19
27.
(a)
the prospective subscriber is the person to be referred to in
the certificate to be issued;
(b)
in case the prospective subscriber is acting through an
agent, the subscriber authorised the agent to have custody
of the subscriber's private key and to request the issue of a
certificate setting out the corresponding public key;
(c)
the information in the certificate to be issued is accurate;
(d)
the prospective subscriber rightfully holds the private key
corresponding to the public key to be referred to in the
certificate;
(e)
the prospective subscriber holds a private key capable of
creating a digital signature; and
(f)
the public key to be referred to in the certificate can be used
to verify a digital signature affixed by the private key held by
the prospective subscriber.
Representations on issue of certificate
(1)
A certification authority shall, by the issue of a certificate, represent
to a person who reasonably relies on the certificate or a digital signature
verifiable by the public key referred to in the certificate that the certification
authority has issued the certificate in accordance with any certification practice
statement incorporated by reference in the certificate or of which the relying
person has notice.
(2)
In the absence of any certification practice statement, the
certification authority shall, subject to subsection (3), represent that (a)
it has complied with all applicable requirements of this Act in
issuing the certificate, and where it has published the
certificate or otherwise made it available to a person relying
on it that the subscriber referred to in the certificate has
accepted it;
(b)
the subscriber identified in the certificate holds the private
key corresponding to the public key referred to in the
certificate;
(c)
the subscriber's public key and private key constitute a
functioning key pair;