Singapore legislation

Section 29

of Electronic Transactions Act

Section 29

Issue of certificate

(1)

A certification authority may issue a certificate to a prospective subscriber only after the certification authority —

(a)

has received a request for issuance from the prospective subscriber; and

(b)

has —

(i)

if it has a certification practice statement, complied with all of the practices and procedures set forth in such certification practice statement including procedures regarding identification of the prospective subscriber; or

(ii)

in the absence of a certification practice statement, complied with the conditions in subsection (2).

(2)

In the absence of a certification practice statement, the certification authority shall confirm by itself or through an authorised agent that —

(a)

the prospective subscriber is the person to be listed in the certificate to be issued;

(b)

if the prospective subscriber is acting through one or more agents, the subscriber authorised the agent to have custody of the subscriber’s private key and to request issuance of a certificate listing the corresponding public key;

(c)

the information in the certificate to be issued is accurate;

(d)

the prospective subscriber rightfully holds the private key corresponding to the public key to be listed in the certificate;

(e)

the prospective subscriber holds a private key capable of creating a digital signature; and

(f)

the public key to be listed in the certificate can be used to verify a digital signature affixed by the private key held by the prospective subscriber.