> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-comun-z-os-en/editran-ff-instalacion-firma-y-verificacion-v7.1.1/otras-utilidades/consulta-de-los-dn-de-los-certificados.md).

# Querying certificate DNs

Editran/FF uses the certificate DN to control remote signers, so the DNs of the certificates used to sign the files must be provided to remote users. For this purpose, the script obten\_dn.sh is used, which writes the DNs to a file preceded by the sequence ‘\* ‘.

```
Displays certificates and exports their DNs to a file.
Operating system: z/os
 
Choose where you want to extract the information from:
1) Certificates with private key (.p12 or .pfx)
2) Public key certificates (.cer, .crt or .pfx)
3) RACF certificates
You can enter 'E' in any text input to exit.
Option:
```

Select 1 when you want to obtain the DN of a certificate that contains the private key. In that case, continue as follows. Here is an example:

```
Enter the path to the keystore: /u/edisign/rsc/keystore/keyStore.pfx
 
Enter the certificate alias: Test XAdES certificate
 
The certificate or certificates will be displayed below.
If you want to save them in a file, enter the directory path.
Optionally, you can also specify the file name.
On z/OS systems, you can use an MVS file (//'DSNAME')
Otherwise, press Enter without typing anything.
Destination (the MVS directory/file must exist): //'KI.EIDA.DN'
 
Certificate 1/1
   * Owner DN: CN=Test certificate for EDITRAN XAdES
   * Issuer DN: CN=EDITRAN Certification Authority
   * Serial number: 310000001fc3d07584a479c75000000000001f
   * Valid from: Thu Jun 11 11:09:15 GMT+01:00 2015
   * Valid until: Thu Jun 11 11:19:15 GMT+01:00 2020
   * Errors:
***************
 
Certificates saved in //'KI.EIDA.DN'
 
 
What do you want to do next?
1) Repeat the operation with a different alias
2) Repeat the operation with different data
3) Perform another operation
Option:
```

Choosing 2 will allow us to change the file containing the certificate; with option 3, it returns to the initial selection.

To obtain the DN of a certificate's public key or to list the CAs of a truststore, use option 2 of the initial menu. Below is the dialog for listing the CAs.

```
Enter the path to the certificate (.cer, .crt) or truststore (.pfx): /u/edisign/rsc/truststore/trustStore.pfx
The certificate or certificates will be displayed below.
If you want to save them in a file, enter the directory path.
Optionally, you can also specify the file name.
On z/OS systems, you can use an MVS file (//'DSNAME')
Otherwise, press Enter without typing anything.
Destination (the MVS directory/file must exist): /u/ki1056e
The certificates are shown numbered
Do you want to save all the certificates (Y/N)?: n
Enter the numbers of the certificates you want to save, separated by spaces: 12 16
Certificates saved in /u/ki1056e/trustStore.txt
What do you want to do next?
1) Repeat the operation
2) Perform another operation
Option:
```

If the certificates are stored in RACF, you must select option 3 of the initial menu, which will continue asking for the RACF user, the ring where the user stores the certificates, and the alias of the certificate whose DN you want to query:

```
Enter the RACF user: userid
Enter the RACF ring name: idanillo
Enter the certificate alias: aliascertRACF
The certificate or certificates will be displayed below.
If you want to save them in a file, enter the directory path.
Optionally, you can also specify the file name.
On z/OS systems, you can use an MVS file (//'DSNAME')
Otherwise, press Enter without typing anything.
Destination (the MVS directory/file must exist):
Certificate 1/1
   * Owner DN: CN=PruebaRACF, O=IndraSTI, C=ES
   * Issuer DN: CN=PruebaRACF, O=IndraSTI, C=ES
   * Serial number: 0
   * Valid from: Fri Feb 08 00:00:00 GMT+01:00 2019
   * Valid until: Sat Feb 08 23:59:59 GMT+01:00 2020
   * Errors:  This certificate has expired.
***************
 
What do you want to do next?
1) Repeat the operation with a different alias
2) Repeat the operation with different data
3) Perform another operation
Option:
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-comun-z-os-en/editran-ff-instalacion-firma-y-verificacion-v7.1.1/otras-utilidades/consulta-de-los-dn-de-los-certificados.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
