Information Technology Act, 2000
Duties of Subscribers: Sections 40 to 42 IT Act
The whole signature system finally rests on one person: the subscriber who holds the private key. Chapter VIII, just three sections and an inserted fourth, sets out his side of the bargain: generate the key pair properly (s.40), perform the prescribed duties for an electronic signature certificate (s.40A), stand behind the certificate he accepts (s.41), and guard the private key, reporting at once if it is compromised (s.42). The Explanation to Section 42 carries the chapter's sting: until the subscriber tells the Certifying Authority of a compromise, the losses are his. This note covers each duty, the liability rule, and the division of responsibility between subscriber and CA.
1. The Man Who Holds the Stamp
A company seal means nothing if it is left on the front desk. The law can license the seal maker, register the design and punish forgers, but the person who keeps the stamp must lock it away and raise the alarm the moment it goes missing; until he does, every impression it makes looks like his. Chapter VIII is that duty written for the private key: the subscriber is the man who holds the stamp.
Figure 1: The subscriber's duties in sequence
2. Who Is a Subscriber
- Definition. A subscriber is a person in whose name the Electronic Signature Certificate is issued (s.2(1)(zg))
- Where he stands. He applies under Section 35, is verified by the CA, accepts the certificate, and thereafter authenticates records under Sections 3 and 3A with the private key the certificate vouches for.
- Why his duties matter. Relying parties never meet the subscriber; they trust the certificate. The system holds only if the key the certificate points to stays in one pair of hands, which is exactly what Chapter VIII, Section 15 (secure signatures) and Section 36 (CA representations) each assume.
3. Section 40: Generation of the Key Pair
Section 40, Information Technology Act, 2000 Where any Digital Signature Certificate, the public key of which corresponds to the private key of that subscriber which is to be listed in the Digital Signature Certificate has been accepted by a subscriber, then, the subscriber shall generate the key pair by applying the security procedure. |
- The duty. The key pair must be generated by applying the security procedure, not by any casual method. In practice this means generation on the prescribed crypto token or, for eSign, inside the ESP's hardware security module.
- Why generation matters. A key pair generated on an insecure machine may already be copied at birth. The duty ensures the private key is born secret, which is the premise of every later presumption.
- Whose key it is. The subscriber generates the pair; the CA never holds the private key. This is why the CA can honestly certify the public key without ever being able to sign for the subscriber.
4. Section 40A: Duties for Electronic Signature Certificates
- The provision. Inserted in 2008: in respect of an Electronic Signature Certificate, the subscriber shall perform such duties as may be prescribed.
- Why it exists. Sections 40 to 42 were written for the digital signature and its key pair. When Section 3A opened the door to other techniques, Section 40A let the Central Government prescribe matching duties for each technique in the Second Schedule.
- In practice. For eSign, the duties travel through the rules and the CCA framework: truthful e-KYC, electronic consent for each signature, and keeping the authentication factor (the OTP, PIN or biometric session) to oneself, since it plays the role the token plays for a DSC.
5. Section 41: Acceptance and Its Representations
Section 41, Information Technology Act, 2000 (substance) (1) A subscriber shall be deemed to have accepted a Digital Signature Certificate if he publishes or authorises the publication of a Digital Signature Certificate to one or more persons, or in a repository, or otherwise demonstrates his approval of the Digital Signature Certificate in any manner. (2) By accepting a Digital Signature Certificate the subscriber certifies to all who reasonably rely on the information contained in the Digital Signature Certificate that (a) the subscriber holds the private key corresponding to the public key listed in the Digital Signature Certificate and is entitled to hold the same; (b) all representations made by the subscriber to the Certifying Authority and all material relevant to the information contained in the Digital Signature Certificate are true; (c) all information in the Digital Signature Certificate that is within the knowledge of the subscriber is true. |
Figure 2: Acceptance and what it certifies
- Acceptance is conduct. No signed acceptance form is needed. Publishing the certificate, authorising its publication in a repository, or any conduct demonstrating approval is acceptance.
- Representations by acceptance. The subscriber's mirror of Section 36: while the CA vouches for its process, the subscriber vouches for his facts, that he holds and is entitled to hold the key, and that what he told the CA and what the certificate states are true.
- To whom. The representations run to all who reasonably rely on the certificate, so a relying party misled by the subscriber's false particulars has a statement to hold him to.
- Link to acceptance-based duties. Acceptance is also the hinge for Section 40 (the generation duty applies once the certificate is accepted) and for the presumption in Section 87 BSA (the certificate's information is presumed correct where the subscriber accepted it)
6. Section 42: Control of the Private Key
Section 42, Information Technology Act, 2000 (1) Every subscriber shall exercise reasonable care to retain control of the private key corresponding to the public key listed in his Digital Signature Certificate and take all steps to prevent its disclosure. (2) If the private key corresponding to the public key listed in the Digital Signature Certificate has been compromised, then, the subscriber shall communicate the same without any delay to the Certifying Authority in such manner as may be specified by the regulations. Explanation. For the removal of doubts, it is hereby declared that the subscriber shall be liable till he has informed the Certifying Authority that the private key has been compromised. |
Figure 3: Compromise, report and the liability line
- Duty to exercise reasonable care. The standard is reasonable care, not insurance: keep the token safe, protect the PIN, never share the key, and take all steps to prevent disclosure. Handing the token and PIN to an accountant for routine filings is the classic breach.
- Compromise of the private key. Anything that puts the key within another's reach: a lost or stolen token, a leaked PIN, malware that copies the key, or an OTP read out to a caller in the eSign setting.
- Duty to notify the Certifying Authority. The report must go to the CA without any delay, in the manner the regulations specify. The CA then suspends or revokes the certificate (ss.37, 38) and publishes notice (s.39), which is what warns the world.
- Liability for failure to protect. The Explanation draws the line in time: for misuse of the key before the CA is informed, the subscriber is liable; after notice, reliance on the certificate is at the relying party's risk. The rule mirrors the RBI's approach to unauthorised bank transactions, where delay in reporting shifts the loss to the customer.
- Litigation angle. In a dispute over a signature the subscriber says he never made, his own conduct under s.42 is usually decisive: prompt reporting supports him, silence sinks him, and criminal liability of the misuser under s.66C runs in parallel (see Topic 42)
7. Subscriber vs Certifying Authority
Figure 4: The division of responsibility
- Two sets of promises. The CA promises a sound process (s.36); the subscriber promises true facts and a guarded key (ss.41, 42). Each set protects the relying party from a different failure.
- Two disciplines. The CA answers to the Controller, through audits, directions and the licence (Topics 49 and 50); the subscriber answers in money, through the liability rule, and in the fate of his certificate.
⚠ Exam trap Do not write that the Certifying Authority generates or keeps the subscriber's private key: the subscriber generates the pair (s.40) and only he holds the private key; the CA certifies the public key. And place the liability line exactly where the Explanation puts it: the subscriber is liable until he informs the CA of the compromise, not until the CA revokes or publishes notice. |
8. Quick Revision and Memory Aids
- 'The man who holds the stamp'. The subscriber's position.
- '40 generates, 40A prescribes, 41 promises, 42 guards'. Chapter VIII in one line.
- 'Publish, authorise, approve'. Modes of acceptance under s.41(1)
- 'Hold, told, true'. The three certifications of s.41(2)
- 'Reasonable care, no delay'. The two duties of s.42.
- 'Liable till you tell'. The Explanation to s.42.
9. Frequently Asked Questions
What does a subscriber certify by accepting a Digital Signature Certificate?
That he holds and is entitled to hold the private key corresponding to the listed public key, that all representations he made to the Certifying Authority and all material relevant to the certificate's information are true, and that all information in the certificate within his knowledge is true (Section 41(2)).
What happens if a subscriber's private key is compromised?
He must communicate the compromise to the Certifying Authority without any delay in the specified manner (Section 42(2)). Under the Explanation, he remains liable for misuse until he has informed the CA; the CA then suspends or revokes the certificate and publishes notice under Section 39.
10. Related Topics
- Topic 51: Electronic Signature Certificates. The certificate the subscriber accepts.
- Topic 42: Validity, Forgery and Misuse. Disputed signatures and stolen keys in court.