> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/open-v5.3-en/linux/aes_rsa.md).

# AES-RSA Key Configuration

### Local configuration

#### Backup

Before carrying out any steps, it is advisable to back up the subdirectory **cfg/.rsa** (if it exists), located in the EDITRAN installation directory.

#### Editran configuration

To start the key exchange with another EDITRAN entity, the only requirement is that a session-presentation must already be correctly configured for the connection to that remote.

### Key exchange

The procedure may vary depending on whether both entities can initiate the TCP connection or whether there is some limitation.

In this guide we will use the following concepts as an example, where in each case you will have to replace the example with your real case:

**Local code**: L00000010

**Remote code**: W00000010

**Local subsystem**: N

**Remote subsystem**: N

**Editran installation directory**: /opt/editran

The possible scenarios are explained below.

#### Scenario 1: Key exchange between entities operating in client/server mode (both initiate TCP connections)

**Receiving the Remote's public key**

When the remote indicates that it is ready to transmit its public key, we begin receiving its key. To do this, the environment must first be generated to receive it.

From the subdirectory **bin**, we run the following command:

```bash
gc_config -R -l[Código local] -r[Código remoto]
```

In the example case, the command would be:

```bash
gc_config -R -lL00000010 -rW00000010
```

In these cases, normally the remote is the one that requests the sending of its RSA key, but at this point Editran is already prepared to begin reception if necessary.

To request key reception, you must open the **menug**, go to Option **1. Operator**, use the option **7.- RECEIVE PRESENTATION** and the session **TELEGC** created. This session will have a name format **\[Local code]-\[Remote code]-\[TELEGC]**.

Using the previous example, the session would be called **L00000010-** **W00000010-TELEGC**:

![operator menu](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-7c335bbdd565ad2981e35259e448f7f44c25d74e%2Fimage3.png?alt=media)

If the transmission finishes successfully, the EMISSION and RECEPTION status will be **...** (indicating that the key exchange went well).

If the transmission does not complete and the EMISSION and/or RECEPTION status shows INTERRUPTED, you must contact the product Support team to help you resolve the case.

EDITRAN transmission is configured to automatically send confirmation of the received key. Therefore, the remote key received is activated. To verify this, you can check the list of "Remote RSA Keys" from the graphical interface of the Editran/GC module.

To consult this detail you must open the program **editrangc**, go to Option **3.- RSA REMOTE KEYS ASSOCIATION (ADMINISTRATION)**, and use the following options:

**OPTION**: C

**SUBSYSTEM**: N

**LOCAL ENVIRONMENT**: L00000010

**REMOTE ENVIRONMENT**: W00000010

![Remote key association](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-d6a5c0cead62f19e237eee765a7cd2657695afc1%2Fimage4.png?alt=media)

In the following window it will already appear as **Active Key**. If not, contact product support to analyze the problem.

![Remote key association](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-abb11f2774ab1f6810d7ce98d4be44dba90d6935%2Fimage5.png?alt=media)

**Sending our own public key to a Remote**

In this step, a 4096-bit RSA key pair (Private + Public) will be generated, identified as the own subsystem. Each subsystem is usually associated with the security applied to a type of information exchanged by EDITRAN.

To carry out this task, from the subdirectory **bin** we run the following command:

```bash
gc_config -l[Código local] -r[Código remoto] -s[Subsistema]
```

Where:

* \[Local code]: Your local code to be used, defined with a 9-character format.
* \[Código remoto]: The remote's local code (also called "remote code"), defined with a 9-character format.
* \[Subsystem]: The chosen subsystem designated with a letter or number, which may be the same as or different from the one defined by the remote (it is recommended that it be the same in both cases for convenience).

Taking the local code as an example **L00000010**, the remote code **W00000010** and the subsystem **N**, the command would be:

```bash
gc_config -lL00000010 -rW00000010 -sN
```

If the command runs correctly, the following message will appear:

```bash
gc_config -lL00000010 -rW00000010 -sN

[L] [Key 0] [Version 1] [Status Key Send File Generated]
```

We will have to start the emission of the public key to the Remote using the session **TELEGC** which will have been created automatically with the previous command if it had not already been created.

To do this, you must open the **menug**, go to Option **1. Operator**, use the option **3.- SEND PRESENTATION** and the session **TELEGC** created. This session will have a name format **\[Local code]-\[Remote code]-\[TELEGC]**.

Using the previous example, the session would be called **L00000010-** **W00000010-TELEGC**:

![Operator Menu](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-28433c4afade549520e74f8efef9b7911bd8e7d5%2Fimage6.png?alt=media)

If the transmission finishes successfully, the EMISSION and RECEPTION status will be **...** (indicating that the key exchange has been completed successfully).

If the transmission does not complete and the EMISSION and/or RECEPTION status shows INTERRUPTED, you must contact the product Support team to help you resolve the case.

EDITRAN transmission is configured to automatically incorporate confirmation from the remote of the emitted key. Therefore, in the list of "Own RSA Keys" it will already appear as active (A). If not, contact product support to analyze the problem.

To consult this detail you must open the program **editrangc**, go to Option **2.- RSA OWN KEYS ASSOCIATION (ADMINISTRATION AND SENDING)**, and use the following options:

**OPTION**: C

**SUBSYSTEM**: N

**LOCAL ENVIRONMENT**: L00000010

**REMOTE ENVIRONMENT**: W00000010

![Remote environment](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-4fafb30b852232d89804b63cb28fa90d72ad97e3%2Fimage7.png?alt=media)

In the following window it will already appear as **Active Key**. If not, contact product support to analyze the problem.

![Key list](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-9d730beb135e96693f1f31c7139e57ae2bd3f8fd%2Fimage8.png?alt=media)

#### Scenario 2: Key exchange from an entity that only operates in client mode (does not accept remote TCP connections)

**Receiving the Remote's public key**

The procedure is the same as in **Scenario 1**.

**Sending our own public key to a Remote**

The same steps as in Scenario 1 are followed; in this case the entity has not been able to connect to send you the key confirmation, so when you check the list of own subsystems it will appear with status "Key file sent (S)".

![Key association](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-856645f20c6914936f31ddd1af56e0b4be1eff96%2Fimage9.png?alt=media)

You will need to connect to the remote entity and request reception of the remote confirmation. To do this, you must open the **menug**, go to Option **1. Operator**, use the option **7.- RECEIVE PRESENTATION** and the session **L00000010-** **W00000010-TELEGC**:

![Operator Menu](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-a56824f0bc971298353aa35811f5de03fbdbecd0%2Fimage10.png?alt=media)

If the transmission finishes successfully, the EMISSION and RECEPTION status will be **...** (indicating that the confirmation has been received successfully).

To check whether the key is activated, you must follow the same steps explained above: open the program **editrangc**, go to Option **2.- RSA OWN KEYS ASSOCIATION (ADMINISTRATION AND SENDING)**, and use the following options:

**OPTION**: C

**SUBSYSTEM**: N

**LOCAL ENVIRONMENT**: L00000010

**REMOTE ENVIRONMENT**: W00000010

![Key Association](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-4fafb30b852232d89804b63cb28fa90d72ad97e3%2Fimage7.png?alt=media)

In the following window it will already appear as **Active Key**. If not, contact product support to analyze the problem.

![Active Key](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-812ff5c856e55bdab67a4940cfc6ee0e275feea7%2Fimage11.png?alt=media)

### Modification of sessions

Once the key exchange has been completed, you can now make changes to the sessions with the configured remote so that encryption is used **Triple AES** and authentication **RSA**. The configuration would be:

**EDITRAN/P:**

![Editran P - Session Query](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-d53661093497c07cb1cfe413b2f4f9df55331de7%2Fimage12.png?alt=media)

**EDITRAN/G:**

![Editran G - Presentation Query](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-ad62bcdd48737f7b0217dcb93974eb289b7b72c9%2Fimage13.png?alt=media)

If you want to modify all the transmissions you have with that remote, you can do so with the bulk modification command **modiperfi**. Located in the directory **bin**, and changing the example remote code W00000010 to the one you want to modify, run:

modiperfi -oP -rW00000010 -m"-Eversrem=53 -Ecifrado=S -Everscifrado=40 -Econfidencial= -Eautentic=RSA -Ecclave=N -Egclaves=S -Elabelloc=N -Elabelrem=N"

modiperfi -oG -rW00000010 -m"-Iversigarem=53 -Icifrado=S -Iverscifrado=40 -Iconfidenc=AE3 -Iautentica=RSA -Igclaves=S -Iclavelocal=N -Iclaveremota=N"

### Generate a new version of the own key

Depending on the policy established by the entities, it may be necessary to renew a subsystem's own key by generating a new version. This process can be carried out from the menu ***editrangc*** following the steps documented in the Key Manager manual section.

Another option is to use the command ***gc\_config*** for this task. Below, the usage method in these cases is explained.

To generate a new version of an existing own subsystem key, it is enough to add the option to the command ***-v.*** Continuing with the example, and located in the folder ***bin*** run:

```bash
gc_config -v -lL00000010 -rW00000010 -sN
```

If the key length to be generated is not specified with the option ***-k***, the key is generated at 4096. If you want to create it at another length (1024 or 2048), it is necessary to use the command in this way:

`gc_config -v -k2048 -lL00000010 -rW00000010 -sN`

If it has been generated correctly, the command output would be as follows:

```
gc_config -v -k2048 -lL00000010 -rW00000010 -sN
[L] [Key 0] [Version 1] [Status Active Key]
[L] [Key 1] [Version 2] [Status Key Send File Generated]

```

The information shown is the subsystem version list:

```txt
[L] own key type
[Key i] key position
[Version n] number that identifies the key version
[Status ...] key status
```

Once the new version has been generated, the steps to follow for its sending are the same as those explained in the own public key exchange.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/open-v5.3-en/linux/aes_rsa.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
