Information Technology Law
Subjects / Information Technology Law / Certifying Authorities and Regulators
Unit 2 · Unit 2

Certifying Authorities and Regulators

The IT Act establishes a hierarchical regulatory framework for digital signature infrastructure.

The IT Act establishes a hierarchical regulatory framework for digital signature infrastructure. The Controller of Certifying Authorities (CCA) supervises Certifying Authorities (CAs) who issue Digital Signature Certificates (DSCs) to subscribers. This Public Key Infrastructure (PKI) is the backbone of electronic authentication in India.

Legal Framework

Provision Subject
S.17 Appointment of Controller of Certifying Authorities (CCA)
S.18 Functions of CCA
S.19 Recognition of foreign Certifying Authorities
S.20 Controller to act as repository (public directory of CAs and certificates)
S.21 License to issue DSCs
S.22 Application for license
S.23 Renewal of license
S.24 Procedure for grant or rejection
S.25 Suspension of license
S.26 Notice of suspension/revocation
S.27 Power to delegate
S.28 Power to investigate contraventions
S.29 Access to computers and data
S.30 Certifying Authority to follow certain procedures
S.30A CA to ensure compliance of subscriber
S.34 Disclosure by Certifying Authority
S.35 CA to issue DSC
S.36 Representations upon issuance
S.37 Suspension of DSC
S.38 Revocation of DSC
S.39 Notice of suspension/revocation to subscriber

Controller of Certifying Authorities (CCA)

Aspect Details
Appointed by Central Government (S.17)
Functions (S.18) Supervise CAs; certify public keys of CAs; lay standards; specify qualifications for CA employees; specify form/content of DSC; facilitate cross-certification
Repository function (S.20) Maintains electronic database of all issued certificates and public keys
Investigative power (S.28) Investigate whether CA is complying with IT Act provisions
Delegation (S.27) May delegate powers to Deputy Controllers / Assistant Controllers
Website cca.gov.in

Why: A central controller is necessary to ensure uniformity of standards, prevent fraud in certificate issuance, and maintain a public repository where any person can verify a certificate's authenticity.

Certifying Authorities (CAs)

License Requirements (S.21-24)

Requirement Provision
Must hold license from CCA S.21
Application with prescribed fees S.22
Must have adequate infrastructure, security, and human resources S.24(2)
License valid for prescribed period; renewable S.23
CCA may suspend license for contravention S.25

Duties of Certifying Authority

Duty Section
Follow prescribed procedures and standards S.30
Ensure subscriber compliance with IT Act S.30A
Use hardware, software, procedures conforming to prescribed standards S.30
Issue DSC on receiving application from subscriber S.35
Publish DSC (with subscriber consent) in repository S.35(3)
Suspend DSC on CCA direction or subscriber request S.37
Revoke DSC on specified grounds S.38
Disclose license, DSC, and certification practice statement S.34

Grounds for Revocation of DSC (S.38)

  1. Subscriber made material misrepresentation in application
  2. Fact in certificate is false
  3. Failure to comply with S.42 conditions (subscriber duties)
  4. DSC issued to subscriber by a CA whose license has been suspended/revoked
  5. CA compromised or is no longer trustworthy

Digital Signature Certificate (DSC) Contents (S.35, Rule 9)

Field Content
Serial number Unique identifier
Identity of subscriber Name, address, designation
Public key Subscriber's public key
Validity period Start and expiry dates
Identity of CA CA name, DSC number
Digital signature of CA CA signs the certificate
Algorithm Hash and signature algorithm used

Regulatory Hierarchy

%%{init: {"theme": "base", "themeVariables": {"primaryColor": "#fef9c3", "primaryBorderColor": "#1a1a1a", "primaryTextColor": "#1a1a1a", "secondaryColor": "#fde047", "secondaryBorderColor": "#1a1a1a", "lineColor": "#1a1a1a", "textColor": "#1a1a1a", "fontSize": "14px", "fontFamily": "Space Grotesk, DM Sans, system-ui, sans-serif", "nodeBorder": "2px", "mainBkg": "#fef9c3", "edgeLabelBackground": "#FFFDF7"}}}%%
flowchart TD
    A(["fa:fa-shield Central Government"]):::start --> B["fa:fa-users Appoints CCA (S.17)"]:::process
    B --> C["fa:fa-gavel CCA supervises, licenses, investigates"]:::process
    C --> D["fa:fa-building Licensed CAs (S.21)"]:::process
    D --> E["fa:fa-file-text Issue DSCs to Subscribers (S.35)"]:::document
    E --> F["fa:fa-users Subscribers use DSCs"]:::process
    F --> G{"fa:fa-question Private key compromised?"}:::decision
    G -->|Yes| H["fa:fa-exclamation-triangle Notify CA (S.42)"]:::warning
    G -->|No| I(("fa:fa-check Valid authentication")):::success
    H --> J["fa:fa-times CA suspends/revokes DSC (S.37/38)"]:::failure

    classDef start fill:#d1fae5,stroke:#1a1a1a,stroke-width:2px,color:#1a1a1a
    classDef process fill:#fef9c3,stroke:#1a1a1a,stroke-width:2px,color:#1a1a1a
    classDef decision fill:#fde047,stroke:#1a1a1a,stroke-width:2px,color:#1a1a1a
    classDef success fill:#86efac,stroke:#1a1a1a,stroke-width:2px,color:#1a1a1a
    classDef failure fill:#fecaca,stroke:#1a1a1a,stroke-width:2px,color:#1a1a1a
    classDef document fill:#dbeafe,stroke:#1a1a1a,stroke-width:2px,color:#1a1a1a
    classDef warning fill:#fed7aa,stroke:#1a1a1a,stroke-width:2px,color:#1a1a1a

Recall Check

  1. Who appoints the Controller of Certifying Authorities and under which section?
  2. Name any three grounds for revocation of a DSC under S.38.
  3. What is the repository function of the CCA?

Key Cases

No landmark judicial decisions specifically adjudicate CCA/CA regulatory issues. The framework is primarily administrative. If challenged, courts apply Wednesbury reasonableness to CCA's licensing decisions and S.28 investigative actions.

Distinctions

Aspect Controller (CCA) Certifying Authority (CA)
Appointment Central Government (S.17) Licensed by CCA (S.21)
Function Supervisory, policy, standards Operational (issues DSCs)
Power Investigate, suspend CA license, certify CA's public key Issue, suspend, revoke individual DSCs
Accountability Reports to Central Government Accountable to CCA
Number One (single national controller) Multiple (private and government CAs)
Example CCA office at cca.gov.in eMudhra, Sify, NIC CA, CDAC

Flashcards

Q: Who is the CCA appointed by? A: Central Government under S.17 IT Act.

Q: What are the main functions of CCA (S.18)? A: Supervise CAs; certify public keys of CAs; lay down standards; specify qualifications and conditions for CA employees; specify form and content of DSC; facilitate cross-certification.

Q: Name any four licensed CAs in India. A: eMudhra, Sify Technologies, (n)Code Solutions, CDAC, NIC CA.

Q: What is the repository function (S.20)? A: CCA maintains an electronic repository of all issued DSCs and public keys as a public directory, accessible for verification.

Q: What happens if a CA's license is suspended? A: All DSCs issued by that CA are automatically affected; subscribers must be notified (S.26); DSCs may be revoked under S.38(4).

Q: Under which section can the CCA investigate a Certifying Authority? A: S.28: power to investigate contraventions by CA.

Q: What must a CA disclose under S.34? A: Its license, DSC, and certification practice statement (document describing policies and procedures).

Exam Scenario

A Certifying Authority issues a DSC to a person who has provided a false identity. Using this DSC, the person enters into a high-value electronic contract with a company. When the fraud is discovered, the company seeks compensation. Discuss the liability of the CA and the subscriber.

The CA has a duty under S.30 to follow prescribed procedures including identity verification before issuing a DSC. If the CA failed to exercise due diligence in verifying identity (as prescribed under IT Certifying Authorities Rules), it is liable for loss caused to any person relying on the certificate (S.36: representations upon issuance). The subscriber committed fraud and is criminally liable under S.71 (misrepresentation to CA) and BNS provisions for cheating. The DSC should be revoked under S.38(2) (material misrepresentation in application). The company can claim compensation from: (1) the fraudulent subscriber (primary liability), (2) the CA (if negligence in verification is proved). The CCA may suspend the CA's license under S.25 for failure to comply with procedures.