munotes®

Registering and Using the Certificate

Get access to whole semester resourcesSemester Pass

Chapter Seven

Syllabus topic 2, "Application and Registration procedure of Digital Signature."

Pages 13 to 14 of 80

The certificate is issued once and registered many times

Obtaining the certificate is one act. Using it means registering it separately on every portal it will be used on, and each portal has its own step. That is the half of MU's topic that a book about the application alone would miss.

Registering it on the portals

PortalWhere the registration is doneWhat it is then used for
Income-tax e-filingRegister DSC under the profile, after installing the emSigner utilitySigning the return, the tax audit report, forms and responses
GSTRegister DSC against the authorised signatory, after installing the emSigner utilityThe registration application, returns, refund applications
MCA, for a company or an LLPAssociate DSC with the DIN or the membership numberEvery filing with the Registrar of Companies
e-Tendering portalsEnrol the certificate against the bidder profileBid submission and bid opening
EPFO and ESICRegister the employer's DSC against the establishmentDigital approval of claims and transfers
Directorate General of Foreign TradeRegister against the Importer Exporter CodeLicence applications

The pattern is the same on all of them: install the utility, plug in the token, select the certificate, and the portal binds it to the PAN or to the user account. The bind is to a PAN, which is why the name on the certificate must match the PAN exactly.

The token, and the rule about it

The private key is generated inside a USB cryptographic token and cannot be exported from it. That is a feature and not an inconvenience: it is what makes non-repudiation mean anything.

Section 42 of the Information Technology Act 2000 makes the duty explicit. The subscriber shall exercise reasonable care to retain control of the private key and take all steps to prevent its disclosure, and if the private key has been compromised the subscriber shall communicate the same without any delay to the Certifying Authority.

Two rules follow, and both are broken every day in practice:

  • The token is not lent. A partner who hands his token and PIN to the accountant has, in law, signed everything the accountant signs.
  • A compromise is reported at once, and the certificate is then revoked.

Duties on both sides

Section 36 requires the Certifying Authority, when issuing a Digital Signature Certificate, to certify that it has complied with the Act, that it has published the certificate or made it available to the person relying on it and the subscriber has accepted it, and that the subscriber holds the private key corresponding to the public key listed in the certificate.

Section 40 requires the subscriber to generate the key pair by applying the security procedure, where a certificate has been accepted whose public key corresponds to a key pair to be generated by the subscriber.

munotes.in13

Registering and Using the Certificate

Section 40A sets out the duties of a subscriber of an Electronic Signature Certificate.

Section 41 governs acceptance: a subscriber is deemed to have accepted a certificate if he publishes it or authorises its publication, or otherwise demonstrates his approval of it.

Suspension and revocation

Section 37, suspension. The Certifying Authority may suspend a certificate on a request from the subscriber or a person authorised by him, or if it is of opinion that the certificate should be suspended in the public interest. A certificate may not be suspended for more than fifteen days unless the subscriber has been given an opportunity of being heard.

Section 38, revocation. The Certifying Authority may revoke a certificate on the subscriber's request, on the death of the subscriber, on the dissolution or winding up of a firm or company where the subscriber is one, and in the circumstances the section sets out. Revocation is permanent; suspension is not.

Section 39, notice. Where a certificate is suspended or revoked, the Certifying Authority shall publish a notice of it in the repository it maintains.

Validity and renewal

A certificate is issued for one, two or three years and stops working on its expiry date, with no grace period.

Renewal is a fresh application. There is no extension of an existing certificate: the applicant applies again, is verified again, and downloads a new certificate, usually onto the same token.

Plan the expiry. A certificate that expires on 20 September expires in the middle of the tax audit season, and a firm that has not renewed cannot file.

What to do when things go wrong

ProblemWhat to do
Token lost or stolenReport to the Certifying Authority at once under section 42 and ask for revocation. Apply again
PIN forgottenThe token locks after a set number of wrong attempts and is then unusable. A new certificate is needed
Certificate expiredApply again; there is no extension
Name on the certificate does not match the PANThe portal will refuse the registration. The certificate has to be reissued with the correct name
Partner who held the certificate has left the firmRevoke under section 38 and issue a new certificate to another partner. Update the authorised signatory on every portal
Firm dissolvedSection 38 covers revocation on dissolution

The one-line summary

The Certifying Authority issues the certificate to a person, the person keeps the private key in a token he does not lend, the certificate is registered separately on every portal against a PAN, and it dies on its expiry date unless a fresh application is made.

munotes.in14

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself, or the past papers, for the same subject.

Report or request
Done!