> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-iseries-en/administracion-y-operacion/appendix-b.-cryptography-system-in-onesait-editran/encryption-errors.md).

# Encryption errors

When a Cryptographic Error occurs, editran provides local information about the error produced and sends the remote side a release request with the error reason, subsequently releasing the connection.

At the end where the error occurs, the Return Code returned by the product that provides the cryptographic services (CRIPTOlib/DES, BDKDES, PCF, CUSP, TSS, ICSF, ...) is reported, so if it occurs, you should consult the references for the return code and/or Reason Code given in the corresponding manual for each product, such as:

* CRIPTOlib/DES: "Criptolib/DES MVS version. DES Security System. User and Installation Manual"
* CUSP/3848: "Cryptographic Unit Support: Installation Reference Manual"
* TSS/4753: "Transaction Security System. Programming Guide and Reference"
* ICSF/ICRF: "Integrated Cryptographic Service Facility/MVS. Application Programmer's Guide"

The editran reasons for the Cryptographic Errors that can occur are:

(ERR1):

The endpoint requesting a Connection Request has not been able to Re-encrypt the Keys in its file (if there is no external key Interface), or else there was an error obtaining the Label at the endpoint that initiates the session.

(ERR2):

The endpoint requesting authentication of its TKE key or its external Exchange Key (with Interface) has not been able to encrypt the Authentication Code, although it did perform the Re-encryption.

If AUTHENTICATION is DES: Probable error in local key.

If AUTHENTICATION is RSA: If the error occurs in the signature, the problem may be in the local key (Private).

If the error is in the uncertainty, the problem may be in the remote key (public).

(ERR3):

The endpoint requesting a Connection Request with Key Change has not been able to generate a transmission key.

(ERR4):

The endpoint that receives the Remote Notification Indication had an error when Re-encrypting the TKR key in its file, or when obtaining the label of the auxiliary key.

(ERR5):

The endpoint that receives the Notification Indication has not been able to decrypt the Authentication Code sent by the Remote side, although it did perform the Re-encryption.

If AUTHENTICATION is DES: Probable error in remote key.

If AUTHENTICATION is RSA: If the error occurs in the signature, the problem may be in the remote key (Public).

If the error is in the uncertainty, the problem may be in the local key (private).

(ERR6):

The endpoint that receives a Notification Indication with Key Change had an error when Re-encrypting the new Reception key coming from the remote side (new TKR).

(ERR7):

The endpoint that is going to send a user data item or Operator Message has had an error in the "on-line" encryption.

(ERR8):

The endpoint that receives a user data item or Operator Message from the Remote side has had an error in the "on-line" decryption.

(ERR9):

* If in cryptographic version it is 3.0 or 4.0, an (ERR9) means that the external Exchange keys used in the authentication process do not match at both ends. Even so, the editran message describing this error will be accompanied by another one that reports at each end the "Label" of the exchange key used. In this way, both ends can verify that the external key Interface correctly identifies the external exchange key that is actually intended to be used.

\\


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-iseries-en/administracion-y-operacion/appendix-b.-cryptography-system-in-onesait-editran/encryption-errors.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
