> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/open-v5.2.1-en/windows/aes_rsa.md).

# AES-RSA key configuration

## Local configuration

### Backup

Before performing any step, it is advisable to make a backup of the subdirectory **cfg\\.rsa** (if it exists), located in the EDITRAN installation directory.

### Editran configuration

To be able to start the key exchange with another EDITRAN entity, the only requirement is that a fully configured session-presentation must exist for the connection with that remote.

In this guide we will use the following concepts as an example, where in each case you will have to replace the example with your real case:

**Local code**: P00000020

**Remote code**: 000080810

**Local subsystem**: N

**Remote subsystem**: N

**Editran installation directory**: C:\EDITRAN

### EDITRAN/GC

#### Generate own key

In this first step, an RSA key pair (Private + Public) is generated, which is identified as the own subsystem. Each subsystem is usually associated with the security applied to a type of information exchanged by EDITRAN.

In general, the subsystem name is agreed between all the entities involved so that it is the same (for example, N), which makes it easier to identify the use of that RSA key.

Enter the EDITRAN/GC menu (EDITRAN key management) and select the option **Own RSA keys, New own key**.

![assets/image3.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-27d232e89e7497d079a43229d9dc05ef43fe231f%2Fimage3.png?alt=media)

In the window that appears, define a **description**, the name of the **subsystem** agreed (in the example, an N), its **EDITRAN local code** and the key length.

As an example in the following screenshot, the values that entity P00000020 would enter when it receives the notification, usually from a financial entity, that it must adapt EDITRAN transmissions to the PSD2 regulations, are shown.

![assets/image4.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-158408d989436fd6689146ddd09860b058dc3e06%2Fimage4.png?alt=media)

Press **OK** to perform the operation. In the list of own subsystems, version 1 will appear as active (A).

Once the own key has been created, the following steps will be repeated for each Editran entity associated with that subsystem.

#### Assign own key to a remote

In the Editran/GC menu, select the branch **RSA Keys/Own**, and in the corresponding list, select the own subsystem, right-click and in the context menu click **Assign to a remote**.

![assets/image5.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-260672233916094b2881c9b5041a3afe7d310c70%2Fimage5.png?alt=media)

In the window presented, select the remote code from the drop-down list and exit with **OK**.

![assets/image6.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-5f633ad8da09fe76244aa3d330a583d3d18bb7e1%2Fimage6.png?alt=media)

You are asked whether you want to send the key at this time, but you must press **No** to postpone the sending until you have decided with the remote entity which side sends first.

![assets/image7.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-0138f1f2d46b72d84f905ea65feb95bd7b11ccca%2Fimage7.png?alt=media)

### Key exchange

Generally, the order in which the exchange is carried out is the one explained below. If the other entity is also Windows, agree on which one receives first.

The procedure may change depending on whether both entities can initiate the TCP connection or whether there is some limitation.

The possible scenarios are explained below.

#### Scenario 1: Key exchange between entities operating in client/server mode (both initiate TCP connections)

**Receipt of the remote public key**

When the remote entity tells us it is ready to transmit its public key, we begin receiving its key.

In the EDITRAN/GC menu select the option **Subsystems > Receive Key File/Remote Confirmation**:

![assets/image8.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-8f78025edf50b06578ce419c6e1f61886c538385%2Fimage8.png?alt=media)

In the next window, click the button that appears next to the Presentation field to select the code of the remote entity from which the reception will be requested. If your installation allows you to operate with several local codes, you must also choose the local code.

![assets/image9.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-fc8a0c591cc411b9bcad11b427be1c7860eafcb1%2Fimage9.png?alt=media)

When confirming with **OK**, the transmission window will show the field "**Presentation**" that will be created in EDITRAN if it does not exist.

Press the **Receive** button to ask EDITRAN/G to receive it. The progress of the transmission and the final result are shown.

![assets/image10.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-c0b0646220f2e29d78d27dcf562ae7a732cf58b1%2Fimage10.png?alt=media)

If, as in the example, the transmission finishes correctly, when you click Exit the key data contained in the received exchange file are displayed. If the transmission does not complete and the Status field shows INTERRUPTED, you should contact the product Support group so they can help you resolve the case.

![assets/image11.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-8bb6a2dfcb4ec191e2a3a677c1b8b1b47dce5955%2Fimage11.png?alt=media)

The EDITRAN transmission is configured to automatically send confirmation of the received key. Therefore, in the list of "Non-Own Subsystems" it will already appear as active (A). If not, contact product support to analyze the problem.

![assets/image12.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-5baf0fc481dbf2b0fcbb5e5903f334fd6e38d6b8%2Fimage12.png?alt=media)

**Sending the own public key to a remote**

Go to the list of own subsystems and select the remote to which you want to send the key. Right-click and in the context menu click **Own key exchange**.

![assets/image13.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-bf879767177316354e6157f7192b97e4dd5502f7%2Fimage13.png?alt=media)

The information of the key export file that will be created when you click is shown **Generate**.

![assets/image14.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-40791f0e8368c0e81f03969a6c006e1fe61631f8%2Fimage14.png?alt=media)

If there is no error in the previous step, the sending window is shown. Press **Send** to ask EDITRAN to start the sending.

![assets/image15.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-1ad42f46b7afde31a5aea47be430021d328d2af4%2Fimage15.png?alt=media)

![assets/image16.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-519401920c8133124335ecacfb55ec7bbcb37e4c%2Fimage16.png?alt=media)

If the transmission ends successfully, since the remote has the key confirmation automated, the key should appear as active (A) in a few minutes. Otherwise, contact the entity to notify them that the confirmation has not been received.

![assets/image17.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-881e791b0ec49b1f9ea2c119f6387d3232f8dc02%2Fimage17.png?alt=media)

#### Scenario 2: Key exchange from an entity that only operates in client mode (does not accept remote TCP connections)

**Receipt of the remote public key**

The procedure is the same as in Scenario 1.

**Sending the own public key to a remote**

The same steps as in Scenario 1 are followed; in this case the entity could not connect to send you the key confirmation, so when you check the list of own subsystems it will appear in the state "Key file sent (S)".

![assets/image18.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-200b500f7a765b2f88f18f65d0d39c62aaf25784%2Fimage18.png?alt=media)

You must connect with the remote entity and request the reception. Select the subsystem in the list, and in the context menu the option **Own key exchange**.

![assets/image19.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-87afcfa64bcc331a646fd9b6ae14a2449d5ef16d%2Fimage19.png?alt=media)

In this case, the key is pending confirmation and you are asked if you want to request its reception

![assets/image20.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-87030d63420d9f53261753f08e4dda0bdcf63e3a%2Fimage20.png?alt=media)

In the transmission window, press **Receive** and wait for the result

![assets/image21.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-5c3f666c893e226b45da75aeee834e4a83cdd881%2Fimage21.png?alt=media)

If it finishes successfully, the information of the received file is shown and the key status will have been updated.

![assets/image22.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-b91849ad8b688422413fc860ecd8798ba45c687e%2Fimage22.png?alt=media)

![assets/image23.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-81e4768c9038eca77a60a42f0cbdae284da9f904%2Fimage23.png?alt=media)

## Session modification

Once the key exchange has been carried out, changes must be made in the sessions with the configured remote so that encryption is used **Triple AES** and authentication **RSA**. The configuration would be:

**EDITRAN/P:**

![assets/image24.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-2a50dc4337ab44558dff1ffe2f5a7b006696398e%2Fimage24.png?alt=media)

**EDITRAN/G:**

![assets/image25.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-4f4e3406d0cb4e3af1b1141300cf26697f45b077%2Fimage25.png?alt=media)

To make the task of changing the configuration easier, the following commands can be executed from the directory **bin**, changing the example remote code 000080810 to the one you want to modify:

modiperfi -oP -r000080810 -m"-Eversrem=52 -Ecifrado=S -Everscifrado=40 -Econfidencial= -Eautentic=RSA -Ecclave=N -Egclaves=S -Elabelloc=N -Elabelrem=N"

modiperfi -oP -r000080810 -aTELEGC -m"-Eversrem=52 -Ecifrado=N"

modiperfi -oG -r000080810 -m"-Iversigarem=52 -Icifrado=S -Iverscifrado=40 -Iconfidenc=AE3 -Iautentica=RSA -Igclaves=S -Iclavelocal=N -Iclaveremota=N"

modiperfi -oG -r000080810 -aTELEGC -m"-Iversigarem=52 -Icifrado=N"

### Generate new version of own key

Depending on the policy established by the entities, it may be necessary to renew the key of an own subsystem by generating a new version. This process can be carried out from the menu ***editrangc*** following these steps.

The first step is to go to the list of own keys and select the subsystem to update. In the context menu click *"Generate New Version of the Key"*

![assets/image26.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-4684f742189eeee1c106bf869eaa419c15112b8b%2Fimage26.png?alt=media)

You can select the size of the new version. That is, if you had a subsystem with a 1024-bit key and want to increase security, you can generate a new version with a larger key length without needing to create a new subsystem.

When the generation of the new version finishes, the list is updated indicating that the key that will be exchanged from now on with the entities will be version 2.

![assets/image27.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-eb30495de58d63faf3d557a94e1b67d3d8278942%2Fimage27.png?alt=media)

You can now carry out the exchange with the entities associated with that subsystem. If you were using the same subsystem with several remotes, the recommendation is to update all the entities, although it is not necessary to do so at the same time. That is, the new version can be sent to entity *\<A>* and entity *\<B>* would continue working with version 1 without any problem. The only thing to keep in mind is that only the history of the last three generated versions is stored.

To begin the exchange with a remote entity, go to the list of local subsystems, select the desired item and in the context menu click *"Update the version of the own key"*

![assets/image28.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-df173541c4a44f443517a9c2805555e78da220a2%2Fimage28.png?alt=media)

The change is reported and confirmation is requested

![assets/image29.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-92c7fdfd6b5b2ae943334fc5d620f520cecdf91e%2Fimage29.png?alt=media)

If it updates correctly, the next step is reported and you are asked whether you want to continue with the sending at that moment.

![assets/image30.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-6408d456f8fc033f187a16145ac4e505c6f298c9%2Fimage30.png?alt=media)

In our example, we choose *"No"* and in the list we can see what the status of the keys looks like in that case:

![assets/image31.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-805be648403b00cd987970d40b54bc9cfe1926ad%2Fimage31.png?alt=media)

The active key remains version *'1'* since the exchange of version *'2'* has not finished. To continue with the sending, the steps explained in [scenario 1](#escenario-1-intercambio-de-claves-entre-entidades-que-funcionan-en-modo-clienteservidor-ambas-inician-conexiones-tcp) or [scenario 2](#escenario-2-intercambio-de-claves-desde-entidad-que-solo-funciona-en-modo-cliente-no-acepta-conexiones-tcp-remotas) will be followed depending on your scenario.

Once sent, version *'1'* is left in state *"Operational (O)"* and version *'2'* as the new key *"Active (A)"*.

![assets/image32.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-f8e94b33dcab5cbe114bc6d413b4a66bc2c834f6%2Fimage32.png?alt=media)

#### gc\_config command

The product provides a utility that also allows actions related to key management to be performed in command mode. This section explains how to generate a new version of an own subsystem with the program ***gc\_config***. The image shows its syntax:

![assets/image33.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-bd56b5f186586e18d898246775db740de97bd7f0%2Fimage33.png?alt=media)

Continuing with the example in the document, a new version of the local subsystem *'N'*. To do this, simply add the option ***-v.*** Located in the Editran folder ***bin*** run:

`gc_config -v -lP00000020 -r000080810 -sN`

If the key length to generate is not specified with the option ***-k***, the key is generated at 4096. If you want to create it with another length (1024 or 2048), it is necessary to use the command in this way:

`gc_config -v -k2048 -lP00000020 -r000080810 -sN`

If it has been generated correctly, the command output would be as follows:

![assets/image34.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-1ed88a89aefd14ba12f8c9131e4aeebb47491598%2Fimage34.png?alt=media)

The information shown is the current list of subsystem versions:

> \[L] own key type
>
> \[Key i] key version position
>
> \[Version n] number that identifies the key version
>
> \[Status ...] key version status

If consulted in ***editrangc***

![assets/image35.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-2b8892cd1dd4d596de20e0272ab5c68a0f02943e%2Fimage35.png?alt=media)

Once the new version has been generated, the steps to follow for its sending are the same as those explained in the exchange of own public key. Another option is to chain the sending with the command ***igacmd***

![assets/image36.png](https://2807498471-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2W4cn5C1WDTJzDOR25es%2Fuploads%2Fgit-blob-73bee83a4eecc7b2858ae66776f61db052bc213d%2Fimage36.png?alt=media)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/open-v5.2.1-en/windows/aes_rsa.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
