> ## Documentation Index
> Fetch the complete documentation index at: https://docs.arc.cdata.com/llms.txt
> Use this file to discover all available pages before exploring further.

# AES Connector

> Configuration and usage guide for the CData Arc AES connector, which natively encrypts and decrypts message content using AES.

export const NameDescription = ({extraRows}) => <table>
    <thead>
      <tr>
        <th>Setting</th>
        <th>Description</th>
      </tr>
    </thead>
    <tbody>
      <tr>
        <td><strong>Connector Id</strong></td>
        <td>The static, unique identifier for the connector.</td>
      </tr>
      <tr>
        <td><strong>Connector Type</strong></td>
        <td>Displays the connector name and a description of what it does.</td>
      </tr>
      <tr>
        <td><strong>Connector Description</strong></td>
        <td>An optional field to provide a free-form description of the connector and its role in the flow.</td>
      </tr>
      {extraRows}
    </tbody>
  </table>;

export const SlasTab = ({siteName = "CData Arc"}) => <>
    <p><em>Settings related to configuring Service Level Agreements (SLAs).</em></p>
    <p>
      SLAs enable you to configure the volume you expect connectors in your flow to send or receive, and to set the time frame in which you expect that volume to be met. {siteName} sends emails to warn the user when an SLA is not met, and marks the SLA as <em>At Risk</em>, which means that if the SLA is not met soon, it will be marked as <em>Violated</em>. This gives the user an opportunity to step in and determine the reasons the SLA is not being met, and to take appropriate actions. If the SLA is still not met at the end of the at-risk time period, the SLA is marked as violated, and the user is notified again.
    </p>
    <p>
      To define an SLA, toggle <strong>Expected Volume</strong> on, then click the <strong>Settings</strong> tab.
    </p>
    <img src="/public/images/sla_empty.png" alt="SLA Empty" />
    <ul>
      <li>If your connector has separate send and receive actions, use the radio buttons to specify which direction the SLA pertains to.</li>
      <li>In the <strong>Expect at least</strong> portion of the window:
        <ul>
          <li>Set the minimum number of transactions you expect to be processed (the volume)</li>
          <li>Use the <strong>Every</strong> fields to specify the time frame</li>
          <li>Indicate when the SLA should go into effect. If you choose <strong>Starting on</strong>, complete the date and time fields.</li>
          <li>Check the boxes for the days of the week that you want the SLA to be in effect. Use the dropdown to choose <strong>Everyday</strong> if necessary.</li>
        </ul>
      </li>
      <li>In the <strong>Set status to 'At Risk'</strong> portion of the window, specify when the SLA should be marked as at risk.
        <ul>
          <li>By default, notifications are not sent until an SLA is in violation. To change that, check <strong>Send an 'At Risk' notification</strong>.</li>
        </ul>
      </li>
    </ul>
    <p>
      The following example shows an SLA configured for a connector that expects to receive 1000 files every day Monday-Friday. An at-risk notification is sent 1 hour before the end of the time period if the 1000 files have not been received.
    </p>
    <img src="/public/images/sla_defined.png" alt="SLA Configuration Example" />
    <Note>
      You can turn off SLA alerts if necessary. This can be useful during maintenance windows. Click <strong>Settings</strong> on the navbar, then navigate to <strong>Alerts &gt; General Alerts</strong>. Click the tablet and pencil icon to edit, and uncheck the <strong>SLA Alerts</strong> setting.
    </Note>
  </>;

export const AlertsTab = ({siteNameShort = "Arc"}) => <>
    <p><em>Settings related to configuring alerts.</em></p>
    <p>
      Before you can execute Service Level Agreements (SLAs), you need to set up email alerts for notifications. By default, {siteNameShort} uses the global settings on the <a href="/26.3/self-hosted/en/getting-started/administration/settings/alerts">Alerts</a> tab. To use other settings for this connector, toggle <strong>Override global setting</strong> on.
    </p>
    <p>
      By default, error alerts are enabled, which means that emails are sent whenever there is an error. To turn them off, uncheck the <strong>Enable</strong> checkbox.
    </p>
    <p>
      Enter a <strong>Subject</strong> (mandatory). Check <strong>Allow {siteNameShort}Script in Subject</strong> to use {siteNameShort}Script in the <strong>Subject</strong> field. When you select this, the <strong>{siteNameShort}Script Editor</strong> button appears (<img src="/public/images/rest_arcscript_editor.png" alt="arcscript editor button" style={{
  display: 'inline',
  verticalAlign: 'middle',
  margin: 0
}} />).
    </p>
    <p>
      Optionally, enter a comma-separated list of <strong>Recipient</strong> emails.
    </p>
  </>;

export const Message = () => <>
    <p><em>Message settings determine how the connector searches for messages and manages them after processing.</em></p>
    <p><strong>Note:</strong> The settings below are deprecated and hidden by default. They appear only on connectors where they were previously enabled or configured to a non-default value. To retain copies of successfully processed files, right-click the connector in the flow, choose <strong>Show Success Path</strong>, and connect the success path to a <a href="/26.3/self-hosted/en/connectors/file">File connector</a>.</p>
    <table>
      <thead>
        <tr><th>Setting</th><th>Description</th></tr>
      </thead>
      <tbody>
        <tr>
          <td><strong>Save to Sent Folder</strong> (Deprecated)</td>
          <td>Copies files processed by the connector to the Sent folder. Disabled by default. Files saved to the Sent folder are not covered by <a href="/26.3/self-hosted/en/getting-started/administration/settings/encryption-at-rest">Encryption at Rest</a>.</td>
        </tr>
        <tr>
          <td><strong>Sent Folder Scheme</strong> (Deprecated)</td>
          <td>Groups files in the <strong>Sent</strong> folder by the selected time interval. Only relevant when <strong>Save to Sent Folder</strong> is enabled.</td>
        </tr>
      </tbody>
    </table>
  </>;

export const MiscConnector = () => <>
    <p><em>Miscellaneous settings are for specific use cases.</em></p>
    <table>
      <thead>
        <tr>
          <th>Setting</th>
          <th>Description</th>
        </tr>
      </thead>
      <tbody>
        <tr>
          <td><strong>Other Settings</strong></td>
          <td>Enables you to configure hidden connector settings in a semicolon-separated list (for example, <code>setting1=value1;setting2=value2</code>). Normal connector use cases and functionality should not require the use of these settings.</td>
        </tr>
      </tbody>
    </table>
  </>;

export const Logging = () => <>
    <p><em>Settings that govern the creation and storage of logs.</em></p>
    <table>
      <thead>
        <tr>
          <th>Setting</th>
          <th>Description</th>
        </tr>
      </thead>
      <tbody>
        <tr>
          <td><strong>Log Level</strong></td>
          <td>The verbosity of logs generated by the connector. When you request support, set this to <strong>Debug</strong>.</td>
        </tr>
        <tr>
          <td><strong>Log Subfolder Scheme</strong></td>
          <td>Instructs the connector to group files in the Logs folder according to the selected interval. The <strong>Weekly</strong> option (which is the default) instructs the connector to create a new subfolder each week and store all logs for the week in that folder. Leaving this setting blank tells the connector to save all logs directly in the Logs folder. For connectors that process many transactions, using subfolders helps keep logs organized and improves performance.</td>
        </tr>
        <tr>
          <td><strong>Log Messages</strong></td>
          <td>Check this to have the log entry for a processed file include a copy of the file itself. If you disable this, you might not be able to download a copy of the file from the <strong>Transactions</strong> tab.</td>
        </tr>
      </tbody>
    </table>
  </>;

export const MacrosExamples = ({extraMacros = []}) => <>
    <p>
      Some macros, such as %Ext% and %ShortDate%, do not require an argument, but others do. All
      macros that take an argument use the following syntax: <code>%Macro:argument%</code>
    </p>

    <p>Here are some examples of the macros that take an argument:</p>

    <ul>
      <li>%Header:headername%: Where <code>headername</code> is the name of a header on a message.</li>
      <li>%Header:mycustomheader% resolves to the value of the <code>mycustomheader</code> header set on the input message.</li>
      <li>%Header:ponum% resolves to the value of the <code>ponum</code> header set on the input message.</li>
      <li>%RegexFilename:pattern%: Where <code>pattern</code> is a regex pattern. For example, <code>%RegexFilename:^([\w][A-Za-z]+)%</code> matches and resolves to the first word in the filename and is case insensitive (<code>test_file.xml</code> resolves to <code>test</code>).</li>
      <li>%Vault:vaultitem%: Where <code>vaultitem</code> is the name of an item in the <a href="/26.3/self-hosted/en/getting-started/administration/settings/global-settings-vault">vault</a>. For example, <code>%Vault:companyname%</code> resolves to the value of the <code>companyname</code> item stored in the vault.</li>
      <li>%DateFormat:format%: Where <code>format</code> is an accepted date format (see <a href="/26.3/self-hosted/en/scripting/value-formatters/date-formatters#sample-date-formats">Sample Date Formats</a> for details). For example, <code>%DateFormat:yyyy-MM-dd-HH-mm-ss-fff%</code> resolves to the date and timestamp on the file.</li>
      {extraMacros.filter(item => item.example).map(item => <li key={`ex-${item.name}`}>{item.example}</li>)}
    </ul>

    <p>You can also create more sophisticated macros, as shown in the following examples:</p>

    <ul>
      <li>Combining multiple macros in one filename: <code>%DateFormat:yyyy-MM-dd-HH-mm-ss-fff%%EXT%</code></li>
      <li>Including text outside of the macro: <code>MyFile_%DateFormat:yyyy-MM-dd-HH-mm-ss-fff%</code></li>
      <li>Including text within the macro: <code>%DateFormat:'DateProcessed-'yyyy-MM-dd_'TimeProcessed-'HH-mm-ss%</code></li>
    </ul>
  </>;

export const MacrosTable = ({siteName = "CData Arc", extraMacros = []}) => <>
    <p>
      Using macros in file naming strategies can enhance organizational efficiency and contextual
      understanding of data. By incorporating macros into filenames, you can dynamically include
      relevant information such as identifiers, timestamps, and header information, providing
      valuable context to each file.
    </p>

    <p>{siteName} supports these macros, which all use the following syntax: <code>%Macro%</code>.</p>

    <table>
      <thead>
        <tr><th>Macro</th><th>Description</th></tr>
      </thead>
      <tbody>
        <tr><td>ConnectorID</td><td>Evaluates to the ConnectorID of the connector.</td></tr>
        <tr><td>ConnectorName</td><td>Evaluates to the name of the connector. Enables you to include the connection name in file names or paths: for example, to tag backup files by which database connection produced them.</td></tr>
        <tr><td>Ext</td><td>Evaluates to the file extension of the file currently being processed by the connector.</td></tr>
        <tr><td>Filename</td><td>Evaluates to the filename (extension included) of the file currently being processed by the connector.</td></tr>
        <tr><td>FilenameNoExt</td><td>Evaluates to the filename (without the extension) of the file currently being processed by the connector.</td></tr>
        <tr><td>MessageId</td><td>Evaluates to the MessageId of the message being output by the connector.</td></tr>
        <tr><td>RegexFilename:<em>pattern</em></td><td>Applies a RegEx pattern to the filename of the file currently being processed by the connector.</td></tr>
        <tr><td>Header:<em>headername</em></td><td>Evaluates to the value of a targeted header (<code>headername</code>) on the current message being processed by the connector.</td></tr>
        <tr><td>LongDate</td><td>Evaluates to the current datetime of the system in long-handed format (for example, Wednesday, January 24, 2024).</td></tr>
        <tr><td>ShortDate</td><td>Evaluates to the current datetime of the system in a yyyy-MM-dd format (for example, 2024-01-24).</td></tr>
        <tr><td>DateFormat:<em>format</em></td><td>Evaluates to the current datetime of the system in the specified format (<code>format</code>). See <a href="/26.3/self-hosted/en/scripting/value-formatters/date-formatters#date-formats-with-literal-characters">Sample Date Formats</a> for the available datetime formats.</td></tr>
        <tr><td>Vault:<em>vaultitem</em></td><td>Evaluates to the value of the specified vault item.</td></tr>
        {extraMacros.map(item => <tr key={item.name}>
            <td>{item.name}</td>
            <td>{item.description}</td>
          </tr>)}
      </tbody>
    </table>
  </>;

export const Performance = () => <>
    <p><em>Settings related to the allocation of resources to the connector.</em></p>
    <table>
      <thead>
        <tr>
          <th>Setting</th>
          <th>Description</th>
        </tr>
      </thead>
      <tbody>
        <tr>
          <td><strong>Max Workers</strong></td>
          <td>The maximum number of worker threads consumed from the threadpool to process files on this connector. If set, this overrides the default setting on the <a href="/26.3/self-hosted/en/getting-started/administration/settings/performance-settings">Performance Settings</a> portion of the <a href="/26.3/self-hosted/en/getting-started/administration/settings/advanced-settings">Advanced Settings</a> page.</td>
        </tr>
        <tr>
          <td><strong>Max Files</strong></td>
          <td>The maximum number of files sent by each thread assigned to the connector. If set, this overrides the default setting on the <a href="/26.3/self-hosted/en/getting-started/administration/settings/performance-settings">Performance Settings</a> portion of the <a href="/26.3/self-hosted/en/getting-started/administration/settings/advanced-settings">Advanced Settings</a> page.</td>
        </tr>
      </tbody>
    </table>
  </>;

export const siteNameShort = "Arc";

export const siteName = "CData Arc";

The AES connector provides native AES encryption and decryption of message content directly within {siteName}.

## Key Capabilities

* Native AES encryption and decryption of message content, with no external tools or scripts required
* Multiple key sources (password-based key derivation, static key, or header-supplied key) and seven cipher modes
* Configurable nonce/IV handling, GCM authentication, password salt, and padding, with interoperability for content encrypted by OpenSSL

## Overview

The AES connector performs native AES encryption and decryption of message content, replacing prior workarounds that required invoking OpenSSL through {siteNameShort}Script and managing external processes. The connector offers two operations: **Encrypt** (the default) and **Decrypt**. You configure how keys, cipher modes, and metadata (such as nonces or IVs and authentication tags) are handled.

<Note>The connector can decrypt content originally encrypted with OpenSSL (AES-CBC), provided the same key, IV, and padding configuration are used.</Note>

Passwords, keys, and sensitive header values are masked in all logs, message details, audit records, debug output, errors, and support packages. In addition, authentication failures never return partially decrypted content.

## Connector Configuration

This section contains all of the configurable connector properties.

### Settings Tab

The available settings depend on the selected **Operation**, **Key** source, and **Cipher Mode**.

#### Configuration

*Settings related to the core operation of the connector.*

<NameDescription />

Use the **Operation** radio buttons to specify whether the connector **encrypts** (the default) or **decrypts** message content.

#### Key

*Settings related to the AES key. The available fields depend on the selected **Key** source. The following table shows the settings for **Password-Based Key Derivation***.

| Setting                     | Description                                                                                                                                                          |
| --------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Key**                     | How the AES key is provided: **Password-Based Key Derivation** (default), **Static** (a fixed key entered in the settings), or a key read from a message **Header**. |
| **Password**                | The password used to derive the AES key. Interpreted as UTF-8.                                                                                                       |
| **Key Size (Bits)**         | The size of the derived AES key in bits: 128, 192, or 256 (default).                                                                                                 |
| **Key Derivation Function** | The PBKDF2 pseudorandom function used to derive the AES key: PBKDF2-HMAC-SHA256 or PBKDF2-HMAC-SHA512.                                                               |
| **Iterations**              | The number of PBKDF2 iterations. Higher values increase resistance to brute-force attacks at the cost of performance. The default is `600000`.                       |
| **Password Salt**           | How the PBKDF2 salt is provided: **Auto-Generate** (default), a static value, or read from a message header.                                                         |
| **Generated Salt Output**   | (auto-generated salt) Whether the generated salt is **Included** in the payload or written to an output header.                                                      |

##### Non-Default Key Options

* If you are using a **Static** **Key**, provide the **Key** as hexadecimal (prefixed with `0x`) or Base64. The decoded key must be 16, 24, or 32 bytes (AES-128, AES-192, or AES-256).
* If you are using a **Header**-supplied **Key**, binary values *you* enter accept hex (`0x`) or Base64; binary values *the connector generates* and writes to headers are Base64-encoded. The decoded key must be 16, 24, or 32 bytes (AES-128, AES-192, or AES-256).

##### Non-Default Password Salt Options

* If you choose **Static** in **Password Salt**, use the **Password Salt** field to provide a value that decodes to exactly 16 bytes, as `0x`-prefixed hexadecimal or Base64.
* If you choose **Header** in **Password Salt**, enter the name of the message header used to read or write the password salt in the **Password Salt Header** field.

#### Cipher

*Settings related to the cipher mode and nonce/IV handling.*

| Setting                         | Description                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Cipher Mode**                 | The AES cipher mode: **GCM**, **CBC**, **ECB**, **CFB**, **OFB**, **CTS**, or **CTR**. GCM is the default, and is recommended because it provides both confidentiality and authentication. ECB is provided only for legacy compatibility. The other options provide confidentiality, but not authentication.                                                                                                                                          |
| **Padding Mode**                | (CBC and ECB modes only) The padding scheme: **PKCS7** (default), **Zeros**, **None**, **ANSIX923**, or **ISO10126**.                                                                                                                                                                                                                                                                                                                                 |
| **Nonce / IV**                  | How the nonce or IV is provided: **Auto-Generate** (default; a unique nonce or IV is generated for each encryption), **Static**, or **Header**. GCM uses a 12-byte nonce; the other modes use a 16-byte IV. ECB does not use a nonce or IV.<br /><br />Selecting **Static** displays a warning that reusing a static nonce or IV with the same key is insecure for GCM and weakens the other modes. If you select **Header**, supply the header name. |
| **Generated Nonce / IV Output** | (**Auto-Generate** only) Whether the generated nonce/IV is **Included** in the payload or written to an output **Header**.                                                                                                                                                                                                                                                                                                                            |

<Note>In **Decrypt** mode, the **Nonce / IV** **Auto-Generate** field changes to **Included**.</Note>

#### Authentication

*GCM cipher mode only.*

| Setting                                  | Description                                                                                                                                                                                   |
| ---------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Authentication Tag**                   | Whether the GCM authentication tag is **Included** in the payload or written to an output **Header**.                                                                                         |
| **Authentication Tag Length (Bits)**     | The authentication tag length in bits: 128 (the default), 120, 112, 104, or 96. 128 is recommended; shorter tags reduce authentication strength and should be used only for interoperability. |
| **Additional Authenticated Data**        | Optional Additional Authenticated Data (AAD): **None** (default), or read from a message **Header**.                                                                                          |
| **Additional Authenticated Data Header** | The name of the message header used to read the AAD. A value beginning with `0x` is decoded as hexadecimal; otherwise it is interpreted as UTF-8.                                             |

### Advanced Tab

#### Advanced Settings

*Settings not included in the previous categories.*

| Setting               | Description                                                                                                                                                                                                                                                                                                  |
| --------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Processing Delay**  | The amount of time (in seconds) by which the processing of files placed in the **Transactions** tab is delayed. This is a legacy setting. Best practice is to [use a File connector](../flows/designing-a-flow#interacting-with-the-local-file-system) to manage local file systems instead of this setting. |
| **Local File Scheme** | A scheme for assigning filenames to messages that are output by the connector. You can use macros in your filenames dynamically to include information such as identifiers and timestamps. For more information, see [Macros](#macros).                                                                      |

#### Message

<Message />

#### Logging

<Logging />

#### Miscellaneous

<MiscConnector />

### Automation Tab

#### Settings

*Settings related to the automatic processing of files by the connector.*

| Setting             | Description                                                             |
| ------------------- | ----------------------------------------------------------------------- |
| **Send Automation** | Whether messages arriving at the connector are automatically processed. |

#### Performance

<Performance />

### Alerts Tab

<AlertsTab />

### SLAs Tab

<SlasTab />

## Included Payload Format

When metadata is included in the payload, the connector orders the fields as follows, omitting any field that is not configured:

```
salt || nonce/IV || ciphertext || authentication tag
```

## Default Header Names

When keys or metadata are read from or written to message headers, the connector uses these default header names:

| Purpose       | Default header         |
| ------------- | ---------------------- |
| Password Salt | `Crypto-Password-Salt` |
| AES Key       | `Crypto-Key`           |
| Nonce / IV    | `Crypto-Nonce`         |
| Auth Tag      | `Crypto-Auth-Tag`      |
| AAD           | `Crypto-AAD`           |

## Macros

<MacrosTable />

### Examples

<MacrosExamples />
