23
PART X - REGULATION OF CERTIFICATION AUTHORITIES
37.
Controller of Certification Authorities
(1)
There is established for the purposes of this Act the public office of
Controller of Certification Authorities.
(2)
The Controller shall be assisted by such other public officers as
may be necessary.
(3)
The Controller shall maintain a publicly accessible database
containing a certification authority disclosure record for each licensed certification
authority which shall contain such particulars as may be prescribed.
(4)
In the application of the provisions of this Act to certificates issued
by the Controller and to digital signatures verified by reference to those
certificates, the Controller shall be deemed to be a licensed certification authority.
38.
Recommended reliance limit
(1)
A licensed certification authority shall, where it issues a certificate
to a subscriber, specify a recommended reliance limit in the certificate.
(2)
The licensed certification authority may specify different limits in
different certificates.
39.
Liability limits for licensed certification authorities
A licensed certification authority shall not be liable (a)
for any loss caused by reliance on a false or forged digital signature
of a subscriber, where it has acted in compliance with the
requirements of this Act relating thereto;
(b)
in excess of the amount specified in the certificate as its
recommended reliance limit for either (i)
a loss caused by reliance on a misrepresentation in the
certificate of any fact that the licensed certification authority
is required to confirm; or
(ii)
failure to comply with sections 26 and 27 in issuing the
certificate.