Advanced Search Options : ❯
Section 42 of the Information Technology Act, 2000
Subscribers must exercise reasonable care to retain control of the private key corresponding to the public key in their Digital Signature Certificate and prevent unauthorised disclosure. A compromised private key must be promptly reported to the Certifying Authority in the prescribed manner. Liability continues until the Certifying Authority is informed of the compromise.
Section 41 of the Information Technology Act, 2000
Acceptance of a Digital Signature Certificate is deemed where a subscriber publishes or authorises its publication, places it in a repository, or otherwise demonstrates approval. The subscriber thereby certifies to reasonable relying parties that the corresponding private key is held lawfully, representations and material information given to the Certifying Authority are true, and information in the certificate within the subscriber's knowledge is true.
Section 40 of the Information Technology Act, 2000
A subscriber accepting a Digital Signature Certificate that lists a public key corresponding to the subscriber's private key must generate the associated key pair by applying the security procedure. This duty links certificate acceptance to secure generation of the public and private keys underlying the certificate.
Section 39 of the Information Technology Act, 2000
Suspension or revocation of a Digital Signature Certificate requires the Certifying Authority to publish a corresponding notice in the repository identified in that certificate for such publication. Where the certificate specifies one or more repositories, the notice must be published in every repository so specified. This mandatory repository-publication requirement applies to each instance of suspension or revocation affecting the certificate.
Section 38 of the Information Technology Act, 2000
A Digital Signature Certificate may be revoked upon the subscriber's request, death, insolvency, or cessation of existence, and where material information is false or concealed, issuance requirements were unmet, or certificate reliability is materially affected by a security compromise. Revocation requires an opportunity of being heard for the subscriber. The Certifying Authority must communicate the revocation to the subscriber.
Section 37 of the Information Technology Act, 2000
Suspension of a Digital Signature Certificate may be undertaken upon a request from the listed subscriber or a person duly authorised to act for that subscriber, or where suspension is considered necessary in the public interest. Suspension may not continue beyond fifteen days unless the subscriber has been afforded an opportunity to be heard. Once suspension is effected, it must be communicated to the subscriber.
Section 36 of the Information Technology Act, 2000
A Certifying Authority issuing a Digital Signature Certificate must certify compliance with the Act and rules and regulations, certificate availability to a relying person, and subscriber acceptance. It must confirm that the subscriber holds the corresponding private key, the public and private keys form a functioning key pair, and certificate information is accurate. It must also lack knowledge of material facts adversely affecting the reliability of these representations.
Section 35 of the Information Technology Act, 2000
Applications for a Digital Signature Certificate must be made in the prescribed form, with the prescribed fee and a certification practice statement or other required statement. Issuance depends on verification that the applicant holds a functional private key corresponding to the listed public key and that the public key can verify signatures created by that private key. Rejection requires recorded reasons and a reasonable opportunity for the applicant to show cause.
Section 34 of the Information Technology Act, 2000
Certifying Authorities must disclose their Digital Signature Certificate and corresponding public key, relevant certification practice statement, revocation or suspension of their certificate, and material adverse facts affecting issued certificates or service capability. Where an event may adversely affect computer-system integrity or conditions governing a Digital Signature Certificate, they must reasonably notify affected persons or follow the procedure in their certification practice statement.
Section 33 of the Information Technology Act, 2000
Section 33 requires every Certifying Authority whose licence is suspended or revoked to immediately surrender the licence to the Controller. Failure to do so constitutes an offence by the person in whose favour the licence was issued, punishable by imprisonment for up to six months, a fine up to ten thousand rupees, or both.
Section 32 of the Information Technology Act, 2000
Every Certifying Authority must conspicuously display its licence at the premises where it carries on business. This requirement ensures that the authority's authorisation is visibly available at its operational location.
Section 31 of the Information Technology Act, 2000
Certifying Authorities must ensure that every person employed or otherwise engaged by them complies, during such employment or engagement, with the Information Technology Act, its rules, regulations, and orders made under it. The obligation requires each Certifying Authority to secure personnel compliance with the applicable statutory and regulatory framework.
Section 30 of the Information Technology Act, 2000
Certifying Authorities must use hardware, software and procedures secure against intrusion and misuse, provide reasonably reliable services suited to intended functions, and maintain security procedures assuring the secrecy and privacy of digital signatures. They must also comply with further operational and security standards prescribed through regulations.
Section 29 of the Information Technology Act, 2000
Where reasonable cause exists to suspect a contravention of the Information Technology Act, its rules, or regulations, authorised access may be made to computer systems, connected apparatus, data, and other material to search for information or data. Persons operating or otherwise concerned with the relevant system or material may be ordered to provide reasonable technical and other assistance necessary for that access and search.
Section 28 of the Information Technology Act, 2000
Investigation of contraventions is entrusted to the Controller or an officer authorised for that purpose. They must investigate breaches of applicable statutory provisions, rules, or regulations, and may exercise powers corresponding to those available to income-tax authorities, subject to the limitations governing those powers.
Section 27 of the Information Technology Act, 2000
Written delegation of powers enables the Controller to authorise a Deputy Controller, Assistant Controller, or any officer to exercise powers vested in the Controller under the relevant chapter. Delegation depends on written authorisation and permits designated officers to exercise those chapter-specific functions to the extent authorised in writing. This mechanism allows administrative exercise of the Controller's powers by specifically authorised officials.
Section 26 of the Information Technology Act, 2000
Suspension or revocation of a Certifying Authority's licence requires publication of notice in the Controller's database and, where specified, in every designated repository. The database must be available through a website accessible round the clock. Where necessary, the Controller may further publicise its contents through electronic or other appropriate media.
Section 25 of the Information Technology Act, 2000
Licence revocation may be ordered after inquiry for materially false application statements, breach of licence conditions, failure to maintain prescribed standards, or contravention of applicable requirements, subject to a reasonable opportunity to show cause. Licence suspension may be imposed pending inquiry where grounds for revocation are reasonably believed to exist. Suspension beyond ten days requires an opportunity to show cause, and no Digital Signature Certificates may be issued during suspension.
Section 24 of the Information Technology Act, 2000
Licensing of certifying authorities permits the Controller, on receiving an application under section 21, to grant a licence or reject it after considering the application, accompanying documents and other appropriate factors. Rejection is conditional on giving the applicant a reasonable opportunity to present its case before an adverse decision is made.
Section 23 of the Information Technology Act, 2000
Licence renewal requires an application in the form prescribed by the Central Government, accompanied by the prescribed fee subject to a maximum of five thousand rupees. The application must be submitted at least forty-five days before expiry of the licence's validity period. These requirements establish the form, fee ceiling, and advance-filing condition governing renewal of licences under the regulatory framework for certifying authorities.