Information Technology Act Section 42 β Control of private key
CHAPTER VIII DUTIES OF SUBSCRIBERS
Cyber Law
Summary
Sub-section (1) requires every subscriber to take reasonable care to keep control of their private key, which is the key that matches the public key listed in their Digital Signature Certificate. The subscriber must also take all steps to prevent the private key from being disclosed to anyone else.
Sub-section (2) states that if the private key corresponding to the public key in the Digital Signature Certificate has been compromised, the subscriber must inform the Certifying Authority about this without any delay. The manner of communicating this information is to be as specified by the regulations.
The Explanation clarifies that the subscriber remains liable until they have informed the Certifying Authority that the private key has been compromised.
Official Text
(1) Every subscriber shall exercise reasonable care to retain control of the private key corresponding to the public key listed in his Digital Signature Certificate and take all steps to prevent its disclosure 4***.
(2) If the private key corresponding to the public key listed in the Digital Signature Certificate has been compromised, then, the subscriber shall communicate the same without any delay to the Certifying Authority in such manner as may be specified by the regulations.
Explanation.βFor the removal of doubts, it is hereby declared that the subscriber shall be liable till he has informed the Certifying Authority that the private key has been compromised.