> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-iseries-en/gestor-de-claves/introduction.md).

# Introduction

In cryptography mode 4.0, 3.0, unlike mode 2.2, the entities require exchanging their respective keys; that is, the exchange is external to the application. This exchange has been carried out in various ways: via applications external to editran, mail and email, telephone, etc., which in many cases shows the “weakness of the exchange.”

In version V5R2, it has incorporated a reliable and secure management system to automate the exchange process, avoiding the weakness mentioned, avoiding the display of keys in plain text, and facilitating reliable onboarding and exchange in both entities.

This module does not require a license; it is included in the functionality of the described phase. However, to use it, an editran/SC RSA license is required. The reason is that 3 types of exchanges will occur:

* An initial exchange (only the first time) of the RSA public key in “plain text.” In reality, although it is sent in plain text, it is not expected to be “viewed” because during the upload and download of the buffer, automatic processes will incorporate it into FCRIPTO40.
* From the initial exchange onward, when new RSA public keys are exchanged, all transmissions will be signed with some private key for which we have confirmation that the corresponding associated public key has been sent to the remote side. That is, in the second exchange it will at least be possible to sign with the initial one, in the third with the initial one or with the second one, and so on.
* From the initial exchange onward, when new DES keys are exchanged, all transmissions will be encrypted and signed. The signature will be made with some RSA private key for which we have confirmation that the corresponding associated RSA public key has been sent to the remote side. Encryption will be done with some RSA public key received from the remote entity.

In addition, all management has been structured into “subsystems.” A subsystem is a group of keys exchanged for a specific remote, group of remotes, or applications.

Each subsystem allows keys to be changed with versions 01 to 99 (when they reach that position, they wrap around), keeping the last 3.

The exchange with the entities will be carried out from a session of the application adapted for this purpose, TELEGC.

Below is the exchange procedure and an example of use.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/ibm-editran-v5.3-iseries-en/gestor-de-claves/introduction.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
