Advanced Search Options : ❯
Section 41 of the Information Technology Act, 2000
Acceptance of a Digital Signature Certificate is deemed where a subscriber publishes or authorises its publication, including through a repository, or otherwise demonstrates approval. By accepting it, the subscriber certifies to reasonable relying parties that the subscriber holds and is entitled to hold the corresponding private key, that representations and material information given to the Certifying Authority are true, and that certificate information within the subscriber's knowledge is true.
Section 40 of the Information Technology Act, 2000
A subscriber accepting a Digital Signature Certificate containing a public key corresponding to the subscriber's private key must generate the corresponding public-private key pair by applying the applicable security procedure. This requirement ensures that the key pair recorded through the certificate is created in accordance with required security safeguards.
Section 39 of the Information Technology Act, 2000
Notice of suspension or revocation of a Digital Signature Certificate must be published by the Certifying Authority in the repository identified in the certificate. Where more than one repository is specified, publication is mandatory in every specified repository.
Section 38 of the Information Technology Act, 2000
Revocation of a Digital Signature Certificate may occur on the subscriber's request, death, insolvency, or the dissolution or winding up of a subscribing firm or company. It may also be based on false or concealed material facts, unmet issuance requirements, or a security compromise materially affecting certificate reliability. The subscriber must be given an opportunity to be heard before revocation, and the Certifying Authority must communicate the revocation to the subscriber.
Section 37 of the Information Technology Act, 2000
Suspension of a Digital Signature Certificate may occur on the request of the listed subscriber or a duly authorised representative, or where required in the public interest. Suspension cannot continue beyond fifteen days unless the subscriber has been given an opportunity to be heard. The subscriber must be informed once suspension occurs.
Section 36 of the Information Technology Act, 2000
Issuance of a Digital Signature Certificate requires certification of legal compliance, subscriber acceptance, availability of the certificate to relying persons, and the subscriber's control of the corresponding private key. The private key must create a digital signature, the public key must verify it, and both must form a functioning key pair. Certificate information must be accurate, and no known material fact may undermine the reliability of these representations.
Section 35 of the Information Technology Act, 2000
Electronic signature Certificate applications must be made in the prescribed form, with the prescribed fee and a certification practice statement or regulatory particulars where no such statement exists. The Certifying Authority may conduct enquiries before granting a Certificate. Any rejection must be supported by written reasons, and the applicant must receive a reasonable opportunity to show cause against the proposed rejection.
Section 34 of the Information Technology Act, 2000
Certifying Authorities must disclose electronic signature certificates, relevant certification practice statements, certificate revocation or suspension, and facts materially affecting certificate reliability or their ability to provide certification services. Where an event may materially affect computer-system integrity or conditions governing grant of an electronic signature certificate, they must notify persons likely to be affected through reasonable efforts or follow the procedure in their certification practice statements.
Section 33 of the Information Technology Act, 2000
Every Certifying Authority whose licence is suspended or revoked must immediately surrender the licence to the Controller. Failure to surrender the licence makes the person in whose favour it was issued liable to a penalty, which may extend to five lakh rupees.
Section 32 of the Information Technology Act, 2000
Every Certifying Authority must display its licence conspicuously at the premises where it carries on business. The requirement ensures that the licence is readily visible at the operational site.
Section 31 of the Information Technology Act, 2000
Certifying Authorities must ensure that every employee and other person engaged by them complies, while acting in the course of employment or engagement, with the Information Technology Act, 2000, and all rules, regulations, and orders made under it. The provision imposes an institutional compliance responsibility extending beyond the certifying entity itself to persons performing work under its direction or on its behalf.
Section 30 of the Information Technology Act, 2000
Certifying Authorities must deploy systems and procedures secure from intrusion and misuse, provide reliable services suited to intended functions, and protect the secrecy and privacy of electronic signatures. They must maintain a repository of issued electronic signature Certificates, publish information on their practices and certificate status, and comply with further regulatory standards.
Section 29 of the Information Technology Act, 2000
Section 29 permits the Controller or an authorised person, on reasonable cause to suspect a contravention of the relevant Chapter, to access computer systems, connected apparatus, data and other material for obtaining available information or data. A person responsible for or involved in operating the relevant system, data, apparatus or material may be ordered to provide reasonable technical and other necessary assistance.
Section 28 of the Information Technology Act, 2000
Section 28 establishes an investigation mechanism for contraventions of the Information Technology Act, 2000, and of rules and regulations made under it. The Controller or an authorised officer must investigate such contraventions and exercise powers corresponding to those conferred on Income-tax authorities, subject to applicable statutory limitations.
Section 27 of the Information Technology Act, 2000
Written authorisation enables the Controller to delegate any power exercisable under the Chapter regulating Certifying Authorities to a Deputy Controller, Assistant Controller, or any other officer. Delegation must be made in writing and permits the authorised officer to exercise those delegated Controller powers within the Chapter pursuant to that authorisation.
Section 26 of the Information Technology Act, 2000
Suspension or revocation of a Certifying Authority's licence requires the Controller to publish notice in the maintained database and, where repositories are specified, in each repository. The database carrying the notice must remain accessible through a website on a round-the-clock basis. Further publicity may be given through appropriate electronic or other media where considered necessary.
Section 25 of the Information Technology Act, 2000
Licensing control of Certifying Authorities permits the Controller to revoke a licence for materially false application particulars, breach of licence conditions, failure to maintain prescribed procedures and standards, or contravention of applicable legal requirements. Revocation requires a reasonable opportunity to show cause. Where reasonable cause exists for revocation, the licence may be suspended pending inquiry; suspension beyond ten days also requires such opportunity. No electronic signature certificates may be issued during suspension.
Section 24 of the Information Technology Act, 2000
Licensing of Certifying Authorities requires the Controller to consider the documents accompanying a licence application and other appropriate factors before granting or rejecting it. Rejection is subject to procedural fairness, and cannot occur unless the applicant has been given a reasonable opportunity to present its case.
Section 23 of the Information Technology Act, 2000
Renewal of a Certifying Authority licence requires an application in the prescribed form, accompanied by the prescribed fee subject to a maximum of five thousand rupees, and filed at least forty-five days before expiry of the licence validity period. The Central Government prescribes the applicable form and fee within that limit.
Section 22 of the Information Technology Act, 2000
Applications for a licence must be made in the form prescribed by the Central Government and accompanied by a certification practice statement, applicant-identification procedures, the prescribed fee subject to the statutory ceiling, and other prescribed documents.