Information Technology Act Section 38 — Revocation of Digital Signature Certificate

CHAPTER VI REGULATION OF CERTIFYING AUTHORITIES

Cyber Law

Summary

Sub-section (1) allows a Certifying Authority to revoke a Digital Signature Certificate it has issued in three situations: when the subscriber or someone authorised by the subscriber asks for it to be revoked; when the subscriber has died; or when the subscriber is a firm or company and that firm or company has been dissolved or wound up.

Under clause (a) of sub-section (1), revocation can happen if the subscriber or any person authorised by the subscriber makes a request to that effect. Under clause (b) of sub-section (1), revocation can happen upon the death of the subscriber. Under clause (c) of sub-section (1), revocation can happen when the subscriber is a firm or company and that firm or company is dissolved or wound up.

Sub-section (2) says that, subject to sub-section (3) and without affecting sub-section (1), a Certifying Authority may revoke a Digital Signature Certificate it has issued at any time if it believes that any of the following conditions apply: a material fact stated in the certificate is false or has been hidden; a requirement for issuing the certificate was not met; the Certifying Authority's private key or security system was compromised in a way that materially affects the certificate's reliability; or the subscriber has been declared insolvent or dead, or if the subscriber is a firm or company, it has been dissolved, wound up, or otherwise ceased to exist.

Under clause (a) of sub-section (2), revocation is possible if a material fact represented in the certificate is false or has been concealed. Under clause (b) of sub-section (2), revocation is possible if a requirement for issuance of the certificate was not satisfied. Under clause (c) of sub-section (2), revocation is possible if the Certifying Authority's private key or security system was compromised in a manner materially affecting the certificate's reliability. Under clause (d) of sub-section (2), revocation is possible if the subscriber has been declared insolvent or dead, or if the subscriber is a firm or company that has been dissolved, wound up, or otherwise ceased to exist.

Sub-section (3) states that a Digital Signature Certificate shall not be revoked unless the subscriber has been given an opportunity to be heard in the matter.

Sub-section (4) states that when a Digital Signature Certificate is revoked under this section, the Certifying Authority must communicate the revocation to the subscriber.

Official Text

(1) A Certifying Authority may revoke a Digital Signature Certificate issued by it–

(a) where the subscriber or any other person authorised by him makes a request to that effect; or

(b) upon the death of the subscriber; or

(c) upon the dissolution of the firm or winding up of the company where the subscriber is a firm or a company.

(2) Subject to the provisions of sub-section (3) and without prejudice to the provisions of sub-section (1), a Certifying Authority may revoke a Digital Signature Certificate which has been issued by it at any time, if it is of opinion that–

(a) a material fact represented in the Digital Signature Certificate is false or has been concealed;

(b) a requirement for issuance of the Digital Signature Certificate was not satisfied;

(c) the Certifying Authority's private key or security system was compromised in a manner materially affecting the Digital Signature Certificate's reliability;

(d) the subscriber has been declared insolvent or dead or where a subscriber is a firm or a company, which has been dissolved, wound-up or otherwise ceased to exist.

(3) A Digital Signature Certificate shall not be revoked unless the subscriber has been given an opportunity of being heard in the matter.

(4) On revocation of a Digital Signature Certificate under this section, the Certifying Authority shall communicate the same to the subscriber.