All NotesCivil LawInformation Technology Act, 2000

Information Technology Act, 2000

Controller of Certifying Authorities: Sections 17 to 20 IT Act

Electronic signatures work only if certificates can be trusted, and certificates can be trusted only if someone licenses and polices the businesses that issue them. That someone is the Controller of Certifying Authorities. Sections 17 to 20 create the office, list its functions, and provide for recognising foreign Certifying Authorities. Topic 6 introduced the regulatory scheme and Topic 41 covered the eSign rules; this note is the complete study of the Controller itself: appointment, functions, the Root Certifying Authority of India, cross-border recognition, the omitted Section 20, and the Controller and Certifying Authority compared.

1. The Mint Master of Digital Trust

Coins circulate because a mint stands behind them, and the mint is inspected by a master who licenses it, sets the standards for its dies, audits its books and can shut it down. In the world of electronic signatures, the Certifying Authorities are the mints, striking certificates instead of coins, and the Controller is the mint master. His own signature on their public keys is what makes every certificate in the country traceable to one trusted root.

2. Section 17: Appointment of the Controller and Officers

  • Appointment (s.17(1)). The Central Government may, by notification, appoint a Controller of Certifying Authorities, and may also appoint such number of Deputy Controllers, Assistant Controllers, other officers and employees as it deems fit. The words 'other officers and employees' were added by the 2008 Amendment.
  • Subordination (s.17(2)). The Controller discharges his functions subject to the general control and directions of the Central Government.
  • Deputy and Assistant Controllers (s.17(2A), (2B) sense). They perform the functions assigned to them by the Controller under his general superintendence and control.
  • Qualifications and conditions of service (s.17(3)). The qualifications, experience and terms and conditions of service of the Controller, Deputy Controllers, Assistant Controllers and other officers are such as may be prescribed by the Central Government.
  • Head office and branches (s.17(4), (5)). The head office and branch offices are at the places the Central Government specifies; the office was established in November 2000 and functions under MeitY.
  • Seal. The office has its own seal, reflecting its status as a distinct statutory authority.

The hierarchy of digital signature regulation

Figure 1: The hierarchy of digital signature regulation

3. Section 18: Functions of the Controller

Section 18, Information Technology Act, 2000 (substance)

The Controller may perform all or any of the following functions: (a) exercising supervision over the activities of the Certifying Authorities; (b) certifying public keys of the Certifying Authorities; (c) laying down the standards to be maintained by the Certifying Authorities; (d) specifying the qualifications and experience which employees of the Certifying Authorities should possess; (e) specifying the conditions subject to which the Certifying Authorities shall conduct their business; (f) specifying the contents of written, printed or visual materials and advertisements that may be distributed or used in respect of an Electronic Signature Certificate and the public key; (g) specifying the form and content of an Electronic Signature Certificate and the key; (h) specifying the form and manner in which accounts shall be maintained by the Certifying Authorities; (i) specifying the terms and conditions subject to which auditors may be appointed and the remuneration to be paid to them; (j) facilitating the establishment of any electronic system by a Certifying Authority either solely or jointly with other Certifying Authorities and regulation of such systems; (k) specifying the manner in which the Certifying Authorities shall conduct their dealings with the subscribers; (l) resolving any conflict of interests between the Certifying Authorities and the subscribers; (m) laying down the duties of the Certifying Authorities; (n) maintaining a data base containing the disclosure record of every Certifying Authority containing such particulars as may be specified by regulations, which shall be accessible to public.

The functions of the Controller grouped

Figure 2: The functions of the Controller grouped

  • Supervision of Certifying Authorities. The umbrella function: licensing under Chapter VI, audits, directions under Section 68, and investigation of contraventions through powers under Sections 28 and 29.
  • Certification of public keys: the Root CA. By certifying each CA's public key, the Controller operates the Root Certifying Authority of India (RCAI). Every verification chain ends at the Controller's self-signed root certificate, which is what makes an Indian digital signature verifiable by anyone.
  • Standards for CAs and their employees. Technical and operational standards for CA infrastructure, and the qualifications and experience CA employees must hold, keeping weak or careless operators out of the trust chain.
  • Conditions for conduct of business. The terms on which CAs operate, including their dealings with subscribers, their advertisements about certificates, and the resolution of conflicts of interest with subscribers.
  • Contents of the Certification Practice Statement. The CPS is the statement of practices a CA follows in issuing certificates (s.2(1)(k)). The Controller specifies what it must contain, and the CA's licence application must include it (s.21 read with the rules)
  • Standards for certificates. The form and content of Electronic Signature Certificates and keys, aligned with international standards such as X.509, so that certificates interoperate.
  • Accounts and audit. The form of CA accounts and the terms and remuneration of auditors, supporting the annual audit discipline in the Certifying Authorities Rules.
  • Maintenance of the public database. The disclosure record of every CA, accessible to the public, so that anyone can check who is licensed, suspended or revoked; in practice published on cca.gov.in along with the certificate trust lists.

4. Section 19: Recognition of Foreign Certifying Authorities

Section 19, Information Technology Act, 2000 (substance)

(1) Subject to such conditions and restrictions as may be specified by regulations, the Controller may, with the previous approval of the Central Government, and by notification in the Official Gazette, recognise any foreign Certifying Authority as a Certifying Authority for the purposes of this Act.

(2) Where any Certifying Authority is recognised under sub-section (1), the Electronic Signature Certificate issued by such Certifying Authority shall be valid for the purposes of this Act.

(3) The Controller may, if he is satisfied that any Certifying Authority has contravened any of the conditions and restrictions subject to which it was granted recognition under sub-section (1), he may, for reasons to be recorded in writing, by notification in the Official Gazette, revoke such recognition.

Recognition of a foreign Certifying Authority

Figure 3: Recognition of a foreign Certifying Authority

  • Foreign electronic signature certificates. Once a foreign CA is recognised, its certificates are valid for the purposes of the Act, so signatures verified against them count as electronic signatures in India.
  • Safeguards. Recognition needs the previous approval of the Central Government, comes with conditions and restrictions, and is revocable by a reasoned, notified order for contravention.
  • Cross-border recognition of electronic signatures. Section 19 is India's mechanism for cross-border trust. In practice, cross-border acceptance still mostly runs through contract (parties agreeing to accept each other's signature frameworks) or through the foreign signer obtaining a certificate from an Indian licensed CA, and trade agreements increasingly address mutual recognition of e-signatures.
  • Why it matters for exams. The section shows the Act anticipated globalised commerce in 2000 itself, and it pairs with Section 1(2) and Section 75 on the Act's reach beyond India.

5. The Omitted Section 20 and the Office Today

  • Section 20 as enacted. Originally, the Controller was to act as the repository of all Digital Signature Certificates, maintain a computerised database of every certificate and ensure its secrecy.
  • Omission in 2008. The 2008 Amendment omitted Section 20. Keeping every subscriber's certificate in one government repository was unnecessary, since each CA maintains its own repository and the Controller's own database under Section 18(n) covers the CAs' disclosure records.
  • The office today. The CCA licenses and audits the CAs, operates the RCAI, publishes certificate trust lists, and issues the guidelines that run the eSign system, in which every eSign Service Provider must be a licensed CA (see Topic 41)

The Controller's office over time

Figure 4: The Controller's office over time

6. Controller vs Certifying Authority

Controller and Certifying Authority compared

Figure 5: Controller and Certifying Authority compared

  • Nature. The Controller is a statutory regulator appointed by the Central Government; a Certifying Authority is a licensed enterprise that has been granted a licence to issue Electronic Signature Certificates (s.2(1)(g))
  • Whose keys they certify. The Controller certifies the public keys of CAs; a CA certifies the public keys of subscribers by issuing them certificates.
  • Discipline. The Controller can suspend or revoke a CA's licence (s.25) and give it directions (s.68); a CA can suspend or revoke a subscriber's certificate (ss.37, 38)
  • Appeals. Orders of the Controller and adjudicating officers go to the Appellate Tribunal, now TDSAT (s.57)

⚠ Exam trap

Three slips are common. First, the Controller does not issue certificates to the public; the CAs do, and the Controller certifies the CAs' own keys. Secondly, recognition of a foreign CA needs the previous approval of the Central Government and a Gazette notification; the Controller cannot do it alone. Thirdly, Section 20 no longer exists; citing the Controller as the repository of all certificates describes the pre-2008 law.

7. Quick Revision and Memory Aids

  • 'Mint master of digital trust'. The Controller's role.
  • '17 appoints, 18 empowers, 19 globalises, 20 gone'. The four sections.
  • 'Supervise, certify, standardise, publicise'. The core of s.18.
  • 'Approval, notification, conditions, revocation'. Foreign CA recognition.
  • 'Controller licenses mints; mints strike certificates'. Controller vs CA.

8. Frequently Asked Questions

What are the main functions of the Controller of Certifying Authorities?

Under Section 18: supervising Certifying Authorities, certifying their public keys as the Root CA, laying down standards for them and their employees, specifying the conditions and manner of their business and their dealings with subscribers, prescribing the form of certificates and accounts, resolving conflicts with subscribers, laying down CA duties, and maintaining a public database of CA disclosure records.

Can a foreign Certifying Authority operate in India?

Yes, if the Controller, with the previous approval of the Central Government, recognises it by Gazette notification under Section 19, subject to conditions. Its certificates are then valid under the Act, and the recognition can be revoked by a reasoned notification for contravention.

9. Related Topics

  • Topic 6: Legal Recognition and Certifying Authorities. The licensing scheme in Chapter VI.
  • Topic 41: eSign Rules 2015. How the CCA runs the eSign framework.