The IT Act establishes a hierarchical regulatory framework for digital signature infrastructure. The Controller of Certifying Authorities (CCA) supervises Certifying Authorities (CAs) who issue Digital Signature Certificates (DSCs) to subscribers. This Public Key Infrastructure (PKI) is the backbone of electronic authentication in India.
Legal Framework
| Provision | Subject |
|---|---|
| S.17 | Appointment of Controller of Certifying Authorities (CCA) |
| S.18 | Functions of CCA |
| S.19 | Recognition of foreign Certifying Authorities |
| S.20 | Controller to act as repository (public directory of CAs and certificates) |
| S.21 | License to issue DSCs |
| S.22 | Application for license |
| S.23 | Renewal of license |
| S.24 | Procedure for grant or rejection |
| S.25 | Suspension of license |
| S.26 | Notice of suspension/revocation |
| S.27 | Power to delegate |
| S.28 | Power to investigate contraventions |
| S.29 | Access to computers and data |
| S.30 | Certifying Authority to follow certain procedures |
| S.30A | CA to ensure compliance of subscriber |
| S.34 | Disclosure by Certifying Authority |
| S.35 | CA to issue DSC |
| S.36 | Representations upon issuance |
| S.37 | Suspension of DSC |
| S.38 | Revocation of DSC |
| S.39 | Notice of suspension/revocation to subscriber |
Controller of Certifying Authorities (CCA)
| Aspect | Details |
|---|---|
| Appointed by | Central Government (S.17) |
| Functions (S.18) | Supervise CAs; certify public keys of CAs; lay standards; specify qualifications for CA employees; specify form/content of DSC; facilitate cross-certification |
| Repository function (S.20) | Maintains electronic database of all issued certificates and public keys |
| Investigative power (S.28) | Investigate whether CA is complying with IT Act provisions |
| Delegation (S.27) | May delegate powers to Deputy Controllers / Assistant Controllers |
| Website | cca.gov.in |
Why: A central controller is necessary to ensure uniformity of standards, prevent fraud in certificate issuance, and maintain a public repository where any person can verify a certificate's authenticity.
Certifying Authorities (CAs)
License Requirements (S.21-24)
| Requirement | Provision |
|---|---|
| Must hold license from CCA | S.21 |
| Application with prescribed fees | S.22 |
| Must have adequate infrastructure, security, and human resources | S.24(2) |
| License valid for prescribed period; renewable | S.23 |
| CCA may suspend license for contravention | S.25 |
Duties of Certifying Authority
| Duty | Section |
|---|---|
| Follow prescribed procedures and standards | S.30 |
| Ensure subscriber compliance with IT Act | S.30A |
| Use hardware, software, procedures conforming to prescribed standards | S.30 |
| Issue DSC on receiving application from subscriber | S.35 |
| Publish DSC (with subscriber consent) in repository | S.35(3) |
| Suspend DSC on CCA direction or subscriber request | S.37 |
| Revoke DSC on specified grounds | S.38 |
| Disclose license, DSC, and certification practice statement | S.34 |
Grounds for Revocation of DSC (S.38)
- Subscriber made material misrepresentation in application
- Fact in certificate is false
- Failure to comply with S.42 conditions (subscriber duties)
- DSC issued to subscriber by a CA whose license has been suspended/revoked
- CA compromised or is no longer trustworthy
Digital Signature Certificate (DSC) Contents (S.35, Rule 9)
| Field | Content |
|---|---|
| Serial number | Unique identifier |
| Identity of subscriber | Name, address, designation |
| Public key | Subscriber's public key |
| Validity period | Start and expiry dates |
| Identity of CA | CA name, DSC number |
| Digital signature of CA | CA signs the certificate |
| Algorithm | Hash and signature algorithm used |
Regulatory Hierarchy
%%{init: {"theme": "base", "themeVariables": {"primaryColor": "#fef9c3", "primaryBorderColor": "#1a1a1a", "primaryTextColor": "#1a1a1a", "secondaryColor": "#fde047", "secondaryBorderColor": "#1a1a1a", "lineColor": "#1a1a1a", "textColor": "#1a1a1a", "fontSize": "14px", "fontFamily": "Space Grotesk, DM Sans, system-ui, sans-serif", "nodeBorder": "2px", "mainBkg": "#fef9c3", "edgeLabelBackground": "#FFFDF7"}}}%%
flowchart TD
A(["fa:fa-shield Central Government"]):::start --> B["fa:fa-users Appoints CCA (S.17)"]:::process
B --> C["fa:fa-gavel CCA supervises, licenses, investigates"]:::process
C --> D["fa:fa-building Licensed CAs (S.21)"]:::process
D --> E["fa:fa-file-text Issue DSCs to Subscribers (S.35)"]:::document
E --> F["fa:fa-users Subscribers use DSCs"]:::process
F --> G{"fa:fa-question Private key compromised?"}:::decision
G -->|Yes| H["fa:fa-exclamation-triangle Notify CA (S.42)"]:::warning
G -->|No| I(("fa:fa-check Valid authentication")):::success
H --> J["fa:fa-times CA suspends/revokes DSC (S.37/38)"]:::failure
classDef start fill:#d1fae5,stroke:#1a1a1a,stroke-width:2px,color:#1a1a1a
classDef process fill:#fef9c3,stroke:#1a1a1a,stroke-width:2px,color:#1a1a1a
classDef decision fill:#fde047,stroke:#1a1a1a,stroke-width:2px,color:#1a1a1a
classDef success fill:#86efac,stroke:#1a1a1a,stroke-width:2px,color:#1a1a1a
classDef failure fill:#fecaca,stroke:#1a1a1a,stroke-width:2px,color:#1a1a1a
classDef document fill:#dbeafe,stroke:#1a1a1a,stroke-width:2px,color:#1a1a1a
classDef warning fill:#fed7aa,stroke:#1a1a1a,stroke-width:2px,color:#1a1a1a
Recall Check
- Who appoints the Controller of Certifying Authorities and under which section?
- Name any three grounds for revocation of a DSC under S.38.
- What is the repository function of the CCA?
Key Cases
No landmark judicial decisions specifically adjudicate CCA/CA regulatory issues. The framework is primarily administrative. If challenged, courts apply Wednesbury reasonableness to CCA's licensing decisions and S.28 investigative actions.
Distinctions
| Aspect | Controller (CCA) | Certifying Authority (CA) |
|---|---|---|
| Appointment | Central Government (S.17) | Licensed by CCA (S.21) |
| Function | Supervisory, policy, standards | Operational (issues DSCs) |
| Power | Investigate, suspend CA license, certify CA's public key | Issue, suspend, revoke individual DSCs |
| Accountability | Reports to Central Government | Accountable to CCA |
| Number | One (single national controller) | Multiple (private and government CAs) |
| Example | CCA office at cca.gov.in | eMudhra, Sify, NIC CA, CDAC |
Flashcards
Q: Who is the CCA appointed by? A: Central Government under S.17 IT Act.
Q: What are the main functions of CCA (S.18)? A: Supervise CAs; certify public keys of CAs; lay down standards; specify qualifications and conditions for CA employees; specify form and content of DSC; facilitate cross-certification.
Q: Name any four licensed CAs in India. A: eMudhra, Sify Technologies, (n)Code Solutions, CDAC, NIC CA.
Q: What is the repository function (S.20)? A: CCA maintains an electronic repository of all issued DSCs and public keys as a public directory, accessible for verification.
Q: What happens if a CA's license is suspended? A: All DSCs issued by that CA are automatically affected; subscribers must be notified (S.26); DSCs may be revoked under S.38(4).
Q: Under which section can the CCA investigate a Certifying Authority? A: S.28: power to investigate contraventions by CA.
Q: What must a CA disclose under S.34? A: Its license, DSC, and certification practice statement (document describing policies and procedures).
Exam Scenario
A Certifying Authority issues a DSC to a person who has provided a false identity. Using this DSC, the person enters into a high-value electronic contract with a company. When the fraud is discovered, the company seeks compensation. Discuss the liability of the CA and the subscriber.
The CA has a duty under S.30 to follow prescribed procedures including identity verification before issuing a DSC. If the CA failed to exercise due diligence in verifying identity (as prescribed under IT Certifying Authorities Rules), it is liable for loss caused to any person relying on the certificate (S.36: representations upon issuance). The subscriber committed fraud and is criminally liable under S.71 (misrepresentation to CA) and BNS provisions for cheating. The DSC should be revoked under S.38(2) (material misrepresentation in application). The company can claim compensation from: (1) the fraudulent subscriber (primary liability), (2) the CA (if negligence in verification is proved). The CCA may suspend the CA's license under S.25 for failure to comply with procedures.