(a) The identity of the authentication service provider
(b) That the signatory in the meantime is controlling the signature originating tools
mentioned in the certificate.
(c) The signature originating tool was valid and true at the date of issuing the certificate.
(d) Any restriction on the scope or extent and value within which the certificate may be
used.
(e) Any restrictions on the scope or the extent of the responsibility that the authentication
service provider shall accept toward any person.
(f) Any other informations to be determined by the competent authority.
Article (34)
The authentication service provider shall have obtained the license from the competent
authority and shall be obliged to:
(a) Act in accordance with the data provided by him in respect of his practices.
(b) Verify the accuracy and completeness of all material data contained in the certificate
throughout the duration of its validity.
(c) Provide reasonably accessible means that enable the party who relies on his services to
ascertain of:
(1) The identity of the authentication service provider.
(2) That the identified person in the certificate has control in the meantime over
the signature originating tool mentioned in the certificate.
(3) The method used in identifying the signatory
(4) The existence of any restrictions on the purpose or value that the signature
originating tool will be used for.
(5) The validity of the signature originating tool and that it has not been subject to
suspicions.
(6) The appropriate mean for notifying revocation.
(d) Provide a mean for the signatory to enable him in giving notice in case the signature
originating tool is misused and should ensure the availability of a service for
revocation of the signature to be used in the appropriate time.
(e) Using trustworthy systems, procedures and human resources in the performance of his
services while taking into consideration the following factors:
(1) The financial and human resources.
(2) Trustworthy hardware and software.
(3) The procedure for obtaining certificates and applications for such certificates
and retention of records.
(4) Providing informations related to signatories identified in the certificates and
render informations to parties who probably rely on the authentication
services.
Article (35)
(1) If damage occurs due to inaccuracy of the certificate or because it is defective due to
error or negligence committed by the authentication service provider, then he will
be held responsible for that damage ensued whether to the party who contracted
with him to give him the certificate or any person who reasonably relies on the
certificate.
(2) The authentication service provider shall not be responsible for any damage if he
proves that he didn’t commit any mistake or negligence or that the damage ensued
for a reason out of his control.
12