Section 28
of Electronic Transactions Act
Section 28
(1)
A certification authority shall disclose —
(a)
its certificate that contains the public key corresponding to the private key used by that certification authority to digitally sign another certificate (referred to in this section as a certification authority certificate);
(b)
any relevant certification practice statement;
(c)
notice of the revocation or suspension of its certification authority certificate; and
(d)
any other fact that materially and adversely affects either the reliability of a certificate that the authority has issued or the authority’s ability to perform its services.
(2)
In the event of an occurrence that materially and adversely affects a certification authority’s trustworthy system or its certification authority certificate, the certification authority shall —
(a)
use reasonable efforts to notify any person who is known to be or foreseeably will be affected by that occurrence; or
(b)
act in accordance with procedures governing such an occurrence specified in its certification practice statement.
Issuing of certificate.