28/08/2016
!!! Beware !!!
Is your Digital Signature Safe?
Finally the time has arrived to discuss the crimes relating to Digital Signature Certificates because being a Registering Authority (RA) of DSC I have to provide an answer for all those who question me that why I can’t obtain a DSC without applicants’ e-mail and Phone Number when few other RAs (not all RAs) can do so.
According to section 71 of the Information Technology Act, 2000
Whoever makes any misrepresentation to, or suppresses any material fact from, the Controller or the Certifying Authority for obtaining any license or Digital Signature Certificate, as the case may be, shall be punished with imprisonment for a term which may extend to two years, or with fine which may extend to one lakh rupees, or with both.
This is the actual Provision as per the Act.
Now let us see how Certifying Authority (CA) ensures the identity of the applicant.
This is done through Mobile and e-mail verification. This is mandatory for Class 2 certificates. This verification will be done once the physical application is approved by CA (e-mudhra/Safescrypt/(n) code). The process will be, RA will have to process the application form and the same has to be submitted to CA for Approval. On approval an SMS and email will be triggered to customer for the mobile verification. The customer has to make a call/send an SMS to the customer Care number of CA with the same number which he had registered for procuring the DSC.
There might be slight difference in sequence of steps mentioned above depending on the Certifying Authority but all the steps are required to be followed by all the CAs.
Thus, during the registration process the Mobile No. and e-mail ID fields have been marked as Mandatory and the same shall be unique for each applicant. Thus the portal never accepts a registration without unique values in these fields.
Thus if any one offers that he can provide a DSC without Mobile No./e-mail ID he definitely must be fooling you or is going to commit a fraud.
Now let us see how few RAs are committing this fraud.
What some fraudulent RAs are doing is they are obtaining few hundreds of dummy SIM cards either in the name of the actual applicants or by submitting fake documents. Once these SIMs are activated they will apply for Digital Signatures using these SIMs and do the mobile verification through them after that they will threw the SIMs or might use for another purpose.
By virtue of this action by RA all the parties who are involved in the process of issuance/obtaining the DSC are either directly/indirectly being covered by the provisions of Sec.71 of the IT Act, 2000.
Moreover there is no need to explain how a Digital Signature can be misused. If such an event is evidenced, even the applicant cannot claim ignorance of the Fraud as the mobile number and email ID are duly verified.
Team HSS