Information Technology Act Section 38 — Revocation of Digital Signature Certificate
CHAPTER VI REGULATION OF CERTIFYING AUTHORITIES
Cyber Law
Summary
Sub-section (1) allows a Certifying Authority to revoke a Digital Signature Certificate it has issued in three situations: when the subscriber or someone authorised by the subscriber asks for it to be revoked; when the subscriber has died; or when the subscriber is a firm or company and that firm or company has been dissolved or wound up.
Under clause (a) of sub-section (1), revocation can happen if the subscriber or any person authorised by the subscriber makes a request to that effect. Under clause (b) of sub-section (1), revocation can happen upon the death of the subscriber. Under clause (c) of sub-section (1), revocation can happen when the subscriber is a firm or company and that firm or company is dissolved or wound up.
Sub-section (2) says that, subject to sub-section (3) and without affecting sub-section (1), a Certifying Authority may revoke a Digital Signature Certificate it has issued at any time if it believes that any of the following conditions apply: a material fact stated in the certificate is false or has been hidden; a requirement for issuing the certificate was not met; the Certifying Authority's private key or security system was compromised in a way that materially affects the certificate's reliability; or the subscriber has been declared insolvent or dead, or if the subscriber is a firm or company, it has been dissolved, wound up, or otherwise ceased to exist.
Under clause (a) of sub-section (2), revocation is possible if a material fact represented in the certificate is false or has been concealed. Under clause (b) of sub-section (2), revocation is possible if a requirement for issuance of the certificate was not satisfied. Under clause (c) of sub-section (2), revocation is possible if the Certifying Authority's private key or security system was compromised in a manner materially affecting the certificate's reliability. Under clause (d) of sub-section (2), revocation is possible if the subscriber has been declared insolvent or dead, or if the subscriber is a firm or company that has been dissolved, wound up, or otherwise ceased to exist.
Sub-section (3) states that a Digital Signature Certificate shall not be revoked unless the subscriber has been given an opportunity to be heard in the matter.
Sub-section (4) states that when a Digital Signature Certificate is revoked under this section, the Certifying Authority must communicate the revocation to the subscriber.
Official Text
(1) A Certifying Authority may revoke a Digital Signature Certificate issued by it–
(a) where the subscriber or any other person authorised by him makes a request to that effect; or
(b) upon the death of the subscriber; or
(c) upon the dissolution of the firm or winding up of the company where the subscriber is a firm or a company.
(2) Subject to the provisions of sub-section (3) and without prejudice to the provisions of sub-section (1), a Certifying Authority may revoke a Digital Signature Certificate which has been issued by it at any time, if it is of opinion that–
(a) a material fact represented in the Digital Signature Certificate is false or has been concealed;
(b) a requirement for issuance of the Digital Signature Certificate was not satisfied;
(c) the Certifying Authority's private key or security system was compromised in a manner materially affecting the Digital Signature Certificate's reliability;
(d) the subscriber has been declared insolvent or dead or where a subscriber is a firm or a company, which has been dissolved, wound-up or otherwise ceased to exist.
(3) A Digital Signature Certificate shall not be revoked unless the subscriber has been given an opportunity of being heard in the matter.
(4) On revocation of a Digital Signature Certificate under this section, the Certifying Authority shall communicate the same to the subscriber.