> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/open-v5.2.1-en/linux/aes_rsa.md).

# AES-RSA key configuration

### Local configuration

#### Backup

Before performing any step, it is advisable to make a backup of the subdirectory **cfg\\.rsa** (if it exists), located in the EDITRAN installation directory.

#### Editran configuration

To be able to start the key exchange with another EDITRAN entity, the only requirement is that there must be a session-presentation correctly configured for the connection with that remote.

### Key exchange

The procedure may change depending on whether both entities can initiate the TCP connection or whether there is some limitation.

In this guide we will use the following concepts as an example, where in each case you will have to replace the example with your real case:

**Local code**: P00000020

**Remote code**: L00099910

**Local subsystem**: N

**Remote subsystem**: N

**Editran installation directory**: /opt/editran

The possible scenarios are explained below.

#### Scenario 1: Key exchange between entities operating in client/server mode (both initiate TCP connections)

**Receipt of the remote public key**

When the remote indicates that it is ready to transmit its public key, we start receiving its key. To do this, first the environment must be generated to receive it.

From the subdirectory **bin**, we execute the following command:

```bash
gc_config -R -l[Código local] -r[Código remoto]
```

In the example case, the command would be:

```bash
gc_config -R -lP00000020 -rL00099910
```

In these cases, it is normal for the remote to request the sending of its RSA key, but at this point Editran is already prepared to start receiving if necessary.

To request receipt of the key, you must open the **menug**, go to Option **1. Operator**, use option **7.- RECEIVE PRESENTATION** and the session **TELEGC** created\*\*.\*\* This session will have a name format **\[Local code]-\[Remote code]-\[TELEGC]**.

Using the previous example, the session would be called **P00000020-** **L00099910-TELEGC**:

![operator menu](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-c45850bd66fdb03ac642c3a5757737c0bbe2207f%2Fimage3.png?alt=media)

If the transmission finishes correctly, the EMISSION and RECEPTION status will be **...** (indicating that the key exchange went well).

If the transmission does not complete and the EMISSION and/or RECEPTION status shows INTERRUPTED, you must contact the product Support group so they can help you resolve the case.

EDITRAN transmission is configured to automatically send the confirmation of the received key. Therefore, the received remote key is activated. To verify it, you can consult the list of "RSA Remote Keys" from the graphical interface of the Editran/GC module.

To consult this detail you must open the program **editrangc**, go to Option **3.- RSA REMOTE KEYS ASSOCIATION (ADMINISTRATION)**, and use the following options:

**OPTION**: C

**SUBSYSTEM**: N

**LOCAL ENVIRONMENT**: P00000020

**REMOTE ENVIRONMENT**: L00099910

![Remote key association](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-3f5163e82604716c7504ffd83d6b767202851b1e%2Fimage4.png?alt=media)

In the next window it will already appear as **Active Key**. If not, contact product support to analyze the problem.

![Remote key association](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-fdca9b377c588a3e97d97920677f4f5dcc7de6e3%2Fimage5.png?alt=media)

**Sending the own public key to a remote**

At this step, a 4096-bit RSA key pair (Private + Public) will be generated, identified as its own subsystem. Each subsystem is usually associated with the security applied to a type of information exchanged by EDITRAN.

To perform this task, from the subdirectory **bin** we execute the following command:

```bash
gc_config -l[Código local] -r[Código remoto] -s[Subsistema]
```

Where:

* \[Local code]: Your local code to be used, defined with the 9-character format.
* \[Remote code]: The local code of the remote (also called "remote code"), defined with the 9-character format.
* \[Subsystem]: This is the chosen subsystem designated with a letter or number, which may be the same as or different from the one the remote will define (it is recommended that it be the same in both cases for convenience).

Taking as an example the local code **P00000020**, the remote code **L00099910** and subsystem **N**, the command would be:

```bash
gc_config -lP00000020 -rL00099910 -sN
```

If the command works correctly, the following message will appear:

```txt
/opt/editran/bin\# gc_config -lP00000020 -rL00099910 -sN

[L] [Key 0] [Version 1] [Status Key Send File Generated]
```

We will have to start the sending of the public key to the Remote using the session **TELEGC** which will have been created automatically with the previous command if it was not already created.

To do this, you must open the **menug**, go to Option **1. Operator**, use option **3.- SEND PRESENTATION** and the session **TELEGC** created\*\*.\*\* This session will have a name format **\[Local code]-\[Remote code]-\[TELEGC]**.

Using the previous example, the session would be called **P00000020-** **L00099910-TELEGC**:

![Operator Menu](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-39dd4f1f9c33256210db7a21371275a9f4f0097e%2Fimage6.png?alt=media)

If the transmission finishes correctly, the EMISSION and RECEPTION status will be **...** (indicating that the key exchange has been carried out successfully).

If the transmission does not complete and the EMISSION and/or RECEPTION status shows INTERRUPTED, you must contact the product Support group so they can help you resolve the case.

EDITRAN transmission is configured to automatically incorporate the remote's confirmation of the emitted key. Therefore, in the list of "RSA Own Keys" it will already appear as active (A). If not, contact product support to analyze the problem.

To consult this detail you must open the program **editrangc**, go to Option **2.- RSA OWN KEYS ASSOCIATION (ADMINISTRATION AND SENDING)**, and use the following options:

**OPTION**: C

**SUBSYSTEM**: N

**LOCAL ENVIRONMENT**: P00000020

**REMOTE ENVIRONMENT**: L00099910

![Remote environment](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-e2cfd985b45968047f9c24d733f5fb5ecbc735da%2Fimage7.png?alt=media)

In the next window it will already appear as **Active Key**. If not, contact product support to analyze the problem.

![Key list](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-622bae20446d1c93159f5c0263768b78e2fe5fce%2Fimage8.png?alt=media)

#### Scenario 2: Key exchange from an entity that only operates in client mode (does not accept remote TCP connections)

**Receipt of the remote public key**

The procedure is the same as that of the **Scenario 1**.

**Sending the own public key to a remote**

The same steps are followed as in Scenario 1; in this case the entity could not connect to send you the key confirmation, so when consulting the list of own subsystems it will appear in state "Key file sent (S)".

![Key association](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-b06f8c4a2ca488c853820764e734ec11602a580f%2Fimage9.png?alt=media)

You will have to connect with the remote entity and request receipt of the remote's confirmation. To do this, you must open the **menug**, go to Option **1. Operator**, use option **7.- RECEIVE PRESENTATION** and the session **P00000020-** **L00099910-TELEGC**:

![Operator Menu](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-21b8154fa79916c5de3b0fe5c0cdd6c93296bc94%2Fimage10.png?alt=media)

If the transmission finishes correctly, the EMISSION and RECEPTION status will be **...** (indicating that the confirmation has been received successfully).

To check whether the key is activated, you must follow the same steps explained earlier: open the program **editrangc**, go to Option **2.- RSA OWN KEYS ASSOCIATION (ADMINISTRATION AND SENDING)**, and use the following options:

**OPTION**: C

**SUBSYSTEM**: N

**LOCAL ENVIRONMENT**: P00000020

**REMOTE ENVIRONMENT**: L00099910

![Key Association](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-e2cfd985b45968047f9c24d733f5fb5ecbc735da%2Fimage7.png?alt=media)

In the next window it will already appear as **Active Key**. If not, contact product support to analyze the problem.

![Active Key](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-5e2f3b307e74fc931d80950b2673f15fba8004f5%2Fimage11.png?alt=media)

### Session modification

Once the key exchange has been carried out, you can now make changes in the sessions with the configured remote so that encryption is used **Triple AES** and authentication **RSA**. The configuration would be:

**EDITRAN/P:**

![Editran P - Session Query](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-1a4500efb2f249cb8840f742328dc150eb2bee47%2Fimage12.png?alt=media)

**EDITRAN/G:**

![Editran G - Presentation Query](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-a4c929569627c37879040cf043d21db91f576d54%2Fimage13.png?alt=media)

If you want to modify all the transmissions you have with that remote, you can do so using the mass modification command **modiperfi**. Located in the directory **bin**, and changing the example remote code L00099910 for the one you want to modify, execute:

modiperfi -oP -rL00099910 -m"-Eversrem=52 -Ecifrado=S -Everscifrado=40 -Econfidencial= -Eautentic=RSA -Ecclave=N -Egclaves=S -Elabelloc=N -Elabelrem=N"

modiperfi -oG -rL00099910 -m"-Iversigarem=52 -Icifrado=S -Iverscifrado=40 -Iconfidenc=AE3 -Iautentica=RSA -Igclaves=S -Iclavelocal=N -Iclaveremota=N"

### Generate new version of own key

Depending on the policy established by the entities, it may be necessary to renew the key of an own subsystem by generating a new version. This process can be carried out from the menu ***editrangc*** following the steps documented in the User Manual - Key Manager.

Another option is to use the command ***gc\_config*** for this task. Below, the mode of use in these cases is explained.

To generate a new key version of an already existing own subsystem, it is enough to add the option ***--v.*** Continuing with the example, and located in the folder ***bin*** execute:

```bash
gc_config -v -lP00000020 -rL00099910 -sN
```

If the key length to generate is not specified with the option ***-k***, the key is generated at 4096. If you want to create it with another length (1024 or 2048), it is necessary to use the command in this way:

```bash
gc_config -v -k2048 -lP00000020 -rL00099910 -sN
```

If it has been generated correctly, the command output would be as follows:

![key generation output](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-20c953ac31e4ae574f11754a7a2b20e6d902d10b%2Fimage14.png?alt=media)

The information shown is the list of subsystem versions:

```txt
[L] own key type
[Key i] key position
[Version n] number identifying the key version
[State ...] key state
```

Once the new version has been generated, the steps to follow for its sending are the same as those explained in the exchange of own public key.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/open-v5.2.1-en/linux/aes_rsa.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
