> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-ims-en/firma-electronica/funciones-interactivas-de-onesait-editran-ff/administrador-de-onesait-editran-ff.md).

# Onesait Editran/FF Administrator

This menu is accessed with option 2 of the general menu.

```
 ------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS                    ADMINISTRATOR                                  |
 ------------------------------------------------------------------------------
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                        1  LOCAL ENVIRONMENT                                  |
|                                                                              |
|                        2  LOCAL AND REMOTE USERS                             |
|                                                                              |
|                        3  SIGNATURE APPLICATIONS                             |
|                                                                              |
|                                                                              |
|                                                                              |
|                                       OPTION :                               |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
 ------------------------------------------------------------------------------
```

## Local environment <a href="#toc8743196" id="toc8743196"></a>

This screen is accessed with option 1 of the administrator menu.

```
 ------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS                    LOCAL ENVIRONMENT                               |
------------------------------------------------------------------------------
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                               A  ADD                                         |
|                                                                              |
|                               C  INQUIRY                                     |
|                                                                              |
|                               M  MODIFICATION                                |
|                                                                              |
|                                                                              |
|                                                                              |
|                                       OPTION :                               |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
------------------------------------------------------------------------------
```

The Local Environment (unique) will be created, where the following screen will appear:

```
------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS                 INQUIRY OF ENVIRONMENT                            |
------------------------------------------------------------------------------
|                                                                              |
|                                                               VERSION 7.1.1  |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
| FILE NAME PREFIX: KI.EGTI.FF                                                 |
|                                                                              |
| SIGNATURE SERVER (ESS):                             port:       T/O     s |
| 172.022.242.193                                              07771     999   |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
------------------------------------------------------------------------------
```

The meaning of each of the fields is as follows.

* **FILE NAME PREFIX**: Maximum 11 bytes. Used to define intermediate files and, optionally, application reception files. It must comply with MVS rules regarding the length of dot-separated segments.
* **SIGNATURE SERVER (ESS)**: is the address of the Java server that provides signature services and their verification; it is installed in USS.
* **Port**: Listening port of the Java server.
* **T/O**: indicates the number of seconds the client waits for its request to be handled by the server. The value 999 means an indefinite wait.

## Users <a href="#toc8743197" id="toc8743197"></a>

This screen is accessed with option 2 of the administrator menu.

```
 ------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS                       USERS                                      |
------------------------------------------------------------------------------
|                                                                              |
|                                                                              |
|                               A  ADD                                         |
|                                                                              |
|                               B  DELETE                                     |
|                                                                              |
|                               C  INQUIRY                                     |
|                                                                              |
|                               M  MODIFICATION                                |
|                                                                              |
|                                                                              |
|                                                                              |
|                                  OPTION           : _                        |
|                                  USER TYPE       : _  (Local/Remote)        |
|                                  ENTITY CODE     : _ _______ _              |
|                                  USER NAME       : _______________          |
|                                                                              |
|                                                                              |
|                                                                              |
------------------------------------------------------------------------------
```

We must enter

* the option,
* the user type (local, for our own users, or remote for users from other entities),
* the code of the entity to which the user belongs (Editran local code for local users and the remote entity code for remote users),
* and the name with which we will internally identify the user.

The user name may contain any character, uppercase and lowercase letters, or spaces.

If the user is local, the entity code indicated is the Editran local code. If there were several local codes, sub-environments, different users could be created for each of the sub-environments. A local user can only be used in Editran transmissions for that local code. Local user names may be repeated in other local codes and are considered different users.

If the user is remote, the entity code corresponds to the remote code of the Editran session. Remote user names may be repeated in other entity codes.

Deleting the user is not allowed if it is associated with any rule. Modifying the user is propagated to all the rules in which it appears.

In the add option, all data must be filled in. In the others, we can type only part of it and use '\*' as wildcards. If not all fields are typed in, a list of users will be shown that we can select.

The screen is as follows.

```
------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS               USER MODIFICATION                                   |
------------------------------------------------------------------------------
|  TYPE: LOCAL           ENTITY: 0 0009998 0         USER:                  |
|                                                                              |
|                                                                              |
| SEL   TYPE     ENTITY        USER              ALIAS / DN / PATH         |
| ---  ------  -----------  ---------------  --------------------------------- |
|      LOCAL   0 0009998 0  administrator    prueba.cer                        |
|      LOCAL   0 0009998 0  proxy          Email=fjaraba@indra.es, C=ES, ST= |
|      LOCAL   0 0009998 0  treasurer       fjn.cer                           |
|      LOCAL   0 0009998 0  user            C=ES, ST=Madrid, L=Madrid, O=INDR |
|      LOCAL   0 0009998 0  local user      C=ES, ST=Madrid, L=Madrid, O=INDR |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
------------------------------------------------------------------------------
```

The header shows the fields that were entered in the previous menu.

* **TYPE** (header): Local or remote.
* **ENTITY** (header): Local or remote code.
* **USER** (header): User name.

The inquiry lines will display

* **SEL**: Selection field. By typing 'S' and pressing \<ENTER>, the user is selected.
* **TYPE**: Local or remote user type.
* **ENTITY**: Local or remote code to which the user belongs.
* **USER**: User name.
* **ALIAS / DN**: Alias of the local user's certificate or DN (identification) of the remote user's certificate.

If all data are typed on the first screen, or the session is selected from the list, the corresponding user screen will appear.

**LOCAL**

```
------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS                   USER ADDITION                                   |
------------------------------------------------------------------------------
|            ENTITY: 0 0009998 0             USER: User1                      |
|                                                                              |
|                                                                              |
|   LOCAL CERTIFICATE ALIAS:                                                   |
|   user1                                                                     |
|                                                                              |
|                                                                              |
|   KEYSTORE PATH:                                                            |
|   rsc/keystore/user1.pfx                            |
|                                                                              |
|                                                                              |
|                                                                              |
|   RACF USER:                                                                |
|                                                                              |
|   KEYRING:                                                                  |
|                                                                              |
|                                                                              |
|                                                                              |
| <PF5> Rule Inquiry                                                          |
------------------------------------------------------------------------------
```

The meaning of the fields is as follows.

* **LOCAL CERTIFICATE ALIAS**: It is the alias of the certificate that allows it to be identified within the keystore or within the keyring. It accepts uppercase and lowercase letters.

There are two types of certificates to use.

* Certificates contained in a keystore
  * **KEYSTORE PATH**: For certificates contained in a keystore, the keystore path will be indicated. The user alias and the path, as well as any associated password, must be registered in the EditranSignatureServices server using the gestor\_claves.sh utility.
* RACF certificates.
  * **RACF USER**: This is the owner of the RACF certificate
  * **KEYRING:** It is the keyring in which the RACF certificate is included

**REMOTE**

```
------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS                   USER ADDITION                                   |
------------------------------------------------------------------------------
|            ENTITY: 0 0009998 0             USER: User1                      |
|                                                                              |
|                                                                              |
|   REMOTE CERTIFICATE IDENTIFICATION (D/P): P (DN, PATH)                   |
|   DN/PATH                                                                    |
|   User1.cer                                                               |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
| <PF5> Rule Inquiry                                                          |
------------------------------------------------------------------------------
```

**REMOTE CERTIFICATE IDENTIFICATION**:'. You can choose between **D** for the DN corresponding to the public digital certificate or **P** for the path where the public digital certificate file is located.

**DN**: 'Distinguished name'. It corresponds to the DN of the digital certificate with which the files will be signed. It is one of the two ways to identify the certificate. If we do not know the DN, we can obtain it from the ZTBFFSAL file

**PATH**: It corresponds to the relative or absolute path where the public digital certificate file with which the files will be signed is located.

If on the user screen we press \<PF5>, we can consult the rules to which the user is associated and the groups in which it is included.

```
 ------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS             INQUIRY OF ASSOCIATED RULES                          |
------------------------------------------------------------------------------
|                                                                              |
|     USER: USER1          TYPE: REMOTE   ENTITY CODE: 000099980      |
|                                                                              |
|          SESSION             STANDARD     COMPANY          GROUP        F   CTF  |
| --------------------------  -----  -------------  ---------------  ---  ---  |
| A00099980 000099980 EDTRFF                                          S        |
| A00099980 000099980 EDTRFF   19                                     S        |
| A00099980 000099980 EDTRFF   19    J67306086                        S        |
| A00099980 000099980 EDTRFF   19    J67306086 ???                    S        |
| A00099980 000099980 EDTRFF   34                                     S        |
| A00099980 000099980 EDTRFF   34    85502452K ???                    S        |
| A00099980 000099980 EDTRFF   34    85502452K 001                    N    S   |
| A00099980 000099980 PEPITO                        Group             S        |
| A00099980 000099980 PRURFF                        Group             N        |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
 ------------------------------------------------------------------------------
```

The header shows the fields being queried.

* **USER**: Current user name.
* **TYPE**: Local or remote, of the current user.
* **ENTITY CODE**: If the user is local, the local code will appear; if remote, the remote code will appear.

The inquiry lines will display

* **SESSION**: Application to which the user was associated.
* **STANDARD**: Banking standard of the rule in which the user is included.
* **COMPANY**: Tax ID number and suffix of the rule in which the user is included.
* **GROUP**: Group to which the user belongs, or spaces if it does not belong to a group.
* **F**: The user can sign.
* **CTF**: The user countersigns.

## Applications (presentation sessions) <a href="#toc8743198" id="toc8743198"></a>

This screen is accessed with option 3 of the administrator menu.

```
 ------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS                SIGNATURE APPLICATIONS                            |
------------------------------------------------------------------------------
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                    1  GENERAL APPLICATION PARAMETERS                        |
|                                                                              |
|                    2  APPLICATION SIGNING RULES                             |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                       OPTION :                               |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
 ------------------------------------------------------------------------------
```

With option 1 we will create the presentation sessions.

The screen is as follows.

```
------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS          GENERAL APPLICATION PARAMETERS                          |
------------------------------------------------------------------------------
|                                                                              |
|                            A  ADD                                           |
|                                                                              |
|                            B  DELETE                                       |
|                                                                              |
|                            C  INQUIRY                                     |
|                                                                              |
|                            M  MODIFICATION                                   |
|                                                                              |
|                            R  ADD WITH COPY                                 |
|                                                                              |
|                               OPTION       :                                 |
|                               LOCAL CODE : 0 0009998 0                     |
|                               REMOTE CODE: 0 0009992 0                     |
|                               APPLICATION : EDTRF1                          |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
------------------------------------------------------------------------------
```

We must enter

* **OPTION :** (A)dd, (D)elete, (I)nquiry, (M)odification or (R) Add with copy&#x20;
* **LOCAL CODE**
* **REMOTE CODE**
* **APPLICATION**: application of the Editran session that will use file signing.

Deleting the session implies deleting all associated groups and users that depend on it. Add with session copy copies all local groups and users to the new session when the local code of the source session matches that of the target session, and copies all remote groups and users when the remote codes match.

In the add option, all data must be filled in. In the others, we can type only part of it using '\*' as wildcards.

In the add with copy option, after filling in the source session and pressing \<ENTER>, the target session will be requested.

```
------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS          GENERAL APPLICATION PARAMETERS                          |
------------------------------------------------------------------------------
|                                                                              |
|                            A  ADD                                           |
|                                                                              |
|                            B  DELETE                                       |
|                                                                              |
|                            C  INQUIRY                                     |
|                                                                              |
|                            M  MODIFICATION                                   |
|                                                                              |
|                            R  ADD WITH COPY                                 |
|                                                                              |
|                               OPTION       : R            IN THE SESSION    |
|                               LOCAL CODE : 0 0009998 0  0 0009998 0        |
|                               REMOTE CODE: 0 0009992 0  0 0009994 0        |
|                               APPLICATION : EDTRF1       EDTRF1             |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
------------------------------------------------------------------------------
```

If a field was not typed on the initial screen, a list of sessions will be shown.

```
------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS               APPLICATION INQUIRY                                |
------------------------------------------------------------------------------
|                    APPLICATION: 000099980                                   |
|                                                                              |
|                            EMI VAL     ATT    TEMPLATE                      |
| S        APPLICATION        REC CER SIG DET    POLICY      FTO LRECL TRA CC |
| - ------------------------ --- --- --- --- ---------------- --- ----- --- -- |
|   000099980A00099980EDTRFF  E       X   A  pln-di-i-EPES-AG                  |
|   000099980000000010EDTRFF  R   N   X   C                    V  02000  N  N  |
|   000099980000099920EDTRFF  E       X   A                                    |
|   000099980000099920EDTRF1  E       X   A                                    |
|   000099980000099930EDTRFF  E   N   X   D                                    |
|   000099980000099940EDTRFF  E   N   X   A                    F  04096  N  S  |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
------------------------------------------------------------------------------
```

The inquiry lines will display

* **S**: Field for selection. By typing 'S' and pressing \<ENTER>, the session is selected.
* **APPLICATION**: Local code, remote code and application.

The following fields are described on the session screen.

* **EMI REC**: Application type, Emission or Reception.
* **VAL CER**: Type of validation that will be performed on the certificates used.
* **SIG**: Signature type, PKCS#7 or XAdES.
* **ATT DET**: Attached or Detached (signing mode).
* **TEMPLATE POLICY**: Template in emission applications and policy in reception applications.
* **FTO**: Reception file format.
* **LRECL**: Reception file length.
* **TRA**: Translate alphabet.
* **CC**: Remove carriage returns.

For the add, add with copy, delete, inquiry and modification options, if all data are typed on the initial screen, or the session is selected from the list, the following session screen appears.

```
------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS             APPLICATION MODIFICATION                             |
------------------------------------------------------------------------------
|                    APPLICATION: A00099980 000099980 EDTRFF                  |
| GENERAL PARAMETERS                                                         |
|  APPLICATION TYPE (E/R).........: R                                        |
|  OCSP/CRL VERIFICATION (N/O/C/A)..: N                                       |
|  SIGNATURE TYPE (P/X)..............: X          SIGNATURE MODE (A/C/D): A   |
|  XAdES SIGNATURE TEMPLATE.......:                                          |
|  XAdES SIGNATURE VERIFICATION POLICY: plt-firma-AGE-v1-8.xml               |
|  NAME OR DIRECTORY OF SIGNATURE FILES:                                      |
|                                                                              |
|                                                                              |
| APPLICATION FILES                                                           |
|  DELETE IF THEY EXIST (Y/N)......: S   ADAPT SIGNED FILE (Y/N).: S         |
|  NAME: KI.EIDA.R%C                                   (DSN)                 |
| FORMATTING PARAMETERS FOR RECEIVED FILES                                    |
|  RECEPTION FILE FORMAT (F/V/E).: V   RECEIVED REC. LENGTH (1-32756): 01024  |
|  TRANSLATE ON RECEPTION (A/E/N): E   RECEPTION CONVERSION TABLE:           |
|  REMOVE DELIMITERS (Y/N)..: N   RECORD DELIM. (HEXADECIMAL)..:             |
|                                                                              |
|                                                                              |
------------------------------------------------------------------------------
```

* **APPLICATION TYPE (E/R)**: Emission, to sign the files to be sent, and Reception, to verify the signature of received files.
* **OCSP/CRL VERIFICATION (N/O/C/A)**: Indicates the type of validation to be performed on the certificates, using OCSP verification, CRL, None, or the one indicated by the certificate itself, in which case 'A' will be entered.
* **SIGNATURE TYPE (P/X)**: Indicates whether the signature follows the PKCS#7 standard (*Public-Key Cryptography Standards*) or the XAdES standard (*XML Advanced Electronic Signatures,* up to XAdES - EPES protection level).
* **SIGNATURE MODE (A/C/D)**: Allows you to choose whether the signed data and the signature will be in the same file or in separate files. With Attached format, the signature is contained in the signed file; with Detached, each user's signature will be contained in a signature file. Mode C is the one that implements the format chosen by Iberpay for the XAdES signature type.
* **XAdES SIGNATURE TEMPLATE**: only for XAdES emission applications, indicates which XAdES signature template you want to apply to the signatures of this application. If that template specifies a policy, the generated signatures will be XAdES -EPES type; if the template does not indicate that feature or if no template is specified, the signature will be XAdES - BES type. (\*)
* **XAdES SIGNATURE VERIFICATION POLICY**: only for XAdES reception applications, indicates the XML file that contains the policy with which the application's signatures must be validated. If specified, the signatures will be XAdES - EPES; otherwise they will be XAdES - BES. (\*)

> ℹ️(\*) Only the document name is entered; it must reside in the “templates” / “policies” directory of the USS installation. These directories will be created when installing the Java server and contain the documents that allow signatures to be created and verified according to AGE criteria (*General State Administration*).
>
> With signing mode 'C', the template must be specified: pln-di-e-unfich-BES.xml
>
> Any other template/policy that is to be used will have to be included in these directories.

* **NAME OR DIRECTORY OF SIGNATURE FILES**: specifies the name of the HFS file or USS directory that will contain the signatures. If the signing mode is Detached, only the name of a directory may be specified; the signature file will be called (within that directory) the same as the data file to be signed plus the extension corresponding to the signature type, ".xsig" or ".p7b". When the signature is Attached, a file name may be entered (which will contain the data and the signatures) according to the rules used in Editran (see the Presentation Session section of the Administration and Operations manual); in this case, if a directory is specified, it will proceed as in Detached mode.

> ℹ️Keep in mind that the generated name must not exceed 44 characters in order to be sent by the application if the remote version is lower than 5.2.

The following parameters apply only when receiving files.

* **DELETE IF THEY EXIST (Y/N)**: 'S', the previously received file will be deleted if it exists. 'N', received files will be accumulated in a presentation as long as there is an adaptation process (ADAPT SIGNED FILE: S).
* **ADAPT SIGNED FILE (Y/N)**: Indicates that the received file will be formatted after signature verification. When the XML signing process needs to transform the data file in order to sign it, on reception the file must be adapted to its original format; this is done in a process after signature verification.
* **NAME**: It is the name of the final destination of the received application files. The file name must match the one included in the first Editran session screen. (general menu option 1.4)

The following parameters apply only when file adaptation is performed.

* **RECEPTION FILE FORMAT (F/V/E)**: The formatted file will have fixed, variable, or extended variable record format (RECFM=FB, VB or VS).
* **RECEIVED REC. LENGTH (1-32756)**: Size of the record in the formatted file.
* **TRANSLATE ON RECEPTION (A/E/N)**: Indicates the alphabet in which the formatted file is desired if it is translated.
* **RECEPTION CONVERSION TABLE**: Indicates the Editran character conversion table that is applied to the file once translated.
* **REMOVE DELIMITERS (Y/N)**. RECORD DELIM. (HEXADECIMAL): Allows removal of the delimiters that ASCII machines place in text files. The hexadecimal values to be removed must be indicated. For a DOS file the delimiter is usually x'0D0A' and for a UNIX file x'0A'. The characters will be removed at any position in the file because the filter is applied to a file without record format. It should not be applied to files that are not text files.

## Application signing rules

This screen is accessed with option 3.2 of the administrator menu.

```
------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS                   SIGNING RULES                                  |
 ------------------------------------------------------------------------------
|                                                                              |
|                                                                              |
|                              A  ADD                                          |
|                                                                              |
|                              B  DELETE                                       |
|                                                                              |
|                              C  INQUIRY                                     |
|                                                                              |
|                              M  MODIFICATION                                 |
|                                                                              |
|                                 OPTION    : C                                |
|                                 EMI-REC   : R                                |
|                                 APPLICATION: A00099980000099980EDTRFF         |
|                                 STANDARD  : 34                               |
|                                 COMPANY   : 85502452K001                     |
|                                                                              |
|                              ('*' for generic selection of STANDARD and COMPANY) |
|                                                                              |
|                                                                              |
 ------------------------------------------------------------------------------
```

We must enter

* the option,
* E for emission R for reception
* the local code, the remote code, and the session application.
* the standard,
* the company.

In all options it is mandatory to fill in **EMI-REC**

In the add option, all data must be filled in. In the others, we can type only part of it using '\*' as wildcards.

If no standard or company is entered, it is understood to be a generic rule. '\*' can be used as a wildcard.

In emission we cannot enter standard or company

If a standard is entered, the rule will apply to files belonging to that standard. Standards 19 and 34 are accepted.

The company is made up of the Tax ID (9 positions) and suffix (3 positions). These Tax ID and suffix values are obtained from the file submitter identification and, if absent, from the identification of the first ordering party (standard 34) or the identification of the first creditor (standard 19). To define a company that can be applied to a Tax ID and all suffixes, we can enter the Tax ID and suffix "???". If we type a company, it is mandatory to include the standard.

For a reception application, multiple rules can be defined, without standard, with standard and without company, and with standard and company.

Rule validations are performed in order from most to least restrictive.

* If the file has a standard, only the rules for that standard are validated.
  * First, the rule with matching Tax ID and suffix from the file will be applied
  * If there is none, the one that matches the Tax ID and has no suffix defined ("???") will be applied
  * If none matches, the rule without Tax ID or suffix will be applied
* If the file has no standard, the generic rule is applied

If no standard or company is entered in the inquiry option, the generic rule will be queried specifically. To query all the rules of an application generically, enter \* in standard and company.

### **Rule screen**

If in the initial screen the option, EMI-REC and the application are filled in, and optionally standard and company, the rule management screen will appear.

```
------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS                RULE MODIFICATION                                 |
 ------------------------------------------------------------------------------
|   APPLICATION: A00099980000099980EDTRFF   STANDARD: 19   COMPANY: J67306086???   |
|   EMI-REC: RECEPTION                                                       |
|                                                                              |
|   TOTAL NUMBER OF SIGNATURES  : 001                                          |
|   REQUIRED NUMBER OF GROUPS    : 001                                          |
|                                                                              |
|                                                                              |
|                                 U  USER                                      |
|                                                                              |
|                                 G  GROUP                                     |
|                                                                              |
|                                    OPTION: U                                 |
|                                    NAME: User1                          |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
 ------------------------------------------------------------------------------
```

The selection fields appear in the header.

* **APPLICATION** (header): Local code, remote code and application.
* **STANDARD** (header): Banking rule.
* **COMPANY** (header): Company composed of NIF plus suffix.
* **EMI-REC** (header): Issuance/Reception)
* **TOTAL NUMBER OF SIGNATURES**: Number of signatures expected in the rule. This parameter applies only in reception.
* **REQUIRED NUMBER OF GROUPS**: Number of user groups expected in the rule. This parameter applies only in reception.
* **OPTION**: User or group. In issuance, groups are not allowed
* **NAME**: Group or user name. The name can be entered in the following ways:
  * Leave blank: A new screen will appear with all users or groups (whichever is specified in the option parameter)
  * Partially enter using the wildcard ‘\*’ at the beginning or end of the name: A new screen will appear with all users or groups (whichever is specified in the option parameter) that meet the rule
  * Entering the full name: The user screen or the group screen will appear, depending on what is entered in the option parameter.

### **Reception user scroll screen.**

If the user is not filled in or is partially filled in, for a reception rule, the following screen will appear

```
------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS               USER MODIFICATION                                   |
 ------------------------------------------------------------------------------
|   APPLICATION: A00099980000099980EDTRFF   STANDARD: 19   COMPANY: J67306086???   |
|   EMI-REC: RECEPTION   SIGNATURES: 003     GROUPS:  000                          |
|                                                                              |
| S        GROUP          USER     COUNTERSIGNER  SIG CTS AMOUNT (P/T)    |
| -   --------------- --------------- --------------- --- --- -------------    |
|                     User1                         S                       |
|                     User2                         S                       |
|                     User3                         S                       |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
 ------------------------------------------------------------------------------
```

* **APPLICATION** (header): Local code, remote code and application.
* **STANDARD** (header): Banking rule.
* **COMPANY** (header): Company composed of NIF plus suffix.
* **EMI-REC** (header): Issuance/Reception
* **SIGNATURES** (header): Number of mandatory signatures in the rule
* **GROUPS** (header): Number of mandatory groups in the rule

The inquiry lines will display

* **S**: Select a line
* **GROUP**. Name of the group to which the user belongs within the rule
* **USER**. User name
* **COUNTERSIGNER**. Countersigner name
* **SIG**: The user signs files
* **CTF**: The user is a countersigner
* **AMOUNT (P/T):** Maximum amount authorized for the user per operation (partial) or for the total file.

If a user is selected, the user screen will appear, whose content is described below.

### **Reception group scroll screen.**

If the group is not filled in or is partially filled in, for a reception rule, the following screen will appear

```
------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS                GROUP MODIFICATION                             |
 ------------------------------------------------------------------------------
|   APPLICATION: 000099930000099980EDTEFF   SIGNATURES: 000  GROUPS: 000            |
|   RECEPTION                                                                  |
|                                                                              |
| S    RULE      COMPANY            GROUP         OBLIG. SIGNS    OBLIG. GROUP |
| -    -----    ------------    ---------------    ------------    ----------- |
|       34      J67306086???    Group1                 000             N       |
|       34      J67306086???    Group2                 000             N       |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
 ------------------------------------------------------------------------------
```

* **APPLICATION** (header): Local code, remote code and application.
* **SIGNATURES** (header): Number of mandatory signatures in the rule
* **GROUPS**(header): Number of mandatory groups in the rule
* **RECEPTION** (header): This is a reception rule

The inquiry lines will display

* **S**: Select a line
* **STANDARD** : Banking rule.
* **COMPANY** : Company composed of NIF plus suffix
* **GROUP**. Name of the rule's group
* **OBLIG. SIGNS**. : Number of mandatory signatures for that group
* **OBLIG. GROUP**. : Indicates whether the group is mandatory or not

ℹ️If a group is selected, the screen for[ group](#pantalla-de-grupo-solo-recepcion) whose content is described below.

### **Reception user screen.**

If a user is filled in, for a reception rule or a user is selected in the reception user scroll screen, the following screen will appear

```
------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS               USER MODIFICATION                                   |
 ------------------------------------------------------------------------------
|   APPLICATION: A00099980000099980EDTRFF   STANDARD: 19   COMPANY: J67306086???   |
|   EMI-REC: RECEPTION    USER: User1                                    |
|   GROUP: TREASURERS             REQUIRES COUNTERSIGNATURE (Y/N): N                 |
|   SIGN FILES (Y/N): S  COUNTERSIGNING USER:                       |
|   MAXIMUM TOTAL AMOUNT: 000010000 MAXIMUM PARTIAL AMOUNT:                    |
|   COUNTERSIGN FILE(S/Y/N):                                                  |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|   PATH OF THE PUBLIC REMOTE CERTIFICATE:                                       |
|   User1.cer                                                               |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
 ------------------------------------------------------------------------------
```

* **GROUP**: If we leave this field blank, the user will not belong to any group. We can include it in a group by typing the group name.
* **SIGN FILES (Y/N)**: The user can sign files. The signing user cannot countersign.
* **REQUIRES COUNTERSIGNATURE (Y/N):** The user's signature must be countersigned.
* **COUNTERSIGNING USER**: This is the name of the user associated with the rule who must countersign. The countersigning user must have countersign permission
* **MAXIMUM TOTAL AMOUNT**: Maximum amount authorized for the user for the total of the file's operations. This parameter applies only to reception rules. A single amount, total or partial, or none, can be entered. In rules without a rule, amounts cannot be entered.
* **MAXIMUM PARTIAL AMOUNT**: Maximum amount authorized for the user per operation. This parameter applies only to reception rules. A single amount, total or partial, or none, can be entered. In rules without a rule, amounts cannot be entered.
* **COUNTERSIGN FILE(S/Y/N)**: The user can countersign files. The user who countersigns cannot sign.
* **REMOTE CERTIFICATE IDENTIFICATION**: This is the DN/PATH of the user record that was supplied in option 2.2 of the Editran/FF menu and is shown here for information. Its meaning was indicated in the Users section

### **Issuance user screen**

If a user is filled in, for an issuance rule or a user is selected in the issuance user scroll screen, the following screen will appear

```
------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS               USER MODIFICATION                                   |
 ------------------------------------------------------------------------------
|   APPLICATION: 000099980A00099980EDTRFF   RULE:      COMPANY:                |
|   EMI-REC: ISSUANCE      USER: User1                                    |
|                                REQUIRES COUNTERSIGNATURE (Y/N): N                 |
|   SIGN FILES (Y/N): S  COUNTERSIGNING USER:                       |
|   MAXIMUM TOTAL AMOUNT:           MAXIMUM PARTIAL AMOUNT:                    |
|   COUNTERSIGN FILE(S/Y/N):                                                  |
|   SIGNER ROLE:                                                          |
|   ACTION ON THE DOCUMENT:                                                 |
|   PLACE OF SIGNATURE                                                          |
|   CITY:               PROV:               ZIP CODE:        COUNTRY:                 |
|   LOCAL CERTIFICATE ALIAS:                                                   |
|   user1                                                                     |
|   KEYSTORE PATH:                                                            |
|   rsc/keystore/user1.pfx                                                |
|                                                                              |
|   RACF USER:                                                                |
|   KEYRING:                                                                  |
|                                                                              |
|                                                                              |
 ------------------------------------------------------------------------------
```

Amounts will not be entered in issuance rules

Additional fields can be filled in

* **PLACE OF SIGNATURE**: If desired, the CITY, PROVINCE, POSTAL CODE and COUNTRY where the signature is made will be entered

The following fields are selected from the AGE policy supplied with the installation (plt-firma-AGE-v1-8.xml).

* **SIGNER ROLE**: Defines the role of the person in the electronic signature.
* **ACTION ON THE DOCUMENT**: Defines the signer's action on the signed document.
* **LOCAL CERTIFICATE ALIAS, RACF USER KEYSTORE PATH and KEY RING**: These are the user record data that were supplied in option 2.2 of the Editran/FF menu and are shown here for information. Their meaning was indicated in the Users section

### **Group screen (reception only)**

If a group is filled in, in a reception rule or a group is selected in the reception group scroll screen, the following screen will appear. In issuance, groups are not allowed.

```
------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS                GROUP MODIFICATION                             |
 ------------------------------------------------------------------------------
|   APPLICATION: A00099980000099980EDTRFF   STANDARD: 19   COMPANY: J67306086???   |
|   EMI-REC: RECEPTION    GROUP:   Treasurers                                   |
|                                                                              |
|   REQUIRED SIGNATURES IN THE GROUP: 001 MANDATORY GROUP (Y/N): S            |
|   MAXIMUM TOTAL AMOUNT: 000010000      MAXIMUM PARTIAL AMOUNT: 000005000     |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
------------------------------------------------------------------------------
```

* **REQUIRED SIGNATURES IN THE GROUP**: Indicates the minimum number of users that must sign in order to fulfill the group.
* **MANDATORY GROUP (Y/N)**: Indicates whether it is mandatory for the group to be fulfilled. The group is fulfilled when the mandatory signatures are reached.
* **MAXIMUM TOTAL AMOUNT and MAXIMUM PARTIAL AMOUNT**, for information purposes, indicate the highest amount value by total file or by operation that the users in the group have.

### **Deactivation of rules and associated users**

If in the initial screen deactivation, EMI-REC, the application (the asterisk wildcard may be used), and optionally rule or company are entered, the deactivation screen for rules and users will appear. If a specific rule is selected by indicating whether it is EMI-REC, the specific application, the rule and the specific company, the rule selection screen will be skipped.

```
------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS                   SIGNING RULES                                  |
 ------------------------------------------------------------------------------
|                                                                              |
|                                                                              |
|                              A  ADD                                          |
|                                                                              |
|                              B  DELETE                                       |
|                                                                              |
|                              C  INQUIRY                                     |
|                                                                              |
|                              M  MODIFICATION                                 |
|                                                                              |
|                                 OPTION    : B                                |
|                                 EMI-REC   : R                                |
|                                 APPLICATION: 000099980000099940*              |
|                                 RULE     : *                                |
|                                 COMPANY   : *                                |
|                                                                              |
|                              ('*' for generic selection of STANDARD and COMPANY) |
|                                                                              |
|                                                                              |
 ------------------------------------------------------------------------------
```

```
------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS                    DEACTIVATION OF RULES                                 |
 ------------------------------------------------------------------------------
|   APPLICATION:                            RULE:      COMPANY:                |
|   EMI-REC: RECEPTION                                                       |
|                                                                              |
| S         APPLICATION         RULE    COMPANY     SIGNATURES  GROUPS             |
| -  ------------------------  -----  ------------  ------  ------             |
|    000099980000099940EDTRFF                        001     000               |
|    000099980000099940EDTRFF   19    P07818237001   001     000               |
|    000099980000099940PRPSD2                        002     000               |
|    000099980000099940PRUEFF                        001     000               |
|    000099980000099940TELECA                        000     000               |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
 ------------------------------------------------------------------------------ 
```

If we select one of the rules, the following screen appears:

```
------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS                    DEACTIVATION OF RULES                                 |
 ------------------------------------------------------------------------------
|   APPLICATION: 000099980000099940EDTRF3   RULE: 19   COMPANY: P07818237001   |
|   EMI-REC: RECEPTION                                                       |
|                                                                              |
|   TOTAL NUMBER OF SIGNATURES  : 001                                          |
|   REQUIRED NUMBER OF GROUPS: 000                                          |
|                                                                              |
|                                                                              |
|                                 U  USER                                      |
|                                                                              |
|                                 G  GROUP                                     |
|                                                                              |
|                                    OPTION:                                   |
|                                    NAME:                                   |
|                                                                              |
|                                                                              |
|  <F2> DEACTIVATE THE RULE AND THE USERS                                        |
|                                                                              |
|                                                                              |
|                                                                              |
 ------------------------------------------------------------------------------
```

If F2 is pressed, the system will deactivate the rule and all associated users after confirmation.

If, on the other hand, U is typed in the option, the system will proceed to deactivate the users associated with the rule.

```
------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS                   DEACTIVATION OF USERS                                |
 ------------------------------------------------------------------------------
|   APPLICATION: 000099980000099940EDTRF3   RULE: 19   COMPANY: P07818237001   |
|   EMI-REC: RECEPTION   SIGNATURES: 001     GROUPS:  000                          |
|                                                                              |
| S        GROUP          USER     COUNTERSIGNER  SIG CTS AMOUNT (P/T)    |
| -   --------------- --------------- --------------- --- --- -------------    |
|                     User2        User1         S   N                   |
|                     User1                         N   S                   |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
 ------------------------------------------------------------------------------
```

When selecting one of the users, the deactivation screen of the user associated with a rule will appear

```
------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS                   DEACTIVATION OF USERS                                |
 ------------------------------------------------------------------------------
|   APPLICATION: 000099980000099940EDTRF3   RULE: 19   COMPANY: P07818237001   |
|   EMI-REC: RECEPTION    USER: User2                                    |
|   GROUP:                       REQUIRES COUNTERSIGNATURE (Y/N): S                 |
|   SIGN FILES (Y/N): S  COUNTERSIGNING USER: User1              |
|   MAXIMUM TOTAL AMOUNT:           MAXIMUM PARTIAL AMOUNT:                    |
|   COUNTERSIGN FILE(S/Y/N): N                                                |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|   IDENTIFICATION OF THE REMOTE CERTIFICATE:                                     |
|   CN=51679456C LUIS NIETO (R: W0011117I), OU=VATES-W0011117I, O="BNP PAR     |
|   IBAS S.A., BRANCH IN SPAIN", L=Ref:AEAT/AEAT0381/POST 1/37473/120     |
|   52021094400, ST=IDCES-51679456C, C=ES                                      |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
 ------------------------------------------------------------------------------
```

ℹ️With Enter, the system deactivates the user associated with the rule

## **Generic query**

If in the initial screen query, EMI-REC, the application, and \* in rule and company are entered, the rule query screen will appear.

```
------------------------------------------------------------------------------
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS                  QUERY OF RULES                               |
------------------------------------------------------------------------------
|   APPLICATION: A00099980000099980EDTRFF   RULE:      COMPANY:                |
|   EMI-REC: RECEPTION                                                       |
|                                                                              |
| S         APPLICATION         RULE    COMPANY     SIGNATURES  GROUPS             |
| -  ------------------------  -----  ------------  ------  ------             |
|    A00099980000099980EDTRFF                        002     001               |
|    A00099980000099980EDTRFF   19                   001     001               |
|    A00099980000099980EDTRFF   19    J67306086      001     000               |
|    A00099980000099980EDTRFF   19    J67306086???   001     001               |
|    A00099980000099980EDTRFF   34                   002     001               |
|    A00099980000099980EDTRFF   34    85502452K???   001     001               |
|    A00099980000099980EDTRFF   34    85502452K001   001     000               |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
 ------------------------------------------------------------------------------ 
```

The selection fields appear in the header.

* **APPLICATION** (header): Local code, remote code and application.
* **STANDARD** (header): Banking rule.
* **COMPANY** (header): Company composed of NIF plus suffix.
* **EMI-REC** (header): Issuance/Reception)

The inquiry lines will display

* **S**: Field to select the rule.
* **APPLICATION**: Local code, remote code and application.
* **STANDARD**: Banking rule.
* **COMPANY**: Company composed of NIF plus suffix.
* **SIGNATURES**: Number of mandatory signatures in the rule.
* **GROUPS**: Number of mandatory groups in the rule.

If a rule is selected, the associated users will appear.

```
 ------------------------------------------------------------------------------ 
|   DD/MM/YY                  SIGNATURE MANAGEMENT               EDITRAN/FF   |
|   HH:MM:SS                 QUERY OF USERS                              |
 ------------------------------------------------------------------------------ 
|   APPLICATION: 000099930000099980BACKUP   RULE: 19   COMPANY: J67306086???   |
|   EMI-REC: RECEPTION   SIGNATURES: 002     GROUPS:  001                          |
|                                                                              |
| S        GROUP          USER     COUNTERSIGNER  SIG CTS AMOUNT (P/T)    |
| -   --------------- --------------- --------------- --- --- -------------    |
|                     User2                         S                       |
|     Group1          User1                         S                       |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
 ------------------------------------------------------------------------------
```

In the header the fields of the rule appear.

* **APPLICATION** (header): Local code, remote code and application.
* **STANDARD** (header): Banking rule.
* **COMPANY** (header): Company composed of NIF plus suffix.
* **ISSUANCE/RECEPTION** (header).
* **SIGNATURES** (header): Number of mandatory signatures in the rule.
* **GROUPS** (header): Number of mandatory groups in the rule.

The inquiry lines will display

* **S**: Field to select the user.
* **GROUP:** Group Name.
* **USER**: User name.
* **COUNTERSIGNER**: Countersigner name
* **SIG**: The user signs files.
* **CTF**: The user countersigns.
* **AMOUNT (P/T)**: Maximum amount authorized for the user per operation (partial) or for the total file.

If a user is selected, the user screen will appear whose content was described in the previous point.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-ims-en/firma-electronica/funciones-interactivas-de-onesait-editran-ff/administrador-de-onesait-editran-ff.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
