2- that the signatory had control of the signature creation information at the time when the certificate of certification was issued. 3- that signature creation information was valid at or before the time when the certificate of certification was issued. Article (38) A certification service provider shall provide reasonably accessible means that enable a relying party to ascertain the following: (1) the identity of the certification service provider. (2) any limitation on the purpose or value for which the signature creation information or the certificate may be used. (3) the method used to determine the identity of the signatory. (4) that the signature creation information is valid and have not been compromised. (5) any limitation on the scope or extent of liability stipulated by the certification service provider. (6) the method to give notice pursuant to this Law. (7) whether a timely revocation service is offered. Article (39) The certification service provider shall revoke or suspend the certification certificate upon the request of the owner of the certificate or under any other circumstances that require suspension or revocation of the certificate. The Supreme Council shall issue a decision specifying those circumstances along with the criteria. The certification service provider shall also immediately notify the owner of the certification certificate regarding the revocation or suspension of the certificate and the reasons therefor and shall cease the suspension or revocation should the reason no longer exists. The certification service provider shall be responsible for the damages incurred by a person acting in good faith as a result of the failure on the part of the certification service 15

Select target paragraph3