12CCHAPTER VIII

 DUTIES OF SUBSCRIBERS

40. Generating key pair in the case of Digital Signature Certificate

 

Where any Digital Signature Certificate, the public key of which corresponds to the private key of that subscriber which is to be listed in the Digital Signature Certificate has been accepted by a subscriber, then, the subscriber shall generate that the R1 key pair by applying the security procedure.

 

42 41.  Control of private key in the case of Digital Signature Certificate

 

(1) Every subscriber shall exercise reasonable care to retain control of the private key corresponding to the public key listed in his Digital Signature Certificate and take all steps to prevent its disclosure to a person not authorised to affix the digital signature of the subscriber.

(2) If the private key corresponding to the public key listed in the Digital Signature Certificate has been compromised, then, the subscriber shall communicate the same without any delay to the Certifying Authority in such manner as may be specified by the regulations.

Explanation- For the removal of doubts, it is hereby declared that the subscriber shall be liable till he has informed the Certifying Authority that the private key has been compromised.

 

41ADuties of the subscribers in the case of Electronic  Signature: 

12D[2]The subscriber shall be bound by such duties as the Central Government may prescribe in respect of electronic signature certificates and in the case of  Digital Signature in addition to those provided in Sections 40 and 41.

 

421. Acceptance of DigitalElectronic14A Signature Certificate
(1) A subscriber shall be deemed to have accepted an DigitalElectronic
14A Signature Certificate if he publishes or authorises the publication of an DigitalElectronic14A Signature Certificate-

(a) to one or more persons;

(b) in a repository, or

otherwise demonstrates his approval of the DigitalElectronic
14A Signature Certificate in any manner,

R2(2) By accepting an DigitalElectronic
14A Signature the subscriber certifies to all who reasonably rely on the information contained in the DigitalElectronic14A Signature Certificate that-

(a) in the case of Digital Signature the subscriber controls holds the private key corresponding to the public key listed in the Digital Digital Signature Certificate and is entitled to hold the same;

(b) all representations made by the subscriber to the Certifying Authority and all material relevant to the information contained in the DigitalElectronic
14A Signature Certificate are true.;

(c) all information in the DigitalElectronic
14A Signature Certificate that is within the knowledge of the subscriber is true;.

 

(d)  the electronic signature certificate is being used in accordance with the certification practice statement of the Certifying Authority for the time being in force;. and

 

(e)     he acknowledges and accepts the terms contained in the Certification Practice Statement of the Certifying Authority.

 

42 Control of private key42a

 

(1) Every subscriber shall exercise shall exercise reasonable care to retain control of the private key corresponding to the public key listed in his Digital Signature Certificate and take all steps to prevent its disclosure to a person not authorised to affix the digital signature of the subscriber.

(2) If the private key corresponding to the public key listed in the Digital Signature Certificate has been compromised, then, the subscriber shall communicate the same without and delay to the Certifying Authority in such manner as may be specified by the regulations.

Explanation- For the removal of doubts, it is hereby declared that the subscriber shall be liable to till he has informed the Certifying Authority that the private key has been compromised

 

12C This chapter requires rearrangement because of technology neutral concept. The matter relating to digital certificate is placed first , then duties of the subscribers in case of certificate other than digital certificate

R1 Amended vide order no. S.O. 1015(E) dated September 19, 2002

12D As the other technology have not been developed fully as and when things mature the Government can prescribe duties

 14A In this clause and in number of other places the term “ Digital” has been changed to “Electronic”  to enable the Act to be technology neutral

 R2 Amended vide order no. S.O. 1015(E) dated September 19, 2002

42a This section has been deleted as it related to a CA and its subscriber