Dear Partner, This message is to intimate you about the procurement and usage of Digital Signatures in UIDAI Authentication & e-KYC APIs for Signing the request XMLs. Currently following types of Digital Signatures are supported: 1.

End User Certificate (Issued for Organization use) - Class2/Class3

2.

Organizational Document Signer Certificate - Class2/Class 3 1. What is the difference between “End User Certificate (Issued for Organization use)” and “Document Signer Certificate”?

Certificate Field Issued To Signed by

Classes

End User Certificate (Issued for Organization use) (Supported by UIDAI APIs) Issued to Individual name, with Organizational value Meant for signing of document at individual capacity of the organization Available in Class 1, 2 and 3

UIDAI Supports only Class 2 and Class 3 Even though, there are technical Server Side capabilities to achieve automated Signing signing, purpose is largely for manual single document signing. Accountability Accountability is with Individual, representing the certificate. Extended Key NA Usage

Mode of Issuance

Document Signer Certificate (Supported by UIDAI APIs) Issued to Organizational Legal name Meant for signing at Organizational capacity. Available in Class 2 and 3 UIDAI Supports Class 2 and Class 3 Purpose is mainly for automated signing and also to reflect organizational accountability. Organizational accountability Specific application requirements are also met, like Email clients, Microsoft Applications, and Adobe Applications.

Class 3 - FIPS 140-1/2 Level 2 Hardware crypto token or HSM

When procuring for UIDAI usage this field should be excluded. Class 3 - FIPS 140-1/2 Level 2 Hardware crypto token or HSM

Class 2 - FIPS 140-1/2 Level 2 Hardware crypto token or HSM

Class 2 - FIPS 140-1/2 Level 2 Software – File based

2. What should be taken care while procuring a “Document Signer Certificate” for the usage in UIDAI APIs? 

A certificate without "Extended Key Usage" should be obtained from CAs.The CAs can be requested for this while creating/procuring a certificate. The certificate will FAIL if the “Extended Key Usage” is present.

3. E-KYC Encryption Keys (For response XML encryption by UIDAI) 

The KUA/KSA should procure an Encryption Certificate (issued for organization use) and share the public key with UIDAI for encrypting the e-KYC response XML going back to the KUA/KSA.



It is mandatory to have the key usage maintained as “Key encipherment” in the certificate



It should be a class 2 or class 3 certificate.

4. Extremely important – MANDATORY TO READ: 

UIDAI is arranging this communication for spreading awareness on procuring and using digital signature keys, and the communication is prepared as per the CCA guidelines available as on 15th May 2015 (http://cca.gov.in/cca/sites/default/files/files/DSCInteroperabilityGuidelinesR2.9. pdf ) . The entities should refer to the latest available Interoperability Guidelines published by the CCA to validate the details provided in this communication at the time of procuring a key.



Its mandatory to go through the latest UIDAI Authentication API document for the Digital Signature related guidelines for its usage in the request XMLs.



Please refer to the mode of issuance of each certificates as per the CCA guidelines. The digital signatures issuance mode (File, USB or HSM) will have a lot of significance on the security, capacity and scalability requirements of an Organization. It is highly recommended to consult with your CA and decide on the mode of issuance best suiting your Organizational/Business requirements.



This notification is for your information and appropriate action. Please note that the UIDAI validation scheme on the Digital Signatures will remain unchanged.



Any further queries should be routed to Auth Support.

Dear Partner, This message is to intimate you about ... -

Organizational Document Signer Certificate - Class2/Class 3. 1. What is the ... mode of issuance best suiting your Organizational/Business requirements.

459KB Sizes 0 Downloads 156 Views

Recommend Documents

Dear Colleagues and Friends, It is our great honor to invite you to the ...
Jun 25, 2009 - to present their research works and exchange their ideas upon topics in ... visit the official website: http://www.upjs.sk/ismck or do not hesitate.

Dear Colleagues and Friends, It is our great honor to invite you to the ...
Jun 25, 2009 - The three-day ISMCK´09 is held under the patronage of the Rector of Pavol Jozef Šafárik. University in Košice, the Dean of Pavol Jozef Šafárik University in Košice, Faculty of. Medicine and is organized by the Association of Med

April 19, 2016 Dear Stakeholder, This letter is to ... - City of Fort Collins
Apr 19, 2016 - including historical & active mines, storage tanks, roadways (county, state, ... on the SWPP, or questions regarding its development, by email to.

11 April 2016 Dear Primary School Parents, I am writing to you about ...
Apr 11, 2016 - In common with all ESF schools we have adopted a joint decision to ... a further step in making the transition from the primary schools following.

April 19, 2016 Dear Stakeholder, This letter is to ... - City of Fort Collins
Apr 19, 2016 - wells, septic systems, forest health, recreation, agricultural practices (farming ... to Fort Collins' drinking water supplies and recommends best practices to ... on the SWPP, or questions regarding its development, by email to.

April 19, 2016 Dear Stakeholder, This letter is to ... - City of Fort Collins
Apr 19, 2016 - ensuring we establish the best possible protections for the City's drinking water ... on the SWPP, or questions regarding its development, by email to. Jill Oropeza, at [email protected] by close of business, May 13, 2016.

Message to Schools and Colleges about Wireless Devices and ...
Message to Schools and Colleges about Wireless Devices and Health.pdf. Message to Schools and Colleges about Wireless Devices and Health.pdf. Open.

Message to Schools and Colleges about Wireless Devices and ...
There was a problem previewing this document. Retrying... Download. Connect more apps... Try one of the apps below to open or edit this item. Message to ...

President's Message September 2, 2006 Dear BC Conservative ...
Sep 2, 2006 - Dear BC Conservative Member,. I would like to invite you to attend our party's 2006 Annual General Meeting on Saturday and. Sunday, October 21st and 22nd. The AGM will be held at the Best Western Inn in Kelowna. BC Conservative members

Dear colleagues, We send to you the information ... -
Eleonora Melnik, Republic of Karelia, Russia; Dr. Yuriy Pelekh, Ukraine; Dr. Laima Railien÷, ... All authors must take care of the language revision by they own.

Initial Report 1. Dear Students, This is the second ...
[email protected]. Text Response. 3. What is the core product or service of your e-business? Please describe it. The core product of ...

President's Message:: Dear Friends, It has been most satisfying to see ...
May 14, 1998 - admission is free. Come and ... around the wonderful White Adobe on the grounds of. SMUS Oral ... for six classes of third graders from Carver.

Dear All, This function is an updated version of that ...
Dear All,. This function is an updated version of that presented in V. Espinoza, R. Venegas, S. Floody, "Modelo de. Sonoridad Utilizando Redes Neuronales" ...

President's Message:: Dear Friends, It has been most satisfying to see ...
May 14, 1998 - Adobe Restoration and Preservation ... around the wonderful White Adobe on the grounds of ... for six classes of third graders from Carver.

Read Online This Is Why You re Fat (And How to Get ...
support and encouragement you need to get to the finish line and beyond. With Jackie s core principles, you ll be shocked to find what is actually making you fat, ...