> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-cics-en/utilities-and-codes/appendix-d.-cryptography-system-in-onesait-editran/key-exchanges-without-exchange-key-management.md).

# Key exchanges without exchange key management

In cryptography version 3.00, it was already indicated that exchanges could be done with key management or without it.&#x20;

When they are done without key-exchange management, one end A generates a key and the other end B generates another. In this case, the generated (exchange) key may be:

* DES. In this case, it was already indicated that the exchanged keys were single or double (with limitations). Depending on the interface:
  * CRIPTOlib/DES
    * If you are going to generate and send a key, create it with a label (up to 64 octets) and associate it with a key of your choice. To generate it, the XSCDALTA JCL is provided. Finally, include the label in the editran profiles as the local key. It sends the key in cleartext to the remote side.
    * If you receive a key from the remote entity (in cleartext), associate it with any label you want and put it into your FICHKDES through the XSCDALTA JCL. Finally, include the label in the editran profiles as the remote key. The label can be up to 64 octets.
  * ICSF environment: This is done through ICSF's own panels.
  * If you are going to generate and send a key, create it with a label (which you will put into the editran profiles as the local key and which can be up to 64 octets) and associate it with a key of your choice. That key is of the exporter type and must be given to the remote side in cleartext. Finally, include the label in the editran profiles as the local key.
  * If you receive a key from the remote entity (in cleartext), associate it with any label you want (up to 64 octets) and put it into ICSF as an importer type. Finally, include the label in the editran profiles as the remote key.
* RSA
  * If you are going to generate and send a key. The XSCRKGEN JCL is provided. It includes 2 DDs (up to 64 octets each), in which you enter the label of the local private key and the label of the local public key. The system randomly generates a key and associates each part with each specific label. Through the XSCRKEXP JCL, indicating the label of the local public key, it exports it to a file, which it sends to the remote side. Finally, it includes the public label in the editran profiles as the local key
  * If you receive a public key from the remote entity (in cleartext), put it into a file. The XSCRKIMP JCL is provided, which reads that file. A DD is included (up to 64 octets), where you include the name of the label you will give to the remote public key you have received. Finally, include the label in the editran profiles as the remote key.

Example 1.

Entity A generates a DES key x’AA..AA’ associated with the label CLAVE-A-LOCAL-DES and sends the key x’AA..AA’ to entity B. Entity B generates a DES key x’BB..BB’ associated with the label CLAVE-B-LOCAL-DES and sends the key x’BB..BB’ to entity A. Entity A incorporates into its DES key file the key x’BB..BB’ with the label CLAVE-B-REMOTA-DES. Entity B incorporates into its DES key file the key x’AA..AA’ with the label CLAVE-A-REMOTA-DES.

In A's profiles&#x20;

```
| LOCAL KEY: CLAVE-A-LOCAL-DES                             |
| REMOTE KEY: CLAVE-B-REMOTA-DES                            |
```

In B's profiles:&#x20;

```
| LOCAL KEY: CLAVE-B-LOCAL-DES                             |
| REMOTE KEY: CLAVE-A-REMOTA-DES                            |
```

Note: Both CLAVE-A-LOCAL-DES and CLAVE-A-REMOTA-DES, although they are different labels, contain the same key. Both CLAVE-B-REMOTA-DES and CLAVE-B-LOCAL-DES, although they are different labels, contain the same key.

Example 2.

Entity A generates an RSA key with 2 labels CLAVE-A-LOCAL-RSA-PRIVADA and CLAVE-A-LOCAL-RSA-PUBLICA, this latter label associated with key x’AA..AA’, which it sends to entity B. Entity B generates an RSA key with 2 labels CLAVE-B-LOCAL-RSA-PRIVADA and CLAVE-B-LOCAL-RSA-PUBLICA, this latter label associated with key x’BB..BB’, which it sends to entity A. Entity A incorporates into its FICHKRSA file the key x’BB..BB’ with the label CLAVE-B-REMOTA-RSA-PUBLICA. Entity B incorporates into its RSA key file the key x’AA..AA’ with the label CLAVE-A-REMOTA-RSA-PUBLICA.

In A's profiles&#x20;

```
| LOCAL KEY: CLAVE-A-LOCAL-RSA-PRIVADA                     |
| REMOTE KEY: CLAVE-B-REMOTA-RSA-PUBLICA                    |
```

In B's profiles:&#x20;

```
| LOCAL KEY: CLAVE-B-LOCAL-RSA-PRIVADA                     |
| REMOTE KEY: CLAVE-A-REMOTA-RSA-PUBLICA                    |
```

Note: Both CLAVE-A-LOCAL-RSA-PUBLICA (does not appear in the profile) and CLAVE-A-REMOTA-RSA-PUBLICA, although they are different labels, contain the same key. Both CLAVE-B-REMOTA-RSA-PUBLICA and CLAVE-B-LOCAL-RSA-PUBLICA (does not appear in the profile), although they are different labels, contain the same key.

&#x20;


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-cics-en/utilities-and-codes/appendix-d.-cryptography-system-in-onesait-editran/key-exchanges-without-exchange-key-management.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
