Singapore legislation

Section 28

of Electronic Transactions Act

Section 28

Disclosure

(1)

A certification authority shall disclose —

(a)

its certificate that contains the public key corresponding to the private key used by that certification authority to digitally sign another certificate (referred to in this section as a certification authority certificate);

(b)

any relevant certification practice statement;

(c)

notice of the revocation or suspension of its certification authority certificate; and

(d)

any other fact that materially and adversely affects either the reliability of a certificate that the authority has issued or the authority’s ability to perform its services.

(2)

In the event of an occurrence that materially and adversely affects a certification authority’s trustworthy system or its certification authority certificate, the certification authority shall —

(a)

use reasonable efforts to notify any person who is known to be or foreseeably will be affected by that occurrence; or

(b)

act in accordance with procedures governing such an occurrence specified in its certification practice statement.