> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-ims-en/operacion/anexo-c.-sistema-de-criptografia-en-onesait-editran.md).

# Appendix C. Cryptography system in Onesait Editran

In the application there is a cryptographic operating mode, corresponding to Cryptographic Version 3.0 and 4.0. This mode uses cryptographic keys that are not exchanged by Editran. The keys will be exchanged between the users. The possible alternatives are:

* DES symmetric keys, externally exchanged by the users, which allow triple DES (TD3C) encryption of the data.
* Public and private keys using the RSA algorithm, externally exchanged, which support electronic signature of transmissions and:
  * triple DES (TD3C) encryption of the data. Cryptographic Version 3.0.
  * AES encryption of the data, with single, double or triple key (for version 5.2 or higher). Cryptographic Version 4.0.

## Cryptographic system parameterization

The labels or tags are provided by a Key Interface or are directly referenced in the session Profile. The authentication algorithm can be DES or RSA.

* With this parameterization, data is encrypted at load time (Batch) with Exchange Keys obtained externally to Editran and with triple DES data encryption algorithm, the parameters to be coded would be the following:

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top"></td><td valign="top">Editran</td></tr><tr><td valign="top">CRYPTOGRAPHY</td><td valign="top">S</td></tr><tr><td valign="top">CRYPTOGRAPHIC VERSION</td><td valign="top">3.0</td></tr><tr><td valign="top">DATA ENCRYPTION ALGORITHM</td><td valign="top">TD3C</td></tr><tr><td valign="top">AUTHENTICATION ALGORITHM</td><td valign="top">DES</td></tr><tr><td valign="top">LOCAL SUBSYSTEM</td><td valign="top"></td></tr><tr><td valign="top">REMOTE SUBSYSTEM</td><td valign="top"></td></tr><tr><td valign="top">LOC. KEY</td><td valign="top">Label of the local key</td></tr><tr><td valign="top">REM. KEY</td><td valign="top">Label of the remote key</td></tr></tbody></table>

* With this parameterization, data is encrypted at load time (Batch) with RSA Keys, provided by the Editran interface, and with triple DES data encryption algorithm, the parameters to be coded would be the following:

<table data-header-hidden><thead><tr><th width="350" valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top"></td><td valign="top">Editran</td></tr><tr><td valign="top">CRYPTOGRAPHY</td><td valign="top">S</td></tr><tr><td valign="top">CRYPTOGRAPHIC VERSION</td><td valign="top">3.0/4.0</td></tr><tr><td valign="top">DATA ENCRYPTION ALGORITHM</td><td valign="top">TD3C</td></tr><tr><td valign="top">AUTHENTICATION ALGORITHM</td><td valign="top">RSA</td></tr><tr><td valign="top">LOCAL SUBSYSTEM</td><td valign="top"><p>Subsystem for the association of Editran/GC own keys</p><p>Ex: H</p></td></tr><tr><td valign="top">REMOTE SUBSYSTEM</td><td valign="top"><p>Subsystem for the association of external Editran/GC keys</p><p>Ex: P</p></td></tr><tr><td valign="top">LOC. KEY</td><td valign="top"></td></tr><tr><td valign="top">REM. KEY</td><td valign="top"></td></tr></tbody></table>

* With this parameterization, data is encrypted at load time (Batch) with AES data encryption algorithm and RSA keys, provided by the Editran interface, the parameters to be coded would be the following:

<table data-header-hidden><thead><tr><th width="351" valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top"></td><td valign="top">Editran</td></tr><tr><td valign="top">CRYPTOGRAPHY</td><td valign="top">S</td></tr><tr><td valign="top">CRYPTOGRAPHIC VERSION</td><td valign="top">4.0</td></tr><tr><td valign="top">DATA ENCRYPTION ALGORITHM</td><td valign="top">AES1 / AES2 / AES3</td></tr><tr><td valign="top">AUTHENTICATION ALGORITHM</td><td valign="top">RSA</td></tr><tr><td valign="top">LOCAL SUBSYSTEM</td><td valign="top"><p>Subsystem for the association of Editran/GC own keys</p><p>Ex: H</p></td></tr><tr><td valign="top">REMOTE SUBSYSTEM</td><td valign="top"><p>Subsystem for the association of external Editran/GC keys</p><p>Ex: P</p></td></tr><tr><td valign="top">LOC. KEY</td><td valign="top"></td></tr><tr><td valign="top">REM. KEY</td><td valign="top"></td></tr></tbody></table>

## Encryption errors

When a Cryptographic Error occurs, the application gives local information about the error produced and sends to the remote side a release request with the reason for the error, later releasing the connection.

At the end where the error occurs, the Return Code returned by the product that provides the cryptographic services (ICSF) is reported, so if it occurs, the Return-Code and/or Reason-Code references should be consulted in the product manual: ICSF "z/OS. Cryptographic Services. Integrated Cryptographic Service Facility. Application Programmer's Guide".

Likewise, the Editran modules that access the ICSF group these Cryptographic Errors as follows:

<table data-header-hidden><thead><tr><th width="87"></th><th width="499"></th></tr></thead><tbody><tr><td></td><td>Editran ENCRYPTION ERRORS</td></tr><tr><td>999</td><td>ERROR OBTAINING PUBLIC KEY</td></tr><tr><td>998</td><td>ERROR GENERATING SYMMETRIC KEY</td></tr><tr><td>997</td><td>ERROR GENERATING KEY PAIR</td></tr><tr><td>996</td><td>ERROR SIGNING</td></tr><tr><td>995</td><td>ERROR VERIFYING SIGNATURE</td></tr><tr><td>994</td><td>ERROR OBTAINING SYMMETRIC KEY</td></tr><tr><td>993</td><td>ERROR SETTING OPERATIONAL KEY</td></tr><tr><td>992</td><td>ERROR CREATING RSA KEY TOKEN</td></tr><tr><td>991</td><td>ERROR IMPORTING RSA PAIR</td></tr><tr><td>990</td><td>ERROR IMPORTING RSA PUBLIC KEY</td></tr><tr><td>989</td><td>ERROR EXPORTING SYMMETRIC KEY</td></tr><tr><td>988</td><td>ERROR CALCULATING HASH</td></tr><tr><td>900</td><td>ERROR GENERATING RANDOM NUMBER</td></tr><tr><td>901</td><td>ERROR ENCRYPTING</td></tr><tr><td>902</td><td>ERROR DECRYPTING</td></tr><tr><td>801</td><td>ERROR CREATING RECORD IN PKDS</td></tr><tr><td>802</td><td>ERROR DELETING RECORD IN PKDS</td></tr><tr><td>803</td><td>ERROR READING RECORD IN PKDS</td></tr><tr><td>804</td><td>ERROR WRITING RECORD IN PKDS</td></tr></tbody></table>

The Editran reasons for the Cryptographic Errors that may occur are the following.

### Cryptographic errors v3.0/ v4.0 RSA or DES <a href="#toc503367090" id="toc503367090"></a>

* (1): An error occurred when obtaining the local key, either because it was not supplied in Profiles or because of an error in the Key Interface.
* (2): When attempting to send an association request or a response, an error occurs generating the uncertainty or the signature. If the algorithm used is DES, the error is in the local key. If it is RSA, the error is in the local key when the signature is generated, or in the remote key when the uncertainty is generated.
* (3): Error while attempting to generate the session key. If the algorithm used is DES, the error concerns the local key. If it is RSA, the erroneous key is the remote one.
* (4): An error occurred when obtaining the remote key, either because it was not supplied in Profiles or because an error occurred in the Key Interface.
* (5): When processing a request or a response from the remote side, an error occurs when attempting to decrypt the uncertainty or the signature. If the DES algorithm is used, the erroneous key is the remote key. If RSA is used, the error is in the remote key when decrypting the signature, or in the local key when decrypting the uncertainty.
* (6): When processing a request or a response from the remote side, an error occurs when decrypting the session key. If the algorithm is DES, the error is in the remote key. If it is RSA, the key in error is the local one.
* (7): The end that is going to send a user data or Operator Message has had an error in the "online" encryption.
* (8): The end that receives a user data or Operator Message from the remote side has had an error in the "online" decryption.
* (9): When processing a request or a response, the session key and signature are decrypted, but either the uncertainty does not match or the signature does not match (this case only in RSA).

> The error occurs because the exchange keys do not match at both ends.
>
> If a Key Interface was used, the message must include the last 8 bytes of the label used.
>
> If the algorithm used is DES, the erroneous key is the local key of the end that generates the message. If it is RSA, the erroneous key is the local key (if an error occurs when validating the uncertainty) or the remote key (if an error occurs when verifying the signature).

***


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-ims-en/operacion/anexo-c.-sistema-de-criptografia-en-onesait-editran.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
