National Repository of Digital Signatures Certificate (NRDC)
The Controller of Certifying Authorities operates the National Repository of Digital Signatures (NRDC) as required under Section 20 of the IT Act 2000. Copies of all Digital Signature Certificates and the corresponding Certificate Revocation List (CRL) issued by all licensed Certifying Authorities in the country are maintained in the NRDC.
Access to these Digital Signature Certificates is provided with a search facility so that the public keys contained in these certificates are available to any member of the public.
The NRDC is updated through weekly submission by all the licensed CAs as prescribed in the Guidelines for submission to NRDC. For latest Information users and relying parties are advised to verify the certificates and CRL from the website of the issuing CA.
Guidelines for submission to NRDC
No. 1(6)/2001-CCA
Office of the Controller of Certifying Authorities
Ministry of Communications and Information Technology
Government of India
Electronics Niketan
6, CGO Complex, New Delhi – 110 003
Circular No. 1/2002
December 16, 2002
GUIDELINES FOR SUBMISSION OF CERTIFICATES AND CRLS
TO THE CCA FOR PUBLISHING IN NRDC BY CERTIFYING
AUTHORITIES
As per Section 20 of the IT Act 2000, the Controller is required to act as the
Repository of all Digital Signature Certificates issued under the Act. For this purpose the
Certifying Authorities licensed under the Act have to submit the Certificates and the
CRLs issued by them to the National Repository of Digital Certificates (NRDC),
maintained by the CCA.
The following is the procedure for submission of the Certificates and CRLs by the
Certifying Authorities:
- Certifying Authorities shall submit Certificates and CRLs to the NRDC on a
weekly basis. All these submissions shall reach the designated email address
by 12 noon every Monday. If it is a gazetted holiday the same shall reach on
the next working day by 12 noon.
- Submission shall be through e-mail
- The e-mail shall be digitally signed by an authorised person and be addressed
to nrdc@cca.gov.in. The digital signature certificate of the authorised person
shall be formally submitted to the CCA on CD and be accompanied by a letter
physically signed by the authorised signatory of the CA (one time or when the
authorized person is changed by the CA).
- Separate e-mails shall be sent for
- Certificates (Sub: NRDC Update – Certificates)
- CRLs. (Sub: NRDC Update – CRLs)
- The actual data pertaining to certificates and CRLs shall be submitted as an
attachment file in LDIF format including the following:
- Certificates – All entries to be added (incremental)
- CRL - All entries, accumulated to date
- The convention for file names shall be as follows:
- Certificates : NRDC_CA Name_Cert_Update_DDMMYYYY.ldif
- CRLs : NRDC_CA Name_CRL_Update_DDMMYYYY.ldif
- Certificates and CRLs updated in NRDC shall be stored as indicated in the
DIT structure attached.
- A sample LDIF file is included in the Annexure.
The Certifying Authorities shall comply with this Guideline with immediate effect.
(K.N.Gupta)
Controller of Certifying Authorities
ANNEXURE
With No, 1(6)2001 – CCA
Dated December 16, 2002
Structure of the Directory Information Tree (DIT) of NRDC
C=in
|
O= India PKI
|
OU= CCA India
|
OU= LCA1
|
(PKC issued to LCA1)
|
|
OU= LCA2
|
(PKC issued to LCA1)
|
|
CN=CCA India
|
(CRL of CCA India – Latest &
Full CRL)
|
|
|
|
O= LCA1
|
(All PKCs issued by LCA1 and the CRL) |
|
|
O= LCA2
|
(All PKCs issued by LCA2 and the CRL) |
|
|
LDIF format for submission by LCA
dn: c=IN
objectclass: Country
dn: o=LCAxx,c=IN
objectclass: Organisation
dn: ou=India CA Services,o=LCAxx,c=IN
objectclass: XX
dn: cn=usr2,ou=CA Services,o=LCAxx,c=IN
objectclass: XX
dn: mail=usr2@xyz.com,cn=usr2,ou=CA Services,o=LCAxx,c=IN
mail:usr2@xyz.com
cn:usr2
ou:CA Services
o:LCAxx
c:IN
usercertificate;binary::MIID6TCCAtGgAwIBAgIQQta2AuwXSe1OLZryR/4uZDANBgkqhkiG9w0BAQQFADCBlzELM
AkGA1UEBhMCSU4xGzAZBgNVBAoTElNhZmVzY3J5cHQgTGltaXRlZDFCMEAGA1UECxM5VGVybXMgb2YgdXNlIGF0IG
h0dHBzOi8vd3d3LnNhZmVzY3J5cHQuY29tL2luZGlhcnBhIChjKTAyMScwJQYDVQQDEx5TYWZlc2NyeXB0IENsYXNzIEMg
Q29uc3VtZXIgQ0EwHhcNMDIwMjA2MDAwMDAwWhcNMDMwMjA2MjM1OTU5WjCBpzELMAkGA1UEBhMCSU4xFDAS
BgNVBAgUC01haGFyYXNodHJhMQ8wDQYDVQQHFAZNdW1iYWkxGzAZBgNVBAoUElNhZmVzY3J5cHQgTGltaXRlZDEa
MBgGA1UECxQRSW5kaWEgQ0Eg
objectclass: XX
|