All NotesCivil LawInformation Technology Act, 2000

Information Technology Act, 2000

Electronic Signature Certificates: Sections 35 to 39 IT Act

The certificate is the passport of the electronic signature system: it ties a named subscriber to a public key, on the word of a licensed Certifying Authority. Chapter VII follows that passport through its life. Section 35 governs how it is applied for and issued, Section 36 lists what the CA is taken to promise the world when it issues one, Sections 37 and 38 govern its suspension and revocation, and Section 39 makes sure the world finds out. This note covers each section, the difference between an Electronic Signature Certificate and a Digital Signature Certificate, the three ways a certificate can stop working, and what a relying party must check before trusting one.

1. A Passport for a Public Key

A passport is issued after verification, carries the issuing authority's guarantee of the particulars inside, can be impounded temporarily or cancelled outright, and both events are recorded where border officers can check. Replace the photograph with a public key, the passport office with a licensed Certifying Authority, and the border check with signature verification, and you have Chapter VII. The one difference: a certificate exists mainly for strangers, the relying parties who will trust a signature because the certificate vouches for it.

The life of an Electronic Signature Certificate

Figure 1: The life of an Electronic Signature Certificate

2. Section 35: Issue of the Certificate

Section 35, Information Technology Act, 2000 (substance)

(1) Any person may make an application to the Certifying Authority for the issue of an Electronic Signature Certificate in such form as may be prescribed by the Central Government.

(2) Every such application shall be accompanied by such fee not exceeding twenty-five thousand rupees as may be prescribed, to be paid to the Certifying Authority; different fees may be prescribed for different classes of applicants.

(3) Every such application shall be accompanied by a certification practice statement or, where there is no such statement, a statement containing such particulars as may be specified by regulations.

(4) On receipt of an application, the Certifying Authority may, after consideration of the certification practice statement or the other statement and after making such enquiries as it may deem fit, grant the Electronic Signature Certificate or, for reasons to be recorded in writing, reject the application: Provided that no application shall be rejected unless the applicant has been given a reasonable opportunity of showing cause against the proposed rejection.

  • Application for the certificate. In the prescribed form, with a fee of up to ₹25,000 as prescribed (different fees for different classes), and accompanied by the CPS or a statement of specified particulars. Form C is the application in the Certifying Authorities Rules; for eSign, the application and consent are electronic (see Topic 41)
  • Verification of the applicant. The CA makes the enquiries it deems fit before granting: identity and address verification under the CCA's Identity Verification Guidelines, ranging from in-person and video verification to Aadhaar or other e-KYC. Weak verification breaks the whole chain, which is why the guidelines are detailed.
  • Grant of the certificate. On satisfaction, the CA grants the certificate, publishes it or makes it available to relying persons, and the subscriber's acceptance triggers his own duties under Chapter VIII.
  • Rejection of the application. Only for reasons recorded in writing and after a reasonable opportunity of showing cause, mirroring the licence-stage hearing under Section 24.
  • A 2008 tidy-up. The original second proviso, which required the CA to be satisfied that the applicant held the private key corresponding to the public key and that the key pair functioned together, was omitted in 2008; the same assurances now live in the representations under Section 36 and the technical standards.

3. Section 36: Representations upon Issuance

What the Certifying Authority certifies by issuing

Figure 2: What the Certifying Authority certifies by issuing

  • The rule. By issuing an Electronic Signature Certificate, the CA certifies to the world the matters in Section 36: compliance, publication, the subscriber's key pair, accuracy and completeness.
  • Compliance and publication. That it has complied with the Act, rules and regulations in issuing the certificate, and that it has published the certificate or otherwise made it available to any person relying on it, the subscriber having accepted it.
  • Accuracy of information. That the information contained in the certificate is accurate, and that all information foreseeably material to its reliability is either in the certificate or incorporated by reference.
  • Subscriber's control of signature creation data. That the subscriber holds the private key corresponding to the public key listed in the certificate, and, in the clauses added in 2008, that the private key is capable of creating a digital signature and that the listed public key can verify a signature so created. The subscriber's exclusive control of that key is also what Section 15 demands for secure status and what Section 42 obliges the subscriber to maintain.
  • No material omission. That it has no knowledge of any material fact which, if included, would adversely affect the reliability of these representations.
  • Why it matters. Section 36 is the legal hook for a relying party misled by a bad certificate: the statements are the CA's own, and a negligent issue can ground liability and regulatory action, alongside the Section 87 BSA presumption that the information in a certificate is correct.

4. Sections 37 and 38: Suspension and Revocation

Suspension and revocation compared

Figure 3: Suspension and revocation compared

  • Suspension (s.37). The CA may suspend a certificate on receipt of a request from the subscriber or a person authorised to act on his behalf, or if it is of the opinion that suspension is in the public interest. A certificate may not be suspended for more than fifteen days unless the subscriber has been given an opportunity of being heard, and the suspension must be communicated to the subscriber.
  • Revocation on request or event (s.38(1)). The CA may revoke a certificate where the subscriber or a person authorised by him requests it, on the death of the subscriber, or on the dissolution of the firm or winding up of the company where the subscriber is a firm or a company.
  • Revocation for cause (s.38(2)). Subject to a hearing, the CA may revoke a certificate if a material fact represented in it is false or has been concealed, a requirement for its issue was not satisfied, the CA's own private key or security system was compromised in a manner materially affecting the certificate's reliability, or the subscriber has been declared insolvent or dead (or the firm or company dissolved or wound up)
  • Hearing and communication. A certificate may not be revoked for cause unless the subscriber has been given an opportunity of being heard, and the revocation must be communicated to him.
  • Compromise of the private key. The subscriber-side trigger: under Section 42(2) the subscriber must report a compromise to the CA without delay and remains liable until he does; the CA then suspends or revokes and publishes notice, after which the loss of later misuse shifts away from him (see Topic 42)

Notice under Section 39

Figure 4: Notice under Section 39

  • Notice of suspension or revocation (s.39). On suspension or revocation, the CA must publish a notice of it in the repository specified in the certificate for the publication of such notices; where more than one repository is specified, the notice goes into all of them. In PKI practice this is the certificate revocation list and the online status service that relying software checks.

5. The Comparisons

Electronic and Digital Signature Certificates

Figure 5: Electronic and Digital Signature Certificates

  • Electronic vs Digital Signature Certificate. A Digital Signature Certificate (s.2(1)(q)) certifies the key pair of a digital signature under Section 3. The 2008 Amendment introduced the wider Electronic Signature Certificate (s.2(1)(tb)), which certifies any recognised technique and includes a Digital Signature Certificate. Every DSC is an ESC; an eSign certificate is an ESC that is also, technically, a DSC because eSign uses asymmetric cryptography.

Expired, suspended and revoked certificates

Figure 6: Expired, suspended and revoked certificates

  • Expired. The validity period simply ran out. No order or hearing is involved. Signatures affixed while the certificate was valid remain verifiable (long-term validation preserves them, see Topic 41); new signatures need a fresh certificate.
  • Suspended. A temporary freeze under Section 37, capped at fifteen days without a hearing. Signatures purportedly created during suspension are not to be relied on, but the certificate can return to life.
  • Revoked. A permanent end under Section 38. The certificate never revives; the subscriber must obtain a new one, and relying parties are fixed with the notice published under Section 39.

6. Reliance on a Certificate

What a relying party checks

Figure 7: What a relying party checks

  • The checks. Verify the signature against the certificate's public key, confirm the certificate's validity period covers the signing, check the repository, CRL or online status for suspension or revocation, and trace the chain through the licensed CA to the Controller's root. Signing software runs these checks automatically.
  • The legal backing. The CA's Section 36 representations, the Section 87 BSA presumption that the certificate's information is correct, and, for secure signatures, the Section 86 BSA presumptions (see Topic 48)
  • The limit. Reliance in the face of a published Section 39 notice is at the relying party's own risk, exactly as a border officer cannot plead ignorance of a cancelled passport on the watch list.

⚠ Exam trap

Two favourites. First, do not mix the hearing clocks: a subscriber's certificate may be suspended beyond fifteen days only after a hearing (s.37), while a CA's licence may be suspended beyond ten days only after one (s.25). Secondly, death of the subscriber and dissolution of the firm or company are revocation grounds, not suspension grounds, and revocation for cause always needs a prior hearing, but revocation on the subscriber's own request or on death does not.

7. Quick Revision and Memory Aids

  • 'A passport for a public key'. What a certificate is.
  • '35 issues, 36 promises, 37 freezes, 38 kills, 39 tells'. Chapter VII in one line.
  • 'Compliance, publication, key pair, accuracy, no omission'. The s.36 representations.
  • 'Request, public interest; fifteen days'. Suspension under s.37.
  • 'Request, death, dissolution; false, unsatisfied, compromised'. Revocation under s.38.
  • 'Expired fades, suspended sleeps, revoked dies'. The three endings.

8. Frequently Asked Questions

On what grounds can an Electronic Signature Certificate be revoked?

Under Section 38: on the request of the subscriber or his authorised person, on his death, or on the dissolution of the firm or winding up of the company; and, after a hearing, where a material fact in the certificate is false or concealed, a requirement of issue was unsatisfied, the CA's private key or security system was compromised so as to affect the certificate's reliability, or the subscriber is declared insolvent or dead.

9. Related Topics

  • Topic 50: Licensing of Certifying Authorities. The issuers of these certificates.
  • Topic 42: Validity, Forgery and Misuse. Compromise, liability and proof in court.