Section 73 of the Information Technology Act imposes criminal penalties of up to two years imprisonment and fines for publishing or distributing an Electronic Signature Certificate known to be false, unaccepted, or revoked.
Legal Prohibition under Section 73 of the IT Act
Digital Signature Certificates (DSC) and Electronic Signature Certificates form the legal foundation for authentication, non-repudiation, and secure transactions under Indian cyber law. Section 73 of the Information Technology Act prevents the fraudulent publication and circulation of compromised or unauthorized electronic certificates. Under Section 73(1), no person shall publish an Electronic Signature Certificate or otherwise make it available to any other party with knowledge that:
- The Certifying Authority (CA) listed in the certificate has not issued it;
- The subscriber named in the certificate has not accepted it; or
- The certificate has been revoked or suspended by the issuing authority.
The single statutory exception permitted under Section 73(1)(c) allows publication of a suspended or revoked certificate solely for the limited purpose of verifying a digital signature created prior to such suspension or revocation.
Statutory Penalties and Fine Structure
Section 73(2) prescribes criminal liability for anyone contravening Section 73(1). Any offender convicted of publishing a false or revoked digital signature certificate shall be punished with imprisonment for a term extending up to two years, or with a fine extending up to one lakh rupees (Rs. 100,000), or both.
This statutory penalty enforces accountability across public key infrastructure (PKI) networks, protecting commercial transactions, government e-filings, and legal contracts from identity fraud. Legal proceedings involving digital technology standards or government safety measures frequently involve procedural reviews, such as reported judicial directions regarding online platforms in The Delhi HC asks Centre to submit steps against Blue Whale game.
Certifying Authorities and Subscriber Responsibilities
The Controller of Certifying Authorities (CCA) regulates licensed Certifying Authorities in India under Chapter VI of the IT Act. Subscribers who apply for digital certificates must submit verified identity documents. If a private key is compromised, the subscriber must immediately request certificate revocation to prevent unauthorized use. Court decisions assessing criminal liability and procedural evidence under state laws reflect similar compliance scrutiny, as seen in Sejalben Tejasbhai Chovatiya Vs. State [Gujarat High Court, 202016].
Best Practices for Certificate Management
Organizations and individuals using digital signatures must verify certificate revocation lists (CRLs) or Online Certificate Status Protocol (OCSP) responders before trusting an electronic signature. Ensuring proper certificate lifecycle management prevents exposure to fraud while avoiding severe penal consequences under Section 73.
