(a) The identity of the authentication service provider (b) That the signatory in the meantime is controlling the signature originating tools mentioned in the certificate. (c) The signature originating tool was valid and true at the date of issuing the certificate. (d) Any restriction on the scope or extent and value within which the certificate may be used. (e) Any restrictions on the scope or the extent of the responsibility that the authentication service provider shall accept toward any person. (f) Any other informations to be determined by the competent authority. Article (34) The authentication service provider shall have obtained the license from the competent authority and shall be obliged to: (a) Act in accordance with the data provided by him in respect of his practices. (b) Verify the accuracy and completeness of all material data contained in the certificate throughout the duration of its validity. (c) Provide reasonably accessible means that enable the party who relies on his services to ascertain of: (1) The identity of the authentication service provider. (2) That the identified person in the certificate has control in the meantime over the signature originating tool mentioned in the certificate. (3) The method used in identifying the signatory (4) The existence of any restrictions on the purpose or value that the signature originating tool will be used for. (5) The validity of the signature originating tool and that it has not been subject to suspicions. (6) The appropriate mean for notifying revocation. (d) Provide a mean for the signatory to enable him in giving notice in case the signature originating tool is misused and should ensure the availability of a service for revocation of the signature to be used in the appropriate time. (e) Using trustworthy systems, procedures and human resources in the performance of his services while taking into consideration the following factors: (1) The financial and human resources. (2) Trustworthy hardware and software. (3) The procedure for obtaining certificates and applications for such certificates and retention of records. (4) Providing informations related to signatories identified in the certificates and render informations to parties who probably rely on the authentication services. Article (35) (1) If damage occurs due to inaccuracy of the certificate or because it is defective due to error or negligence committed by the authentication service provider, then he will be held responsible for that damage ensued whether to the party who contracted with him to give him the certificate or any person who reasonably relies on the certificate. (2) The authentication service provider shall not be responsible for any damage if he proves that he didn’t commit any mistake or negligence or that the damage ensued for a reason out of his control. 12

Select target paragraph3