> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-ims-en/gestor-de-claves/definiciones-y-pantallas.md).

# Definitions and screens

It is necessary to register the transaction for the exchange key management (ZTBD) in the local Editran environment (see Appendix):

Access to exchange key management is performed from option 6 of the product's general menu. The following screen is then displayed:

```
------------------------------------------------------------------------------
|   16/06/26           EXCHANGE KEY MANAGEMENT           EDITRAN/GC   |
|   11:13:04                                                         5.3       |
 ------------------------------------------------------------------------------
|                                                                              |
|                                                                              |
|                                                                              |
|   1  LOCAL ENVIRONMENT ADMINISTRATOR                                          |
|                                                                              |
|   2  RSA OWN KEY MANAGEMENT (ADMINISTRATION, GENERATION AND SENDING)      |
|                                                                              |
|   3  ASSOCIATION OF RSA OWN KEYS (ADMINISTRATION, EXPORT AND SENDING)  |
|                                                                              |
|   4  ASSOCIATION OF RSA REMOTE KEYS (ADMINISTRATION)                       |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                            OPTION..........:                                 |
|                                                                              |
|                                                                              |
|                                                                              |
|       <ENTER> PERFORM QUERY, <PF3> EXIT                                 |
 ------------------------------------------------------------------------------
```

## Local environment administrator

In this option we will define the general operating parameters of Editran/GC. Once the environment has been registered, we will only be able to modify it and query it, but not delete it.

```
------------------------------------------------------------------------------
|   30/06/26           EXCHANGE KEY MANAGEMENT           EDITRAN/GC   |
|   13:02:42            LOCAL ENVIRONMENT ADMINISTRATOR               5.3       |
 ------------------------------------------------------------------------------
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                               A  ADD                                        |
|                                                                              |
|                               M  MODIFY                                |
|                                                                              |
|                               C  QUERY                                    |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                               OPTION.......:                                 |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|       <ENTER> PERFORM OPERATION, <PF3> EXIT                                |
 ------------------------------------------------------------------------------
```

```
------------------------------------------------------------------------------
|   30/06/26           EXCHANGE KEY MANAGEMENT           EDITRAN/GC   |
|   13:10:26            LOCAL ENVIRONMENT ADMINISTRATOR               5.3       |
------------------------------------------------------------------------------
|                                                                              |
|   REQUIRES EDITRAN FOR MANAGEMENT (Y/N).........: S                            |
|   FILE INSTALLATION PREFIX..........: KI.EGTI.L00                  |
|   SERVICE EDITRA APPLICATION.... ..........: TELEGC                       |
|   LABEL PREFIX...............................: EDITRAN                      |
|   REGION NAME FOR BATCH PROCESS.........: ZTBGJGC                      |
|   TRANSACTION NAME FOR BATCH PROCESS....: ZTBH                         |
|   KEY MANAGEMENT PROCEDURE NAME: ZTBGP1GR                     |
|   WORK UNIT NAME (SYSDA,VIO).............: SYSDA                        |
|                                                                              |
|   JCL CARDS:                                                             |
|   ==============                                                             |
| => //KIGESCIT JOB (EGDI,KIT,,99),GESCL,CLASS=B,NOTIFY=&SYSUID,               |
| => //    MSGCLASS=H                                                          |
| => //*                                                                       |
| => //*                                                                       |
| => //*                                                                       |
|                                                                              |
|       <ENTER> PERFORM OPERATION, <PF3> EXIT                                |
 ------------------------------------------------------------------------------
```

The parameters on this screen are explained below.

* **Requires Editran for Management (Y/N)**:

> With this field we indicate whether we want to use the application for sending and receiving the exchanged keys.

* **File Installation Prefix**:

> This is the prefix with which the files for key exchange will be created.

* **Service Editran Application**:

> If the application is used for key exchange, a presentation session associated with a transmission session must be defined, whose application code is the one shown in this parameter. Through these sessions, the sending and receiving of keys will be carried out.
>
> The Appendix shows the Editran session configuration screen, where CALLING END = X and TRAFFIC DIRECTION = X must be configured, in addition to the Editran/GC-specific procedures for key exchange.

* **Label Prefix**:

> This is the prefix with which all key labels will begin when this name is generated automatically.

* **Region and transaction name for batch process**:

> Name of the procedure and its associated transaction where the keys are generated.

* **Key management procedure name**:

> This is the name of the specific previous procedure for loading and sending the keys through the service application.

> The Editran/GC-specific procedures are shown in the Appendix. The user who runs the procedures must be authorized to create RSA keys in ICSF.

* **Work unit name (SYSDA,VIO)**:

> Name of the unit to create the key files to be exchanged

* **JCL CARDS**:

> The JCL cards with which the batch procedures will be launched.

## RSA own key management <a href="#ref289354453" id="ref289354453"></a>

This section details the screens that allow us to manage the RSA key pairs that we want to have in our installation.

```
------------------------------------------------------------------------------
|   11/06/26           EXCHANGE KEY MANAGEMENT           EDITRAN/GC   |
|   11:06:35            RSA OWN KEY MANAGEMENT                          |
------------------------------------------------------------------------------
|                                                                              |
|                       A  ADD                                                |
|                                                                              |
|                       B  DELETE                                                |
|                                                                              |
|                       M  MODIFY                                        |
|                                                                              |
|                       C  QUERY AND DISPLAY PUBLIC KEY                 |
|                                                                              |
|                       G  GENERATION                                          |
|                                                                              |
|                       E  EXPORT-SEND (TO THE REMOTES OF THE SUBSYSTEM)    |
|                                                                              |
|                       OPTION..........: A                                    |
|                       SUBSYSTEM......: S                                    |
|                       LOCAL ENVIRONMENT...: 0 0009998 0                          |
|                                                                              |
|                                                                              |
|       <ENTER> PERFORM OPERATION, <PF3> EXIT                                |
 ------------------------------------------------------------------------------
```

With the purely administrative options (A, B, M and C) we will proceed to create the characteristics of a subsystem to which we will associate a key pair. The subsystem name is any letter or any number from 0 to 9.

```
------------------------------------------------------------------------------
|   16/06/26           EXCHANGE KEY MANAGEMENT           EDITRAN/GC   |
|   11:25:05            RSA OWN KEY MANAGEMENT                5.3       |
------------------------------------------------------------------------------
|                                                                              |
|      SUBSYSTEM.....: S                      LOCAL ENVIRONMENT..: 000099980      |
|      SUBSYSTEM DESCRIPTION..........: Tests                            |
|      ADMINISTRATOR NAME...........: IMS Support                        |
|      ADMINISTRATOR PHONE.........: 914808080                          |
|      EDITRAN/P SERVICE APPLICATION...: TELEGC                             |
|                                                                              |
| PAIR LABEL: EDITRAN.000099980.S.000000000.RSA.PAREJA.LOCAL                 |
| KEY GENERATION LENGTH (BITS)..: 2048 (1024/2048/4096)              |
|                                                                              |
|          RELATIONSHIP OF PRIVATE AND PUBLIC KEYS (LABEL + VERSION)            |
| VERS GEN DATE TIME. MOD DATE TIME.    STATE   SEL                         |
| ---- --------------- --------------- ----------- ---                         |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|       <PF3> EXIT, <ENTER> ADD                                              |
 ------------------------------------------------------------------------------
```

The first three fields that can be implemented are self-explanatory. As for the Service Application, it is the one we have set in the Environment, but we have the option to change it.

* **Pair Label**:

> When adding, the name of the label that will identify the private and public key pair in the ICSF file appears. It is generated by default by Editran/GC with the prefix that has been set in the Environment plus the entity's local code, the subsystem name, zeros and the key type it points to. These names can be changed according to the entity's needs in the add option.

* **Key generation length (BITS)**:

> Indicates the length with which the RSA key pair will be generated, which may be 1024, 2048 or 4096 bits. By default, 2048 is shown.
>
> The rest of the fields will be completed when we proceed to generate the RSA key pair, option G on the previous screen. When this is the chosen option and we press \<ENTER> on the screen, the following warning will appear:

<pre><code><strong>------------------------------------------------------------------------------
</strong>|   16/06/26           EXCHANGE KEY MANAGEMENT           EDITRAN/GC   |
|   11:26:55            RSA OWN KEY MANAGEMENT                5.3       |
------------------------------------------------------------------------------
|                                                                              |
| SUBSYSTEM.......: S                    LOCAL ENVIRONMENT....: 000099980         |
|                                                                              |
|                            *******************                               |
|                            * W A R N I N G *                               |
|                            *******************                               |
|                                                                              |
|          THE CHOSEN OPTION WILL CREATE A NEW VERSION, WHICH              |
|          WILL CAUSE THE OLDEST VERSION TO BE LOST (IF IT EXISTS).                   |
|                                                                              |
|                                                                              |
|          THE LENGTH OF THE NEW VERSION OF THE KEY IS 2048                 |
|                                                                              |
|                                                                              |
|                                                                              |
|             DO YOU WANT TO CONTINUE WITH THE REQUEST (Y/N).........: N                |
|                                                                              |
|                                                                              |
|       PRESS &#x3C;PF2> TO CONFIRM THE OPERATION                                |
 ------------------------------------------------------------------------------ 
</code></pre>

To complete the generation, type “S” and press \<PF2>, causing the batch procedure that creates the keys to run; when it has finished, when we query we will see the data for the generated keys.

```
------------------------------------------------------------------------------
|   16/06/26           EXCHANGE KEY MANAGEMENT           EDITRAN/GC   |
|   11:27:05            RSA OWN KEY MANAGEMENT                5.3       |
------------------------------------------------------------------------------
|                                                                              |
|      SUBSYSTEM.....: S                      LOCAL ENVIRONMENT..: 000099980      |
|      SUBSYSTEM DESCRIPTION..........: Tests                            |
|      ADMINISTRATOR NAME...........: IMS Support                        |
|      ADMINISTRATOR PHONE.........: 914808080                          |
|      EDITRAN/P SERVICE APPLICATION...: TELEGC                             |
|                                                                              |
| PAIR LABEL: EDITRAN.000099980.S.000000000.RSA.PAREJA.LOCAL                 |
| KEY GENERATION LENGTH (BITS)..: 2048 (1024/2048/4096)              |
|                                                                              |
|          RELATIONSHIP OF PRIVATE AND PUBLIC KEYS (LABEL + VERSION)            |
| VERS GEN DATE TIME. MOD DATE TIME.    STATE   SEL  (S)ELEC. VIEW PUBLIC   |
| ---- --------------- --------------- ----------- ---                         |
|  01  20160526-120851 20160906-131951 4-ACTIVE                                |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|       <PF3> EXIT, <ENTER> KEY DISPLAY                            |
 ------------------------------------------------------------------------------

```

* **Key version**:

> It tells us the number of times we have generated keys.

* **Generation date and time**.
* **Modification date and time**:

> Indicates the date and time when a state change has been made for that key version.

* **Key status:**
  * '4-ACTIVE': indicates the key pair that will be used for sending.
  * '3-OPERATIONAL': indicates that another key pair has been generated that is in active state and that this version is available for use, but is not sent.
* **Selection**:
  * By typing an ‘S’ in query mode (option ‘C’) we can see the public key.

```
------------------------------------------------------------------------------
|   16/06/26           EXCHANGE KEY MANAGEMENT           EDITRAN/GC   |
|   11:40:04            RSA OWN KEY MANAGEMENT                5.3       |
------------------------------------------------------------------------------
| SUBSYSTEM......: S                     LOCAL ENVIRONMENT: 000099980             |
| GENERATION DATE: 20160526-120851       STATE: 4-ACTIVE     LENGTH: 2048  |
| LABEL....: EDITRAN.000099980.S.000000000.RSA.PAREJA.LOCAL.V02                |
| MODULE                                                                       |
|      C67179C2727358C6A0D9BAE0608313BDE97C0CBF7B85D8675799F8CFDE6B5151        |
|      EAC228DB888657F0D11406CD1F8EBD5DABEEE909851B8375E6C130FCCE2343DB        |
|      D335F789435588CE78FCEECC13DEA28BB340EBC87A9271FA1FC9FF8FD4108D73        |
|      5DA983A5B6D0AE03055CCFB3F91CDB485BBC11C9CB18A07AE031C4C681E4577C        |
|      7C0FB120719DB5B4A8AA2FCC14C8745C26B4C1BDCE65DF5F22DCFD61495E8D50        |
|      4060E3D4360A824EA3715E78926693930CFE55A9A74BD788BABF2FF46ED02581        |
|      E5FEADBB4B8D2331CD44AB5A7F16D212BEFBE6DB47ACCC1F768DE086183CB954        |
|      81585856DF4BF19035411342978556281D96E6FE171E1EDA10F17411356E3CEF        |
| EXPONENT                                                                    |
| 00010001 (65537)                                                             |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
| <PF3> EXIT                                                                  |
 ------------------------------------------------------------------------------
```

* By typing an ‘A’ in modification mode (option ‘M’) we can activate a key that is in *operational state* which implies that it moves to *active state* and therefore, the version that was active will become operational.

```
------------------------------------------------------------------------------
|   16/06/26           EXCHANGE KEY MANAGEMENT           EDITRAN/GC   |
|   11:42:39            RSA OWN KEY MANAGEMENT                5.3       |
------------------------------------------------------------------------------
|                                                                              |
|      SUBSYSTEM.....: S                      LOCAL ENVIRONMENT..: 000099980      |
|      SUBSYSTEM DESCRIPTION..........: Tests                            |
|      ADMINISTRATOR NAME...........: IMS Support                        |
|      ADMINISTRATOR PHONE.........: 914808080                          |
|      EDITRAN/P SERVICE APPLICATION...: TELEGC                             |
|                                                                              |
| PAIR LABEL: EDITRAN.000099980.S.000000000.RSA.PAREJA.LOCAL                 |
| KEY GENERATION LENGTH (BITS)..: 2048 (1024/2048/4096)              |
|                                                                              |
|          RELATIONSHIP OF PRIVATE AND PUBLIC KEYS (LABEL + VERSION)            |
| VERS GEN DATE TIME. MOD DATE TIME.    STATE   SEL  (S)ELEC. VIEW PUBLIC   |
| ---- --------------- --------------- ----------- ---                         |
|  01  20160517-173222 20160906-131951 3-OPERATIONAL                             |
|  02  20160526-120851 20160906-131951 4-ACTIVE                                |
|                                                                              |
|                                                                              |
|                                                                              |
|       <PF3> EXIT, <ENTER> MODIFY                                         |
 ------------------------------------------------------------------------------
```

To export a new version of the key to all remotes we can use option ‘E’ of the menu. When pressing \<ENTER> on the key screen, the following warning will appear.

```
------------------------------------------------------------------------------
|   16/06/26           EXCHANGE KEY MANAGEMENT           EDITRAN/GC   |
|   10:43:55            RSA OWN KEY MANAGEMENT                5.3       |
------------------------------------------------------------------------------
|                                                                              |
| SUBSYSTEM.......: S                    LOCAL ENVIRONMENT....: 000099980         |
|                                                                              |
|                            *******************                               |
|                            * W A R N I N G *                               |
|                            *******************                               |
|                                                                              |
|          THE CHOSEN OPTION TAKES THE ACTIVE KEY OF THE SUBSYSTEM              |
|          SELECTED AND EXPORTS IT TO ALL REMOTES THAT             |
|          EXIST WITH THE SUBSYSTEM (IF THEY DID NOT HAVE THAT ACTIVE),              |
|          ALSO ALLOWING LOAD AND SEND OR LOAD ONLY                       |
|                                                                              |
|          THE LENGTH OF THE KEY TO EXPORT IS 2048                          |
|                                                                              |
|                                                                              |
|             DO YOU WANT TO EXPORT (Y)............................: N                |
|             DO YOU WANT TO SEND (Y/N)............................: N                |
|                                                                              |
|       PRESS <PF2> TO CONFIRM THE OPERATION                                |
 ------------------------------------------------------------------------------ 
```

* **Do you want to EXPORT**:

> By typing ‘S’ a file with the public key will be generated for each of the remotes.

* **Do you want to SEND**:

> By typing ‘S’ the sending of each of the files will be requested by the service application we have implemented.
>
> This option is equivalent to using option G of point 3 (ASSOCIATION OF RSA OWN KEYS - MANAGES EXPORT AND KEY SENDING) applied to all the remotes we have defined in option 3.
>
> For the sending to be carried out properly to a given remote, the same validations as in point 3 will be followed and it will also be verified that there is no key of any kind pending sending or confirmation with that remote
>
> After requesting the sending, the number of remotes for which this key is associated and the number of remotes to which the sending was possible will be returned.

```
INCORRECT EXPORT (EXPORTED     8 OF     9)
```

## Association of RSA own keys <a href="#ref289354098" id="ref289354098"></a>

Once we have at least one RSA key pair, we are already in a position to send the public key to the remotes. We have the following options.

```
------------------------------------------------------------------------------
|   16/06/26           EXCHANGE KEY MANAGEMENT           EDITRAN/GC   |
|   11:45:58           ASSOCIATION OF RSA OWN KEYS              5.3       |
------------------------------------------------------------------------------
|                          A  ADD                                             |
|                                                                              |
|                          R  ADD WITH COPY                                   |
|                                                                              |
|                          B  DELETE                                             |
|                                                                              |
|                          M  MODIFY                                     |
|                                                                              |
|                          C  QUERY AND VERIFY                          |
|                                                                              |
|                          G  MANAGE EXPORT AND KEY SENDING           |
|                                                                              |
|                                                                              |
|                  OPTION..........: a                                         |
|                  SUBSYSTEM......: s                                         |
|                  LOCAL ENVIRONMENT...: 0 9998    0                               |
|                  REMOTE ENVIRONMENT..: 0 9999    0                               |
|                                                                              |
|       <ENTER> PERFORM OPERATION, <PF3> EXIT                                |
 ------------------------------------------------------------------------------
```

The administrative options allow us to create remote profiles associating them with the key subsystems we want to send.

```
------------------------------------------------------------------------------
|   16/06/26           EXCHANGE KEY MANAGEMENT           EDITRAN/GC   |
|   12:08:06           ASSOCIATION OF RSA OWN KEYS              5.3       |
------------------------------------------------------------------------------
|  SUBSYSTEM.: S    LOCAL......: 000099980     REMOTE.....: 000099990         |
|                                                                              |
|      SUBSYSTEM DESCRIPTION..........: Tests                            |
|      ADMINISTRATOR NAME...........: IMS Support                        |
|      ADMINISTRATOR PHONE.........: 914808080                          |
|      EDITRAN/P SERVICE APPLICATION...: TELEGC                             |
|                                                                              |
| RSA LABEL...: EDITRAN.000099980.S.000000000.RSA.PAREJA.LOCAL                 |
| ACTIVE KEY LENGTH IN THE SUBSYSTEM..: 2048                               |
| RSA SUBSYSTEM FOR SIGNATURE............:                                    |
|                                                                              |
|          RELATIONSHIP OF PRIVATE AND PUBLIC KEYS (LABEL + VERSION)            |
| VERS GEN DATE TIME. MOD DATE TIME.    STATE   SEL                         |
| ---- --------------- --------------- ----------- ---                         |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|       <PF3> EXIT, <ENTER> ADD                                              |
 ------------------------------------------------------------------------------
```

The data that appear are the same as those explained in the previous section and the following is added:

* **RSA subsystem for signing**:

> We must enter the name of a subsystem with which we have exchanged RSA keys with the remote. If it is the first key we send, this parameter will NOT be implemented.
>
> Option ‘G’ will allow us to export the public key.

```
------------------------------------------------------------------------------
|   16/06/26           EXCHANGE KEY MANAGEMENT           EDITRAN/GC   |
|   12:10:55            RSA OWN KEY MANAGEMENT                5.3       |
------------------------------------------------------------------------------
|                                                                              |
| SUBSYSTEM.......: S                    LOCAL ENVIRONMENT....: 000099980         |
|                                                                              |
|                            *******************                               |
|                            * W A R N I N G *                               |
|                            *******************                               |
|                                                                              |
|          THE CHOSEN OPTION WILL CREATE A NEW VERSION, WHICH              |
|          WILL CAUSE THE OLDEST VERSION TO BE LOST (IF IT EXISTS).                   |
|                                                                              |
|                                                                              |
|          THE LENGTH OF THE NEW VERSION OF THE KEY IS 2048                 |
|                                                                              |
|                                                                              |
|                                                                              |
|             DO YOU WANT TO CONTINUE WITH THE REQUEST (Y/N).........: N                |
|                                                                              |
|                                                                              |
|       PRESS <PF2> TO CONFIRM THE OPERATION                                |
 ------------------------------------------------------------------------------ 
```

* **Do you want to EXPORT**:

> By typing ‘S’ the file with the public key for the remote will be generated.

**Do you want to SEND**:

> By typing ‘S’ the sending of the file will be requested by the service application we have implemented.
>
> To export the key it will be verified that there is a new version of the RSA key that is not already associated with this remote. If RSA subsystem for signing was specified, it will also be validated that the signing key has previously been exchanged with the remote.
>
> When we re-enter the administration we will be able to see

```
------------------------------------------------------------------------------
|   16/06/26           EXCHANGE KEY MANAGEMENT           EDITRAN/GC   |
|   12:32:58           ASSOCIATION OF RSA OWN KEYS              5.3       |
------------------------------------------------------------------------------
|  SUBSYSTEM.: S    LOCAL......: 000099980     REMOTE.....: 000099990         |
|                                                                              |
|      SUBSYSTEM DESCRIPTION..........: Tests                            |
|      ADMINISTRATOR NAME...........: IMS Support                        |
|      ADMINISTRATOR PHONE.........: 914808080                          |
|      EDITRAN/P SERVICE APPLICATION...: TELEGC                             |
|                                                                              |
| RSA LABEL...: EDITRAN.000099980.S.000000000.RSA.PAREJA.LOCAL                 |
| ACTIVE KEY LENGTH IN THE SUBSYSTEM..: 2048                               |
| RSA SUBSYSTEM FOR SIGNATURE............:                                    |
|                                                                              |
|          RELATIONSHIP OF PRIVATE AND PUBLIC KEYS (LABEL + VERSION)            |
| VERS GEN DATE TIME. MOD DATE TIME.    STATE   SEL  (S)ELEC. VIEW PUBLIC   |
| ---- --------------- --------------- ----------- ---                         |
|  01  20160517-173222 20160518-161011 4-ACTIVE                                |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|       <PF3> EXIT, <ENTER> MODIFY                                         |
 ------------------------------------------------------------------------------
```

* **Key status**:
  * '1-GENERATED': indicates that the file with the public key has been created.
  * '2-SENT': the sending of the file with the public key has been requested.
  * '3-OPERATIONAL': this version is available for use, but not for export.
  * '4-ACTIVE': it is available for export as well as for use.
  * '5-CANCELLED': it is not available for export or use.
* **Selection**:
  * By typing an ‘S’ in query mode (option ‘C’) we can see the public key.
  * By typing an ‘A’ in modification mode (option ‘M’) we can activate a key regardless of its stat&#x65;*,* which implies that it moves to *active state* and therefore, the version that was active will become operational.
  * By typing a ‘C’ in modification mode (option ‘M’) we can cancel a key regardless of its state. When canceling the key, the latest version of the key that is operational will become active, if this is possible.

## Association of RSA remote keys

The complete RSA key exchange takes place when we have sent our public key and received the remote public key. To prepare the file for the received key we have this option.

```
------------------------------------------------------------------------------
|   16/06/26           EXCHANGE KEY MANAGEMENT           EDITRAN/GC   |
|   16:45:38           ASSOCIATION OF RSA EXTERNAL KEYS               5.1       |
------------------------------------------------------------------------------
|                          A  ADD                                             |
|                                                                              |
|                          R  ADD WITH COPY                                   |
|                                                                              |
|                          B  DELETE                                             |
|                                                                              |
|                          M  MODIFY                                     |
|                                                                              |
|                          C  QUERY AND VERIFY                          |
|                                                                              |
|                                                                              |
|                                                                              |
|                                                                              |
|                  OPTION..........: a                                         |
|                  SUBSYSTEM......: s                                         |
|                  LOCAL ENVIRONMENT...: 0 9998    0                               |
|                  REMOTE ENVIRONMENT..: 0 9999    0                               |
|                                                                              |
|       <ENTER> PERFORM OPERATION, <PF3> EXIT                                |
 ------------------------------------------------------------------------------ 
```

Here we associate the public key of a remote with a subsystem; the subsystem name will be the one chosen by the remote from which we receive the key, and it does not have to be the same as the one with which we associated the local key.

The data on the screen that appears below are the same as those explained in point 3.3: name of the label under which the remote public key will be stored in the ICSF file and the length of the active key. As in the case of own keys, the name can be changed according to our choice in the add option.

When we enter query mode we can display the received public key for verification with the remote, just like in the "RSA own key management" section.

The modification option will allow us to activate or cancel a key with the same observations as those explained in the previous point "Association of RSA own keys".

```
------------------------------------------------------------------------------
|   16/06/26           EXCHANGE KEY MANAGEMENT           EDITRAN/GC   |
|   12:07:37           ASSOCIATION OF RSA EXTERNAL KEYS               5.3       |
------------------------------------------------------------------------------
|      SUBSYSTEM: S     LOCAL: 000099980     REMOTE: 000099990                |
|                                                                              |
|      SUBSYSTEM DESCRIPTION..........: Tests                            |
|      ADMINISTRATOR NAME...........: IMS Support                        |
|      ADMINISTRATOR PHONE.........: 914808080                          |
|      EDITRAN/P SERVICE APPLICATION...: TELEGC                             |
|                                                                              |
| RSA LABEL...: EDITRAN.000099980.S.000099990.RSA.EXTERNAL.PUBLIC                |
| ACTIVE KEY LENGTH.............: 2048                               |
| RSA SUBSYSTEM FOR SIGNATURE............:                                    |
|                                                                              |
|          RELATIONSHIP OF PRIVATE AND PUBLIC KEYS (LABEL + VERSION)            |
| VERS GEN DATE TIME. MOD DATE TIME.    STATE   SEL  (S)ELEC. VIEW PUBLIC   |
| ---- --------------- --------------- ----------- ---                         |
|  01  20131031-112621 20140128-152032 4-ACTIVE                                |
|                                                                              |
|                                                                              |
|                                                                              |
|       <PF3> EXIT, <ENTER> MODIFY                                         |
 ------------------------------------------------------------------------------
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-ims-en/gestor-de-claves/definiciones-y-pantallas.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
