(2) Where one or more repositories are specified, the Certifying Authority shall publish notices of
such suspension or revocation, as the case may be, in all such repositories.
CHAPTER VIII
DUTIES OF SUBSCRIBERS
40. Generating key pair.–Where any Digital Signature Certificate the public key of which
corresponds to the private key of that subscriber which is to be listed in the Digital Signature Certificate
has been accepted by a subscriber, 1*** the subscriber shall generate 2[that key] pair by applying the
security procedure.
3
[40A. Duties of subscriber of Electronic Signature Certificate.–In respect of Electronic Signature
Certificate the subscriber shall perform such duties as may be prescribed.]
41. Acceptance of Digital Signature Certificate.–(1) A subscriber shall be deemed to have accepted
a Digital Signature Certificate if he publishes or authorises the publication of a Digital Signature
Certificate–
(a) to one or more persons;
(b) in a repository; or
otherwise demonstrates his approval of the Digital Signature Certificate in any manner.
(2) By accepting a Digital Signature Certificate the subscriber certifies to all who reasonably rely on
the information contained in the Digital Signature Certificate that–
(a) the subscriber holds the private key corresponding to the public key listed in the Digital
Signature Certificate and is entitled to hold the same;
(b) all representations made by the subscriber to the Certifying Authority and all material relevant
to the information contained in the Digital Signature Certificate are true;
(c) all information in the Digital Signature Certificate that is within the knowledge of the
subscriber is true.
42. Control of private key.–(1) Every subscriber shall exercise reasonable care to retain control of
the private key corresponding to the public key listed in his Digital Signature Certificate and take all steps
to prevent its disclosure 4***.
(2) If the private key corresponding to the public key listed in the Digital Signature Certificate has
been compromised, then, the subscriber shall communicate the same without any delay to the Certifying
Authority in such manner as may be specified by the regulations.
Explanation.–For the removal of doubts, it is hereby declared that the subscriber shall be liable till he
has informed the Certifying Authority that the private key has been compromised.
CHAPTER IX
5
[PENALTIES, COMPENSATION AND ADJUDICATION]
6
43. [Penalty and compensation] for damage to computer, computer system, etc.–If any person
without permission of the owner or any other person who is in charge of a computer, computer system or
computer network,–
(a) accesses or secures access to such computer, computer system or computer network
[or computer resource];
7
1. The word “then” omitted by notification No. S.O. 1015(E) (w.e.f. 19-9-2002).
2. Subs. ibid., for “the key” (w.e.f. 19-9-2002).
3. Ins. by Act 10 of 2009, s. 19 (w.e.f. 27-10-2009).
4. The words “to a person not authorised to affix the digital signature of the subscriber” omitted by notification No. S.O.1015(E)
(w.e.f. 19-9-2002).
5. Subs. by Act 10 of 2009, s. 20, for “PENALTIES AND ADJUDICATION” (w.e.f. 27-10-2009).
6. Subs. by s. 21, ibid., for “Penalty” (w.e.f. 27-10-2009).
7. Ins. by s. 21, ibid. (w.e.f. 27-10-2009).
18