICHKDES is initialized and a key is incorporated that is entered twice in the JCL's SYSIN to avoid errors. If you list the file, you will no longer see the value you entered in clear text. Once the HMK has been entered, in z/OS 2 auxiliary keys must be entered. When in the local editran environment we indicate:&#x20;

```
|  LOCAL LABEL.....: xxxxxxxx            REMOTE LABEL....: yyyyyyyy           |
```

We are indicating those auxiliary keys (through 2 labels that contain the keys), which will be important in the installation, since they will be used to encrypt, generate, and re-encrypt other keys, so that they remain hidden in the different places where the latter are stored. These 2 labels store simple DES keys, 8 octets long), whose value must be identical in both. editran tools are provided to incorporate those auxiliary keys into FICHKDES: JCL ZTBSJCR (CRIPTOlib/DES) or ZTBSJICS (ICSF-CMOS). In the latter, there are panels where the chosen label and the chosen key are indicated. The local label contains an EXPORTER-type key and the remote label contains an IMPORTER-type key. The keys that are generated are random; they are not specified in the JCL, they are created by the program being called. Once both keys have been incorporated into the corresponding DES environment and into the local environment, cryptography can begin to be used.

In open environments, usually the previous DES cryptography steps come "preinstalled". When the product is installed, the ckds.des file with the above keys is generated automatically. If you want to start from scratch, creating your own keys (this process can only be done when no editran sessions have been created), rename the old ckds.des and run the command pinsdes xxxxxxxxxxxxxxxx yyyyyyyyyyyyyyyy in an MSDOS window over the installed editran directory (x and y are the same values, for HMK confirmation, which is 16 hexadecimal characters, the last 8 octets), so that the HMK will be created. Next, for the AUXILIARY key, enter the command introsec SI000000000016 yyyyyyyyyyyyyyyy (SI000000000016 is the label. The rest is the value of that key, which must have odd parity

When RSA cryptography is used, in addition to having a DES environment, 2 modules are required: CRIPTOlib/RSA + RSA API (for ICSF-CMOS or for CRIPTOlib/DES). It is software encryption, owned by Indra, that simulates the functions of RSA cryptography. When RSA is used, a file called FICHKRSA is created in z/OS (in open environments it is called ckds.rsa). It is necessary to incorporate into the DES environment we have a label associated with a DES key, which will be used to encrypt all the RSA keys that we incorporate into the FICHKRSA. In z/OS, a JCL XSCRFILE is provided, which initializes the FICHKRSA, and through 2 SYSINs 2 labels are incorporated (up to 64 octets in this case), so that the program initializes the control record of that file with the 2 DES keys that protect it (application-form keys together with the labels). Next, the program in a later step generates a random odd-parity key (the one that encrypts the previous 2), and incorporates it twice into the entity's DES file (ICSF or CRIPTOlib), once with the first label (local or exporter type) and once with the second label (remote or importer)

In open environments, usually the previous RSA cryptography steps are achieved by running the command inst\_rsa xxxxxxxxxxxxxx (x is a 14-character label) in an MSDOS window over the installed editran directory

RSA cryptography is based on the following:

* A key has 2 parts, private part and public part, each stored with a different label.
* Anyone can know the public part without integrity risk
* Both ends exchange the public part of their respective keys. The private part is never exchanged. It is owned by the entity that generated the RSA key. Not even it can see it in clear text.
* With the remote public part, DES keys are encrypted, (which will then be used to encrypt the data). The only one capable of decrypting this DES key (and then decrypting the data) is the entity that has the private part of the associated RSA key.
* With the private part, texts are signed. Whoever has the public part of the previous private one can recognize who signed it, (since only the one who had the private key could have signed it)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-cics-en/utilities-and-codes/appendix-d.-cryptography-system-in-onesait-editran/initial-concepts.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
