The Information Technology Act, 2000
CHAPTER VII: ELECTRONIC SIGNATURE CERTIFICATES
Section 36: Representations Upon Issuance Of Digital Signature Certificate
Bare Act
A Certifying Authority while issuing a Digital Signature Certificate shall certify that -
- it has complied with the provisions of this Act and the rules and regulations made thereunder;
- it has published the Digital Signature Certificate or otherwise made it available to such person relying on it and the subscriber has accepted it;
- the subscriber holds the private key corresponding to the public key, listed in the Digital Signature Certificate;
-
the subscriber holds a private key which is capable of creating a digital signature;
- the public key to be listed in the certificate can be used to verify a digital signature affixed by the private key held by the subscriber;
- the subscriber's public key and private key constitute a functioning key pair;
- the information contained in the Digital Signature Certificate is accurate; and
- it has no knowledge of any material fact, which if it had been included in the Digital Signature Certificate would adversely affect the reliability of the representations in clauses (a) to (d).
Simplified Act
When a Certifying Authority gives out a Digital Signature Certificate, it confirms that:
- it has followed all the rules and regulations of the Information Technology Act;
- it has made the certificate available to the people who need to trust it, and the person who the certificate is for has agreed to it;
- the person the certificate is for, known as the subscriber, has the secret code (private key) that matches the public code (public key) on the certificate;
- the subsc… Read the complete text with KanoonGPT Pro.
Explanation using examples
Let's say John is a software developer who needs a Digital Signature Certificate (DSC) to authenticate his identity online. He approaches a Certifying Authority (CA) for the DSC. The CA, while issuing the DSC, ensures that:
- It has followed all the rules of the Information Technology Act, 2000 during the process;
- It has made the DSC available to John and any other person who might rely on it, and John has accepted it;
- John holds the private key that matches the public key listed in the DSC;
- John's private key can create a digital signature, and the public key listed in the certificate can verify a digital signature made by John's private key;
- John's public and private keys work together as a functioning key pair;
- All the information in the DSC, such as John's name, email, and country, is accurate;
- There is no crucial fact that, if it had been included in the DSC, would have made the representations in the DSC unreliable.
Only after these checks and verifications, the CA issues the DSC to John.

