> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/px-5.2.1-en/installation/linux_instalacion.md).

# Linux installation

## Requirements

To ensure correct system operation **Editran/PX**, the installation environment must meet the following requirements:

* On systems **Red Hat Enterprise Linux 9 (RHEL 9)**: have version of **OpenSSL 3.5** provided by the operating system itself with all security updates applied.
* On systems **Red Hat Enterprise Linux 8 (RHEL 8)**: have **OpenSSL version 1.1.1** installed.

## Creation of an application user

It is recommended to create a new dedicated user account to work with **Editran/PX** (for example, `editran`). The account name may be any one defined by your organization.

As a security criterion, if a dedicated account is used, it must be used for the daily operation of the product and must not have system administration privileges (root/sudo). If a dedicated account is not used, the operational account must meet these same criteria. These recommendations are detailed in the section [Security](#seguridad).

## Installer

In Linux environments, software installers are distributed for the operating systems and architectures in the following table:

| Operating system | Architecture | Package                               |
| ---------------- | ------------ | ------------------------------------- |
| RHEL 9           | x86\_64      | EditranPX-v52.1.x-x86\_64-redhat9.run |
| RHEL 8           | x86\_64      | EditranPX-v52.1.x-x86\_64-redhat8.run |

To install the product, run the installer corresponding to your operating system:

```bash
chmod u+x EditranPX-52.1.x-x86_64-redhatx.run
./EditranPX-52.1.x-x86_64-redhatx.run
```

The installation steps are detailed below through screenshots of the installer run in text mode (console). On servers with a graphical interface, the installer will show windows equivalent to the screens described in this section, maintaining the same flow, options and values presented in text mode.

### Installation directory

The installer requests the directory where the files will be copied. You can enter a path or press **Enter** to accept the default proposed path.

![installation directory](https://944169240-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F6Bgxolt1oQVu07Im3iZJ%2Fuploads%2Fgit-blob-76460f56837c225624bb0244d0557fe0c90f9180%2F15_instalacion_linux_ruta.png?alt=media)

### Configuration

The system will ask whether you want to perform a basic configuration of **Editran/PX** using the prompt:

`Select whether you want to configure EditranPX [Y/n]:`

* **Y/y** (or **Enter**): starts configuration and allows you to define the **listening port** and the **Editran server** to which it will provide service.
* **N/n**: skips configuration.

![configuration](https://944169240-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F6Bgxolt1oQVu07Im3iZJ%2Fuploads%2Fgit-blob-4ac41a2db044ac7e033217535f29fe455df6561e%2F16_instalacion_linux_configuracion.png?alt=media)

### Monitoring

In this section the listening port intended for monitoring activity of **Editran/PX** from Editran Mainframe.

![monitoring](https://944169240-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F6Bgxolt1oQVu07Im3iZJ%2Fuploads%2Fgit-blob-2bd228d7f742230e91a58dc45983a0dbb5e90a27%2F17_instalacion_linux_monitorizacion.png?alt=media)

### Summary and installation.

The installer presents a summary with the collected values, copies the files, and completes the installation.

![summary](https://944169240-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F6Bgxolt1oQVu07Im3iZJ%2Fuploads%2Fgit-blob-e06cfece4a4637ef1d1c54ecfde2f9eac71f1f84%2F18_instalacion_linux_fin.png?alt=media)

## Dependencies

The installation of **Editran/PX** includes the script `home-px/inst/depends`, whose purpose is to help the system administrator identify and resolve third-party library dependencies required by the product.\
This script uses the command `rpm`, provided by the operating system, to manage and query installed software packages.\
Before running the script, it is necessary to edit the variable `EDITRAN_HOME` to indicate the path where the application is installed **Editran/PX**:

```bash
#
# Global variables
#
EDITRAN_HOME=/opt/editranpx
```

Next, the steps performed by the script are described through a practical example:\
First, the script shows the dependencies required by **Editran/PX**. To do this, it searches the system for installed packages matching OpenSSL and lists them together with their version:

```bash
#Dependencies:
-->OpenSSL v3
#Installed packages [rpm]:
openssl V3.5.1
openssl-devel V3.5.1
openssl-fips-provider V3.0.7
openssl-fips-provider-so V3.0.7
openssl-libs V3.5.1
xmlsec1-openssl V1.2.29
```

Next, it checks whether the dependency corresponding to the OpenSSL libcrypto library is correctly resolved:

```bash
#Resolving libcrypto.so.3  It is already resolved
libcrypto.so.3 => /lib64/libcrypto.so.3 (0x00007f7f92600000)
lrwxrwxrwx 1 root root 18 Jan 19 09:51 /lib64/libcrypto.so.3 -> libcrypto.so.3.5.1
```

If the dependency is not resolved, the script locates the corresponding library in the file list of the installed packages and creates the necessary symbolic link within the installation tree of **Editran/PX**, thus allowing the product to correctly locate the required library.

## Editran/PX service on Red Hat Enterprise Linux

To configure **Editran/PX** as a service managed by **systemd**, follow the steps below.

> ℹ️ *Note:* In the examples it is assumed that the product has been installed in the path `/opt/editranpx`. If the installation is in a different location, you must adapt the indicated paths.

### Service unit configuration

On Linux systems that use **systemd**, a **service unit** is a configuration file that defines how an application is managed as a system service (startup, stop, restart, dependencies and run user). These units allow services to start automatically during system boot and be managed with the command `systemctl`.

In the case of **Editran/PX**, the service unit is defined in the file `/opt/editranpx/service/editranpx.service` and its content is as follows:

```bash
[Unit]
Description=Editran Proxy
After=network.target

[Service]
Type=forking
User=editran
WorkingDirectory=/opt/editranpx
ExecStart=/opt/editranpx/EDItranPX -s start
ExecStop=/opt/editranpx/EDItranPX -s stop

[Install]
WantedBy=multi-user.target
```

To adapt the service configuration to your environment, it is necessary to edit this file and review the parameters described below:

**User**: system user under which the service will run.\
**WorkingDirectory, ExecStart and ExecStop**: must correctly reflect the installation path of **Editran/PX**.

### Service registration in systemd

With root user permissions, create the service unit file in the systemd configuration directory, `/etc/systemd/system/editranpx.service` as a symbolic link to the file `/opt/editranpx/service/editranpx.service`.

> ⚠️ *Important:* If the installation of **Editran/PX** is located on a mount point that is not available during system boot, copy `/opt/editranpx/service/editranpx.service` to `/etc/systemd/system` instead of creating a symbolic link, to ensure that **systemd** can locate the unit.

### Reloading the systemd configuration

Reload the service manager configuration by running `systemctl daemon-reload`.

### Enabling the service at startup

Optionally, the service can be configured to start automatically when the system boots. To do this, run the command `systemctl enable editranpx.service`\
Depending on the specific dependencies of your system, you may need to adapt the editranpx.service file for this option to work correctly.

### Service management commands

The following commands allow you to query the status of the service **editranpx** and control its execution from the command line using `systemd`:

* View the current status of the service: `systemctl status editranpx.service`
* Start the service: `systemctl start editranpx.service`
* Stop the service: `systemctl stop editranpx.service`
* Restart the service: `systemctl restart editranpx.service`

## License

Once installation is complete, you must request a [license file](/documentacion-editran/px-5.2.1-en/installation/licencia.md).

## Security

EditranPX is an application that acts as a gateway and does not process or collect the content of files transmitted between Editran applications.\
However, to reduce operational risks, it is recommended to protect the local resources generated by the application (configuration, binaries and logs) and apply good system administration practices.

### Deployment security

1. Any access control to listening ports must be implemented on the machine hosting Editran/PX and in the associated network security elements.
2. Any published listening port must have explicit source filtering rules and a default-deny policy for unauthorized sources.
3. When deployment is carried out in a dedicated DMZ, there must be a firewall in front of Editran/PX to filter and control inbound traffic.
4. The publication of Editran/PX listening ports must be carried out in accordance with the organization's security policies.

### Secure operation

1. It is recommended to create a dedicated account for operating EditranPX (for example, editran), different from system administrative accounts. If a dedicated account is not created, the account used to operate EditranPX must meet the same security conditions defined in this section.
2. Apply the principle of least privilege: read and execute permissions on binaries, and write permissions only in the directories necessary for operation (for example, configuration and logs).
3. Restrict management of the EditranPX service so that the operational account can only start and stop that service through a specific delegation, without granting general system administration root/sudo privileges.
4. Restrict access to the EditranPX installation directory and its subdirectories so that they are accessible only to root and to the service's operational account. The rest of the system users must not have read, write, or execute permissions on that path, unless there is justified operational need.
5. Keep the operating system and third-party dependencies updated with the security patches recommended by the manufacturer, within a periodic maintenance policy.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/px-5.2.1-en/installation/linux_instalacion.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
