> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-ims-en/gestor-de-claves/introduccion.md).

# Introduction

The product has incorporated reliable and secure management to automate the exchange and preservation process of RSA keys using ICSF services. In this way, RSA keys are stored in the PKDS key file provided by IBM in the installation

This module does not require a license; it is built into the features of the described phase. However, to use it, an Editran/SC RSA license is required (in turn, the previous license requires having a DES environment, that is, an Editran/SC DES license).

Editran/GC performs two types of RSA key exchanges that are stored in the ICSF PKDS file:

An initial exchange (only the first time) of the RSA public key “in clear”.

From the initial exchange onward, when new RSA public keys are exchanged, all transmissions should be signed with some private key for which we know that the corresponding associated public key has been sent to the remote side. In other words, in the second exchange it will at least be possible to sign with the initial one; in the third with the initial one or with the second, and so on.

In addition, the entire management has been structured into “subsystems.” A subsystem is a group of exchanged keys for a particular remote system, group of remote systems, or applications.

Each subsystem supports several keys with versions 01 to 99 (when they reach that position they wrap around), keeping the last 3.

Up to three versions of a key can be stored and the list shows the versions that are currently being stored. As an example in the following image, we see that the first key stores version 5, the second stores version 7, and the third stores version 8. In addition, we see a ‘4-ACTIVE’, which tells us that version 8 is the active version.

```
------------------------------------------------------------------------------
|   14/02/26           KEY MANAGEMENT FOR EXCHANGE           EDITRAN/GC   |
|   14:57:19           ASSOCIATION OF OWN RSA KEYS              5.3       |
 ------------------------------------------------------------------------------
|      SUBSYSTEM: A     LOCAL: 000099980     REMOTE: 000099940                |
|                                                                              |
|      SUBSYSTEM DESCRIPTION..........:                                    |
|      ADMINISTRATOR NAME...........:                                    |
|      ADMINISTRATOR PHONE NUMBER.........:                                    |
|      SERVICE EDITRAN/P APPLICATION...: TELEGC                             |
|                                                                              |
| RSA LABEL...: EDITRAN.000099980.A.000000000.RSA.LOCAL.PRIVADA                |
| ACTIVE KEY LENGTH IN THE SUBSYSTEM..: 1024                               |
| RSA SUBSYSTEM FOR SIGNATURE............: A                                  |
|                                                                              |
|          LIST OF PRIVATE AND PUBLIC KEYS (LABEL + VERSION)            |
| VERS GENERATION DATE-TIME  MODIFICATION DATE-TIME    STATUS   SEL  (S)ELECT. PUB VER   |
| ---- --------------- --------------- ----------- ---                         |
|  05  20221124-122021 20221124-124902 3-OPERATIONAL                             |
|  07  20221124-124204 20221124-124705 3-OPERATIONAL                             |
|  08  20221124-124516 20221124-124902 4-ACTIVE                                |
|                                                                              |
|       <PF3> EXIT, <ENTER> KEY VIEWING                            |
 ------------------------------------------------------------------------------
```

A private key can store up to three versions (three public + private pairs of RSA keys); however, only one of them can be active. The version that is active is the version that will be exported when associating the key with a remote system. When a key is activated, the other two (if they exist) will be deactivated automatically, but they will remain Operational until a new version is generated that causes one to disappear, since only three key versions are allowed.

When generation exceeds the first three keys, you can continue generating keys continuously up to 99 and then the next version automatically resets to version 1 (cyclically). Said key 01, since it is a more recent version than 99, will belong to the same subsystem N.

The exchange with the entities will be carried out from an Editran session adapted for that purpose.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-ims-en/gestor-de-claves/introduccion.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
