Information Technology Act Section 36 — Representations upon issuance of Digital Signature Certificate
CHAPTER VI REGULATION OF CERTIFYING AUTHORITIES
Cyber Law
Summary
A Certifying Authority, when it issues a Digital Signature Certificate, must certify certain things.
Under clause (a), it must certify that it has followed the provisions of this Act and the rules and regulations made under it.
Under clause (b), it must certify that it has published the Digital Signature Certificate or otherwise made it available to the person relying on it, and that the subscriber has accepted it.
Under clause (c), it must certify that the subscriber holds the private key that corresponds to the public key listed in the Digital Signature Certificate.
Under clause (ca), it must certify that the subscriber holds a private key which is capable of creating a digital signature.
Under clause (cb), it must certify that the public key to be listed in the certificate can be used to verify a digital signature affixed by the private key held by the subscriber.
Under clause (d), it must certify that the subscriber's public key and private key together form a functioning key pair.
Under clause (e), it must certify that the information contained in the Digital Signature Certificate is accurate.
Under clause (f), it must certify that it has no knowledge of any material fact which, if it had been included in the Digital Signature Certificate, would adversely affect the reliability of the representations made in clauses (a) to (d).
Official Text
A Certifying Authority while issuing a Digital Signature Certificate shall certify that—
(a) it has complied with the provisions of this Act and the rules and regulations made thereunder;
(b) it has published the Digital Signature Certificate or otherwise made it available to such person relying on it and the subscriber has accepted it;
(c) the subscriber holds the private key corresponding to the public key, listed in the Digital Signature Certificate; 1[
(ca) the subscriber holds a private key which is capable of creating a digital signature;
(cb) the public key to be listed in the certificate can be used to verify a digital signature affixed by the private key held by the subscriber;]
(d) the subscriber's public key and private key constitute a functioning key pair;
(e) the information contained in the Digital Signature Certificate is accurate; and
(f) it has no knowledge of any material fact, which if it had been included in the Digital Signature Certificate would adversely affect the reliability of the representations in clauses
(a) to (d).