> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-comun-z-os-en/editran-ff-instalacion-firma-y-verificacion-v7.1.1/instalacion-y-requisitos/instalar-en-uss.md).

# Install in USS

1. It is recommended to create a directory on the z/OS Unix partition (USS) to install the signature verification software, for example: /u/edisign.
2. Send, in binary mode, the package EditranSignature-zos.Vn.n-AAAA-MM-DD.tar to the USS. You can use any file transfer utility, such as ftp.
3. Connect to the USS and extract the file inside the created directory (u/edisign>tar -xof EditranSignatureServices-zos.V3.1.0-2024-04-10.tar). This will leave a structure like the one in the following example:

```sh
/u/edisign: >ls -l
drwxr-xr-x   2 KI10139  KISNCE      8192 May 25 12:19 bin
drwxrwxrwx   2 KI10139  KISNCE      8192 May 25 10:18 conf
drwxr-xr-x   2 KI10139  KISNCE      8192 May 25 09:55 crl
drwxr-xr-x   3 KI10139  KISNCE      8192 May 25 10:18 lib
drwxrwxrwx   2 KI10139  KISNCE      8192 May 25 10:28 logs
drwxr-xr-x   2 KI10139  KISNCE      8192 May 25 10:18 plantillas
drwxr-xr-x   2 KI10139  KISNCE      8192 May 25 10:18 politicas
drwxr-xr-x   4 KI10139  KISNCE      8192 Dec 17  2018 rsc
```

The product configuration scripts are in the bin directory and we must ensure they have write and execute permission. These scripts must be modified with the JAVA\_HOME directory of the installation and with the directory created to install the software (point 1), in the DIR\_XADES variable.

It is also recommended that the logs folder have write permission, at least, for the user group.

The server uses temporary files whose creation location will be indicated in the start\_xades.sh script by modifying the variable DIRTMP=/u/edisign/tmp (Optionally, by modifying the call parameter -Djava.io.tmpdir="/u/edisign/tmp").

4. Running */u/edisign/bin/configuracion\_xades.sh* the product configuration will be adapted to the own installation. The command returns:

```
#####EDITRAN/XAdES Configuration#####
```

The values with password (passProxy and passTrustStore) are stored encoded and the rest in plain text.

If desired, the plain text values can be edited with a plain text editor, but not the encoded values.

Value of the conf\xades.properties file

```
#EDITRAN/XAdES Parameters (Mandatory)
ipEditranXades=127.0.0.1
portEditranXades=7760
#Type of store from which the certificates are extracted. It can be FILE for the classic keystore system,
#HSM for cryptographic cards or RACF to use this system (only in z/OS).
tipoAlmacen=FICHERO
#Connection with remote EDITRAN/OCSP (Optional, fill in if remote EDITRAN/OCSP is used)
ipEditranOcsp=
puertoEditranOcsp=
#Connection with proxy for Internet connection. It is necessary in the case of wanting to use OCSP or CRL to verify the revocation
#of certificates or in the case of wanting to sign with TimeStamp, for which a connection with a server is needed
ipProxy=
puertoProxy=
userProxy=
passProxy=
#Operating System where EDITRAN/XAdES is installed. In the case of Windows, Unix or AS400 operating systems, its value must be N(No).
#In the case of z/OS operating systems, its value must be S(Yes)
zOS=S
#Properties of FILE mode
#TrustStore of the CAs (Mandatory)
pathTrustStore=rsc/truststore/trustStore.pfx
passTrustStore=********
#Default KeyStore (Optional)
pathKeyStore=rsc/keystore/keyStore.pfx
#Properties of HSM mode
#Path to the native HSM library (Mandatory)
pathLibreria=
#CA token (Mandatory)
tokenCA=
passTokenCA=
#Default signature certificate token (Optional)
tokenDefecto=
#Properties of RACF mode
#Username that accesses the default rings (Optional)
usuarioDefecto=
#Name of the ring with the default signature certificates (Optional)
anilloDefecto=
 
Modify the properties of the conf\xades.properties file? (Y/N)
```

By entering Y it will ask for the parameter values; only those that need to be changed must be entered.

In the Store Type option, the mode of obtaining the certificates needed for signing and the CAs that ensure the validity of the certificates is selected, both for signing and for verification. In File mode, the default mode, the certificates are obtained from files (.pfx), which is the system used in previous versions of the product. In RACF mode, these certificates must be included in that system, in rings accessible by a user.

If the certificates used in the applications need OCSP validation and this is done remotely, the Editran/OCSP server is needed, and the address and port where it is installed must be configured.

To be able to perform OCSP/CRL verification of the certificates and also signing with TimeStamp to connect to the server that time-stamps the signing time, a proxy will normally be needed to leave the Host, so in that case the proxy address and port, as well as a user and password, will have to be specified in order to access the Internet through it.

This configuration will be saved in the xades.properties file in the conf directory (in the example: /u/edisign/conf/xades.properties).

We describe all these properties below:

* Mandatory properties:
  * Editran/XAdES IP: IP on which the Editran/XAdES Java Server is started.
  * Editran/XAdES Port: Port on which the Editran/XAdES Java Server is started.
  * Store Type: The mode for obtaining the certificates for signing and the CAs. In File mode they are obtained from files (.pfx). In RACF mode, they are obtained from this system, stored in rings accessible to users. The CAs will be those marked as trusted by RACF.
* Mandatory properties of File mode:
  * Truststore path: This is the path of the certificate store where the certificate of all the CAs in which we must trust is stored.
  * Password: Password of the truststore.
* Optional properties:
  * Remote Editran/OCSP: Only necessary in the case of wanting to use Editran/OCSP remotely; by default it is used locally in the case of wanting to verify certificates.
  * Editran/OCSP IP: IP address of the machine where the Remote Editran/OCSP server is installed and running.
  * Editran/OCSP Port: Port of the Editran/OCSP server to be able to connect to it.
  * Proxy: Use of proxy for the Internet connection of Editran/XAdES. It is necessary in the case of certificate verification both by means of CRL or OCSP, and also for signing with TimeStamp to connect to the server that stamps the signature time:
    * Proxy IP: Port of the proxy with which Editran/XAdES needs to connect.
    * Proxy Port: Port of the proxy for the Internet connection.
    * Proxy User: In case it is necessary, proxy user for the Internet connection.
    * Proxy Password: Password of the proxy user.
* z/OS System: Indicates whether the system where the Java program is running is a z/OS machine or not.

5. To start and stop the process, the scripts will be used:

```
/u/edisign/bin/start_xades.sh
/u/edisign/bin//stop_xades.sh
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-comun-z-os-en/editran-ff-instalacion-firma-y-verificacion-v7.1.1/instalacion-y-requisitos/instalar-en-uss.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
