> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/open-v5.3-en/windows/aes_rsa.md).

# AES-RSA Key Configuration

## Local configuration

### Backup

Before carrying out any steps, it is advisable to back up the subdirectory **cfg\\.rsa** (if it exists), located in the EDITRAN installation directory.

### Editran configuration

To be able to start the key exchange with another EDITRAN entity, the only requirement is that there must be a fully configured presentation session for the connection with that remote.

In this guide we will use the following concepts as an example, where in each case you will have to replace the example with your real case:

**Local code**: P00000020

**Remote code**: 000080810

**Local subsystem**: N

**Remote subsystem**: N

**Editran installation directory**: C:\EDITRAN

### EDITRAN/GC

#### Generate own key

In this first step, an RSA key pair (Private + Public) is generated, identified as the own subsystem. Each subsystem is usually associated with the security applied to a type of information exchanged by EDITRAN.

In general, the subsystem name is agreed upon by all the entities involved so that it is the same (for example, N), which makes it easier to identify the use of that RSA key.

Enter the EDITRAN/GC menu (EDITRAN Key Management) and select the option **Own RSA Keys, New Own Key**.

![assets/image3.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-27d232e89e7497d079a43229d9dc05ef43fe231f%2Fimage3.png?alt=media)

In the window that appears, define a **description**, the name of the **subsystem** agreed upon (in the example, N), its **EDITRAN local code** and the key length.

As an example in the following screenshot, the values that entity P00000020 would enter are shown when it receives the notification, usually from a financial entity, that it must adapt EDITRAN transmissions to the PSD2 regulations.

![assets/image4.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-158408d989436fd6689146ddd09860b058dc3e06%2Fimage4.png?alt=media)

Press **OK** to perform the operation. In the list of own subsystems it will appear as active (A), version 1.

Once the own key has been created, the following steps will be repeated for each Editran entity associated with that subsystem.

#### Assign own key to a remote

In the Editran/GC menu, select the branch **RSA Keys/Own**, and in the corresponding list, select the own subsystem, right-click and in the context menu click **Assign to a remote**.

![assets/image5.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-260672233916094b2881c9b5041a3afe7d310c70%2Fimage5.png?alt=media)

In the window presented, select the remote code from the drop-down list and exit with **OK**.

![assets/image6.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-5f633ad8da09fe76244aa3d330a583d3d18bb7e1%2Fimage6.png?alt=media)

You are asked whether you want to send the key at this time, but you must click **No** to postpone the sending until you have decided with the remote entity which side sends first.

![assets/image7.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-0138f1f2d46b72d84f905ea65feb95bd7b11ccca%2Fimage7.png?alt=media)

### Key exchange

In general, the order in which the exchange is carried out is the one explained below. If the other entity is also Windows, agree which one receives first.

The procedure may vary depending on whether both entities can initiate the TCP connection or whether there is some limitation.

The possible scenarios are explained below.

#### Scenario 1: Key exchange between entities operating in client/server mode (both initiate TCP connections)

**Receiving the Remote's public key**

When the remote tells us it is ready to transmit its public key, we start receiving its key.

In the EDITRAN/GC menu select the option **Subsystems > Receive Key File/Remote Confirmation**:

![assets/image8.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-8f78025edf50b06578ce419c6e1f61886c538385%2Fimage8.png?alt=media)

In the next window, click the button that appears next to the Presentation field to select the code of the remote entity from which receipt will be requested. If your installation allows you to operate with multiple local codes, you must also choose the local code.

![assets/image9.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-fc8a0c591cc411b9bcad11b427be1c7860eafcb1%2Fimage9.png?alt=media)

When confirming with **OK**, in the transmission window the field "**Presentation**" that will be created in EDITRAN if it does not exist will appear filled in.

Click the button **Receive** to ask EDITRAN/G for the reception. The progress of the transmission and the final result are shown.

![assets/image10.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-c0b0646220f2e29d78d27dcf562ae7a732cf58b1%2Fimage10.png?alt=media)

If, as in the example, the transmission ends correctly, when you click Exit the key data contained in the received exchange file are displayed. If the transmission does not complete and the Status field shows INTERRUPTED, you should contact the product Support group to help you resolve the case.

![assets/image11.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-8bb6a2dfcb4ec191e2a3a677c1b8b1b47dce5955%2Fimage11.png?alt=media)

The EDITRAN transmission is configured to automatically send confirmation of the received key. Therefore, in the list of "Non-Own Subsystems" it will already appear as active (A). If not, contact product support to analyze the problem.

![assets/image12.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-5baf0fc481dbf2b0fcbb5e5903f334fd6e38d6b8%2Fimage12.png?alt=media)

**Sending our own public key to a Remote**

Go to the list of own subsystems and select the remote to which you want to send the key. Right-click and in the context menu click **Exchange of the own key**.

![assets/image13.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-bf879767177316354e6157f7192b97e4dd5502f7%2Fimage13.png?alt=media)

The export file information for the key that will be created when you click **Generate**.

![assets/image14.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-40791f0e8368c0e81f03969a6c006e1fe61631f8%2Fimage14.png?alt=media)

If there is no error in the previous step, the send window is shown. Click **Send** to ask EDITRAN to start the sending.

![assets/image15.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-1ad42f46b7afde31a5aea47be430021d328d2af4%2Fimage15.png?alt=media)

![assets/image16.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-519401920c8133124335ecacfb55ec7bbcb37e4c%2Fimage16.png?alt=media)

If the transmission ends successfully, since the remote has the key confirmation automated, the key should appear as active (A) within a few minutes. Otherwise, contact the entity to notify them that it has not received the confirmation.

![assets/image17.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-881e791b0ec49b1f9ea2c119f6387d3232f8dc02%2Fimage17.png?alt=media)

#### Scenario 2: Key exchange from an entity that only operates in client mode (does not accept remote TCP connections)

**Receiving the Remote's public key**

The procedure is the same as in Scenario 1.

**Sending our own public key to a Remote**

The same steps as in Scenario 1 are followed; in this case the entity could not connect to send you the key confirmation, so when checking the list of own subsystems it will appear with status "Key file sent (S)".

![assets/image18.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-200b500f7a765b2f88f18f65d0d39c62aaf25784%2Fimage18.png?alt=media)

You must connect with the remote entity and request reception. Select the subsystem in the list, and in the context menu the option **Exchange of the own key**.

![assets/image19.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-87afcfa64bcc331a646fd9b6ae14a2449d5ef16d%2Fimage19.png?alt=media)

In this case, the key is pending confirmation and you are asked whether you want to request its reception

![assets/image20.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-87030d63420d9f53261753f08e4dda0bdcf63e3a%2Fimage20.png?alt=media)

In the transmission window, click **Receive** and wait for the result

![assets/image21.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-5c3f666c893e226b45da75aeee834e4a83cdd881%2Fimage21.png?alt=media)

If it finishes successfully, the information from the received file is displayed and the key status will have been updated.

![assets/image22.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-b91849ad8b688422413fc860ecd8798ba45c687e%2Fimage22.png?alt=media)

![assets/image23.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-81e4768c9038eca77a60a42f0cbdae284da9f904%2Fimage23.png?alt=media)

## Modification of sessions

Once the key exchange has been performed, changes must be made in the sessions with the configured remote so that encryption is used **Triple AES** and authentication **RSA**. The configuration would be:

**EDITRAN/P:**

![assets/image24.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-2a50dc4337ab44558dff1ffe2f5a7b006696398e%2Fimage24.png?alt=media)

**EDITRAN/G:**

![assets/image25.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-4f4e3406d0cb4e3af1b1141300cf26697f45b077%2Fimage25.png?alt=media)

To make the configuration changes easier, the following commands can be run from the directory **bin**, changing example remote code 000080810 to the one you want to modify:

modiperfi -oP -r000080810 -m"-Eversrem=52 -Ecifrado=S -Everscifrado=40 -Econfidencial= -Eautentic=RSA -Ecclave=N -Egclaves=S -Elabelloc=N -Elabelrem=N"

modiperfi -oP -r000080810 -aTELEGC -m"-Eversrem=52 -Ecifrado=N"

modiperfi -oG -r000080810 -m"-Iversigarem=52 -Icifrado=S -Iverscifrado=40 -Iconfidenc=AE3 -Iautentica=RSA -Igclaves=S -Iclavelocal=N -Iclaveremota=N"

modiperfi -oG -r000080810 -aTELEGC -m"-Iversigarem=52 -Icifrado=N"

### Generate a new version of the own key

Depending on the policy established by the entities, it may be necessary to renew a subsystem's own key by generating a new version. This process can be carried out from the menu ***editrangc*** following these steps.

The first step is to go to the list of own keys and select the subsystem to update. In the context menu click *"Generate New Version of the Key"*

![assets/image26.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-4684f742189eeee1c106bf869eaa419c15112b8b%2Fimage26.png?alt=media)

You are allowed to select the size of the new version. That is, if you had a subsystem with a 1024-bit key and want to increase security, you can generate a new version with a longer key length without needing to create a new subsystem.

When the generation of the new version finishes, the list is updated indicating that the key that will be exchanged from now on with the entities will be version 2.

![assets/image27.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-eb30495de58d63faf3d557a94e1b67d3d8278942%2Fimage27.png?alt=media)

You can now perform the exchange with the entities associated with that subsystem. If you were using the same subsystem with several remotes, the recommended approach is to update all entities, although it is not necessary to do so at the same time. That is, the new version can be sent to entity *\<A>* and entity *\<B>* would continue working with version 1 without problem. The only thing to keep in mind is that only the history of the last three versions generated is stored.

To start the exchange with a remote entity, go to the list of local subsystems, select the desired item and in the context menu click *"Update the version of the own key"*

![assets/image28.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-df173541c4a44f443517a9c2805555e78da220a2%2Fimage28.png?alt=media)

The change is reported and confirmation is requested

![assets/image29.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-92c7fdfd6b5b2ae943334fc5d620f520cecdf91e%2Fimage29.png?alt=media)

If it updates correctly, the next step is reported and you are asked whether you want to continue with the sending at that moment.

![assets/image30.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-6408d456f8fc033f187a16145ac4e505c6f298c9%2Fimage30.png?alt=media)

In our example, we choose *"No"* and in the list we can see how the key status looks in that case:

![assets/image31.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-805be648403b00cd987970d40b54bc9cfe1926ad%2Fimage31.png?alt=media)

The active key remains version *'1'* since the exchange of version *'2'* has not finished. To continue with the sending, follow the steps explained in [scenario 1](#escenario-1-intercambio-de-claves-entre-entidades-que-funcionan-en-modo-clienteservidor-ambas-inician-conexiones-tcp) or [scenario 2](#escenario-2-intercambio-de-claves-desde-entidad-que-solo-funciona-en-modo-cliente-no-acepta-conexiones-tcp-remotas) depending on your scenario.

Once sent, version *'1'* is in status *"Operational (O)"* and version *'2'* as the new key *"Active (A)"*.

![assets/image32.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-f8e94b33dcab5cbe114bc6d413b4a66bc2c834f6%2Fimage32.png?alt=media)

#### Versioning of the own key with the gc\_config command

The product provides a utility that also allows actions related to key management to be performed in command mode. This section explains how to generate a new version of an own subsystem with the program ***gc\_config***. The image shows its syntax:

![assets/image33.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-bd56b5f186586e18d898246775db740de97bd7f0%2Fimage33.png?alt=media)

Continuing with the document example, a new version of the local subsystem *'N'*&#x77;ill be generated. To do this, simply add the option ***-v.*** Located in the Editran folder ***bin*** run:

gc\_config -v -lP00000020 -r000080810 -sN

If the key length to be generated is not specified with the option ***-k***, the key is generated at 4096. If you want to create it at another length (1024 or 2048), it is necessary to use the command in this way:

gc\_config -v -k2048 -lP00000020 -r000080810 -sN

If it has been generated correctly, the command output would be as follows:

![assets/image34.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-1ed88a89aefd14ba12f8c9131e4aeebb47491598%2Fimage34.png?alt=media)

The information shown is the current list of subsystem versions:

> \[L] own key type
>
> \[Key i] position of the key version
>
> \[Version n] number that identifies the key version
>
> \[State ...] state of the key version

If consulted in ***editrangc***

![assets/image35.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-2b8892cd1dd4d596de20e0272ab5c68a0f02943e%2Fimage35.png?alt=media)

Once the new version has been generated, the steps to follow to send it are the same as those explained in the exchange of the own public key. Another option is to chain the sending with the command ***igacmd***

![assets/image36.png](https://780925830-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiQfLim2uDaLOZRkgWkOk%2Fuploads%2Fgit-blob-73bee83a4eecc7b2858ae66776f61db052bc213d%2Fimage36.png?alt=media)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/open-v5.3-en/windows/aes_rsa.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
