Govt suspends 3 digital certificates by NIC to prevent misuse

Image
Press Trust of India New Delhi
Last Updated : Aug 04 2014 | 7:15 PM IST
The Controller of Certifying Authorities suspended three digital certificates issued by the National Informatics Centre Certifying Authority (NIC-CA) to prevent their misuse, Parliament was informed today.
Digital Signature Certificates (DSCs) are issued by Certifying Authorities for electronic authentication of users, Communication and IT Minister Ravi Shankar Prasad told Lok Sabha.
The Controller of Certifying Authorities, which is appointed under the Information Technology Act, 2000, licences Certifying Authorities to issue Digital Signature Certificates.
Digital Signature Certificates are issued under Sub Section 4 of Section 35 of the IT Act and they facilitate e-commerce and e-filing of documents through authentication of users and their transactions, he added.
"Three certificates issued to NIC-CA were suspended by CCA (Controller of Certifying Authorities. The unauthorised certificates that had been issued, were revoked by the NIC-CA. This was done to prevent misuse," Prasad said.
The incident has been investigated and the findings suggest that the perpetrators made an electronic intrusion in to the CA systems from outside India, he added.
"NIC-CA has been asked to revamp their infrastructure from all aspects -- technical, physical and procedural," Prasad said.
Besides, an advisory has been issued to all Certifying Authorities to examine and wherever necessary, strengthen security controls in the infrastructure used for Digital Signature Certificates issuance, the Minister added.
Last month, Google and Microsoft had complained about the unauthorised Digital Signature Certificates issued by NIC-CA.
Google in a blog post had said: "On Wednesday, July 2, we became aware of unauthorised digital certificates for several Google domains.
"The certificates were issued by NIC of India, which holds several intermediate CA certificates trusted by the Indian Controller of Certifying Authorities (India CCA)."
Similarly, Microsoft said it is aware of improperly issued SSL certificates that could be used in attempts to spoof content or perform phishing attacks.
"SSL certificates were improperly issued by NIC, which operates subordinate CAs under root CAs operated by Government of India's Controller of Certifying Authorities, which are CAs present in the Trusted Root Certification Authorities Store," it added.
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Aug 04 2014 | 7:15 PM IST

Next Story