| General | |||
| Classes of ID-Cert | |||
| Super SSL Certificate | |||
| Accredited Organization | |||
| Fees and Charges | |||
| Service Level | |||
|   | |||
| Forms | |||
|
|||
|
|||
|
|||
| Online Services | |||
|
|||
|
|||
|
|||
| Download | |||
|
|||
|
|||
|
|||
|
|||
|
|||
|   | |||
| General | |||
| Digi-Sign carries on the business of a Recognized Certification Authority. It issues certificates for the purpose of supporting digital signatures that serve to confirm the identity of the holder of a particular certificate. | |||
| A Recognized Certification Authority may issue Certificates recognized by the GCIO under section 22 of the Electronic Transaction Ordinance (Cap. 553) or Certificates not recognized by the GCIO. | |||
| The following Digi-Sign certificates are recognized by the GCIO of the Government of the Hong Kong Special Administrative Region, in accordance with section 22 of the Electronic Transactions Ordinance (Cap. 553) of Hong Kong: | |||
|
|||
| The issuance of these recognized certificates is governed by the Certification Practice Statement that Digi-Sign publishes from time to time. The current and the preceding versions of the Certification Practice Statement can be read from this Website. For identification purpose, Digi-Sign's Certification Practice Statement for these recognized certificates bears the Object Identifier (OID) 1.3.6.1.4.1.8420.1.x.x, the last two digits denoting the version number. | |||
| In addition to Recognized Certificates, Digi-Sign also issues the following streams of Certificates not recognized by the GCIO using separate Private Keys: | |||
|
|||
| The issuance of Super SSL certificates on or before March 21, 2004 is governed by the OmniRoot SSL Certification Practice Statement while the Super SSL certificates issued thereafter are governed by the Super SSL Certification Practice Statement that Digi-Sign publishes from time to time. | |||
| The issuance of Premium-Cert is governed by the General Purpose Certification Practice Statement that Digi-Sign publishes from time to time. | |||
| The current and the preceding versions of these statements can be read from this Website. For identification purpose, Digi-Sign's OmniRoot SSL Certification Practice Statement bears the Object Identifier (OID) 1.3.6.1.4.1.8420.2.x.x, where the last two digits denoting the version number and Digi-Sign's General Purpose Certification Practice Statement bears the Object Identifier (OID) 1.3.6.1.4.1.8420.4.x.x, where the last two digits denoting the version number. | |||
|
For recognized certificates, a set of rules in the Digi-Sign's Certification Practice Statement governs the issuance of ID-Cert. This set of rules also provides the applicability of an ID-Cert to a particular community and / or class of application with common security requirements. It is the responsibility of a user (relying party) of the ID-Cert to decide whether to accept an ID-Cert issued by Digi-Sign to:
- Decrypt encrypted electronic messages as they are received by the subscriber; and - Issue acknowledgement by the subscriber upon the receipt of the encrypted electronic message. These rules provide a useful means for the relying parties or potential relying parties of an ID-Cert to determine whether it is sufficiently trustworthy for a particular use. |
|||
| The Digi-Sign Certification Practice Statement shall not be treated as, or deemed to be, any offer to the Public. Digi-Sign reserves its absolute right to refuse any subscriber application, or issue of ID-Cert pursuant to its Certification Practice Statement, without giving any reasons. | |||
| For Super SSL certificates and Premium-Cert, please contact the Digi-Sign Hotline: (852) 2917 8833 for details. | |||
| IMPORTANT NOTICE: | |||
|
ID-Cert subscribers are bound by the Subscriber Terms and Conditions and provisions of the Digi-Sign Certification Practice Statement, which prescribe, amongst others, that Digi-Sign: (a)
Shall not be responsible for the contents of any transmission, message,
contract adopted by or signed by the Subscriber using keys and ID-Cert
provided by Digi-Sign; (b)
Shall not be responsible for the use of the Subscriber's private key and
ID-Cert by the Subscriber; (c)
Shall publish the Subscriber's public key and ID-Cert in the Digi-Sign
Certificate Directory; (d)
Reserves its absolute right to amend the provisions of the CPS from time
to time; and (e) Reserves its absolute right to revoke key and ID-Cert and to publish it in the Certificate Revocation List where (i) Digi-Sign suspects a compromise of the Subscriber's key or ID-Cert, or (ii) such compromise is proven, or (iii) Digi-Sign is properly requested to do so under the CPS. |
|||
| Relying
parties and others may rely on an ID-Cert only after confirming that the
ID-Cert and its issuer's certificate have not been revoked or suspended,
and the ID-Cert and its issuer's certificate have not expired. Relying parties
and others are requested to check the details in the Digi-Sign Certificate
Directory and the Certificate Revocation List at <ldap.dg-sign.com>
For
Super SSL certificates and Premium-Cert, please contact the Digi-Sign
Hotline: (852) 2917 8833 for details. |
|||
| Classes
of ID-Cert |
|||
| There are four classes of ID-Cert issued by Digi-Sign under this CPS, namely, the Personal ID-Cert Class 1, Organizational ID-Cert Class 2, Encipherment ID-Cert Class 3 and Organizational ID-Cert Class 5. Description of the ID-Cert is as follows: | |||
| (1) Personal ID-Cert Class 1 | |||
|
This
ID-Cert is issued to individuals to support Digital Signatures that purport
to confirm the identities or other significant characteristics of the
individuals who hold a particular key. It is issued to individuals who
have attained the age of 18 years and who provide the necessary personal
particulars requested by Digi-Sign as per the Subscriber Application form.
Such particulars will be checked against the information contained in
one of the following documents for verification of the personal identity: (a)
Hong Kong permanent identity card; (b) Hong Kong identity card; (c)
Valid travel document indicating that the holder's limit of stay in Hong
Kong has not expired. |
|||
| Alternatively, the personal particulars as requested by Digi-Sign according to the Subscriber Application form may be made available to Digi-Sign through an accredited organization following the authorization of the individuals concerned. | |||
|
|
|||
| (2) Organizational ID-Cert Class 2 | |||
|
This
ID-Cert is issued to organizations to support Digital Signature that purport
to confirm the identities or other significant characteristics of the organizations
and identify the Authorized Delegates who have been duly authorized to hold
a particular key and make Digital Signatures for and on behalf of the organizations.
It is issued to organizations which provide the necessary organizational
details requested by Digi-Sign as per the Subscriber Application form,
including in particular, the following: (a)
Business registration, or exemption from business registration, under
the Business Registration Ordinance (Cap. 310); (b)
Registration of a company incorporated in Hong Kong Special Administrative
Region ("HKSAR"), or registration of an overseas company, under
Part XI of the Companies Ordinance (Cap. 32); (c)
For organizations other than those registered with the Company Registry
or Inland Revenue Department of the Government of HKSAR:
(d)
For bureaux, departments and agencies of the Government of HKSAR, an authorization
letter. |
|||
|
Alternatively, the details required by Digi-Sign as per the Subscriber Application form may be made available to Digi-Sign through an Accredited Organization following the authorization of the organizations concerned. |
|||
|
|
|||
| The Subscriber Application details from the Accredited Organization must include proof of the identity of the applicant organization. Such proof must be adequate in substantiation of the respective registration details in (2) (a), (b) and / or (c) above. | |||
|
|
|||
|
For further explanation of (2) above, an applicant organization includes an unincorporated company and a company incorporated in the HKSAR, an overseas company registered in the HKSAR, a statutory body, or an organization that is established under one of the Hong Kong Ordinances. |
|||
|
|
|||
| Applicants for Organizational ID-Cert Class 2 are required to state the personal particulars of an Authorized Delegate. Such personal particulars will be checked against the information contained in one of the documents listed in (1) for Personal ID-Cert Class 1 for verification of the personal identity of the Authorized Delegate. If the nominated Authorized Delegate is already an existing Personal ID-Cert Class 1 subscriber, this verification will be dispensed with. | |||
|
|
|||
| (3) Encipherment ID-Cert Class 3 | |||
|
This
ID-Cert is issued to individuals and organizations for encryption and
decryption of electronic messages and to support Digital Signatures (for
the issue of acknowledgements by the Subscriber upon receipt of encrypted
messages) that purport to confirm the identities or other significant
characteristics of the individual who hold a particular key, or Authorized
Delegates or Authorized Users of organizations who have been duly authorized
to hold a particular key and make the Digital Signatures for and on behalf of
the organizations. The normal practice is for the subscriber to lodge a
Subscriber Application for the Encipherment ID-Cert Class 3 at the same time
as the application for Personal ID-Cert Class 1 or Organizational ID-Cert
Class 2 or Organizational ID-Cert Class 5, as the case may be. Where
the Subscriber Application is submitted separately for the Encipherment
ID-Cert Class 3, the applicant must be an existing Personal ID-Cert Class
1 Subscriber, or an existing Organizational ID-Cert Class 2 Subscriber or
an existing Organizational ID-Cert Class 5 Subscriber at the
time of application for the Encipherment ID-Cert Class 3. The
procedures, controls and relevant requirements for an applicant to lodge
an application of an Encipherment ID-Cert Class 3, as well as for Digi-Sign
to process the application, will be the same as those for the application
for a Personal ID-Cert Class 1 or an Organizational ID-Cert Class 2 or an
Organizational ID-Cert Class 5, as the case may be. |
|||
|
|
|||
| (4) Organizational ID-Cert Class 5 | |||
|
This
ID-Cert is issued to organizations to support Digital Signatures that purport
to confirm the identities or other significant characteristics of the organizations
and identify the Authorized Users who have been duly authorized to hold a particular
key and make Digital Signatures for and on behalf of the organizations. It is
issued to organizations which provide the necessary organizational details requested
by Digi-Sign as per the Subscriber Application form, including in particular, the
following: (a)
Business registration, or exemption from business registration, under the
Business Registration Ordinance (Cap. 310); (b)
Registration of a company incorporated in Hong Kong Special Administrative
Region ("HKSAR"), or registration of an overseas company, under Part XI of
the Companies Ordinance (Cap. 32); (c)
For organizations other than those registered with the Company Registry or
Inland Revenue Department of the Government of HKSAR:
(d)
For bureaux, departments and agencies of the Government of HKSAR, an
authorization letter. |
|||
|
Alternatively, the details required by Digi-Sign as per the Subscriber Application form may be made available to Digi-Sign through an Accredited Organization following the authorization of the organizations concerned. |
|||
|
|
|||
| The Subscriber Application details from the Accredited Organization must include proof of the identity of the applicant organization. Such proof must be adequate in substantiation of the respective registration details in (4) (a), (b) and / or (c) above. | |||
|
|
|||
|
For further explanation of (4) above, an applicant organization includes an unincorporated company and a company incorporated in the HKSAR, an overseas company registered in the HKSAR, a statutory body, or an organization that is established under one of the Hong Kong Ordinances. |
|||
|
|
|||
| Applicants for Organizational ID-Cert Class 5 are required to appoint an Authorized Representative to administer the application, which mainly includes the submission of application, the receipt of secure packet in person and the delivery of secure packet to the corresponding Authorized User, and to state the personal particulars of the Authorized Representative. Such personal particulars will be checked against the information contained in one of the documents listed in (1) for Personal ID-Cert Class 1 for verification of the personal identity of the Authorized Representative. If the appointed Authorized Representative is already an existing Personal ID-Cert Class 1 Subscriber, this verification will be dispensed with. | |||
|
|
|||
| Applicants are also required to nominate the Authorized User of the Organizational ID-Cert Class 5 and to state the personal particulars of the Authorized User. Such personal particulars will be verified against the information contained in the relevant identity documents, including Hong Kong identity cards, passports, valid travel documents, or other valid identity documents that substantiate the personal particulars of the Authorized User, duly provided and confirmed by the applicants. | |||
|
|
|||
| For Super SSL certificates and Premium-Cert, please contact the Digi-Sign Hotline: (852) 2917 8833 for details. | |||
|
|
|||
| Accredited Organization | |||
|
Digi-Sign is responsible to establish the criteria for accreditation of organizations for the purpose of transfer of Subscriber Application details information direct from such organizations in support of Subscriber Applications for ID-Cert. Prior to accreditation, Digi-Sign will verify the following: (a) The organization providing the Subscriber Application details is a statutory body, or a public body, or is otherwise establish under the Hong Kong laws; (b) The organization has the capability and procedure in place to retain personal identity information for the purpose of substantiating the identification of the person applying for Personal ID-Cert Class 1; (c) The organization has the capability and procedure in place to retain the Subscriber Application details for the purpose of substantiating the identity of the organization applying for Organizational ID-Cert Class 2 or Organizational ID-Cert Class 5; (d) The organization has its privacy policy in conformance to the Personal Data (Privacy) Ordinance (Cap. 486); (e) For Personal ID-Cert Class 1, the organization providing the Subscriber Application details is in a position to:
(f) For Organizational ID-Cert Class 2, the organization providing the Subscriber Application details is in a position to:
(g) For Organizational ID-Cert Class 5, the organization providing the Subscriber Application details is in a position to:
(h) Where the Subscriber Application details have been received from an Accredited Organization, the hand-over of the PIN Mailer may be done through the Accredited Organization as a Digi-Sign agent, provided that Digi-Sign is satisfied that the systems and procedures, including management controls, relevant to the handling of PIN Mailers by the Accredited Organization, are documented and that they are at least as effective and secure as those employed by Digi-Sign. The Accredited Organization will also be subjected to spot checks by Digi-Sign to ensure that the systems and procedures agreed and documented are complied with by the Accredited Organization. (i) When an organization ceases to be Digi-Sign's Accredited Organization:
|
|||
| Application Forms and Procedure | |||
| 1. Application Form for Personal ID-Cert Class 1 and Explanatory Note | |||
| 2. Application Form for Organizational ID-Cert Class 2 and Explanatory Note | |||
| 3. Application Form for Encipherment ID-Cert Class 3 | |||
| 4. Application Form for Organizational ID-Cert Class 5 and Explanatory Note | |||
| 5. ID-Cert Subscriber Terms and Conditions | |||
| 6. ID-Cert Subscriber Terms and Conditions (For Tradelink Sponsored Subscriber) | |||
|
|
|||
| For Super SSL certificates and Premium-Cert, please contact the Digi-Sign Hotline: (852) 2917 8833 for details. | |||
| Download Root CA and Signing CA Certificates | |||
| -Click here to download ID-Cert Root CA Certificate | |||
| -Click here to download ID-Cert Signing CA Certificate | |||
| -Click here to download ID-Cert Root CA Certificate 1 | |||
| -Click here to download ID-Cert Signing CA Certificate 1 | |||
|
|
|||
| For the Root CA and Signing CA certificates of Super SSL certificates and Premium-Cert, please contact the Digi-Sign Hotline: (852) 2917 8833 for details. | |||
| Change of Subscriber Information | |||
|
An ID-Cert subscriber may apply to Digi-Sign to change the following Subscriber details: 1. For the changes applied to individual subscribers or the Authorized Delegate or Authorized Representative of Organizational subscribers
2. For the changes applied to Organizational subscribers
The subscriber must complete a Digi-Sign Change Request form. However, Digi-Sign shall revoke the existing ID-Cert and issue a new one, if the requested change involves change of the following information published in the ID-Cert: A. For
the changes applied to individual subscribers or the Authorized Delegate or
Authorized User of Organizational subscribers - Name
B. For
the changes applied to Organizational subscribers - Company
/ Organization Name |
|||
| Download Change Request Form | |||
|
|
|||
| For Super SSL Certificates and Premium-Cert, please contact the Digi-Sign Hotline: (852) 2917 8833 for details. | |||
| Certificate Revocation Form and Procedures | |||
|
The
subscribers may at any time apply to Digi-Sign to revoke the ID-Cert.
However, a subscriber must promptly apply to Digi-Sign to revoke the ID-Cert
upon the occurrence of the following: - Loss
of the private key A request to revoke an ID-Cert must be in writing and submitted by the subscriber, the Authorized Delegate or the Authorized Representative for the Authorized Users of the subscriber as the case may be, to Digi-Sign in person. Digi-Sign will provide facilities for the subscriber to download a revocation request form. Digi-Sign will keep records of the time and date of receipt of a revocation request, and endeavour to process the revocation before the end of the next working day of its receipt at the Digi-Sign Office. Processing of the request will include checking of the subscriber's signature in the revocation request form. Once the validity of the revocation request is established, Digi-Sign will initiate action in its trustworthy system to revoke the ID-Cert, and update the Certificate Revocation List (CRL). The business hours for processing of ID-Cert Revocation Request are as follows: Monday
to Friday: 8:30am to 6:00pm For
all revocation of ID-Cert, the Digi-Sign trustworthy system will update
the Digi-Sign CRL promptly upon the processing of revocation of an ID-Cert
in the system. Digi-Sign will further issue a notice of revocation to
the subscriber, and this will be done within two working days of the update
of the revocation to the CRL. |
|||
| Certificate Revocation Form | |||
|
|
|||
| For Super SSL Certificates and Premium-Cert, please contact the Digi-Sign Hotline: (852) 2917 8833 for details. | |||
| Digi-Sign Fees & Charges | |||
| Effective from 1 July, 2007 | |||
| Subscription fee payable for Personal ID-Cert Class 1: | |||
|
|||
| Subscription fee payable for Organizational ID-Cert Class 2: | |||
|
|||
| Subscription fee payable for Organizational ID-Cert Class 5: | |||
|
|||
| Applicable
to all Classes of ID-Cert:
1. All Classes of ID-Cert are valid for a maximum of 36 months from date of issuance. 2. An
encipherment certificate will be issued at HK$30 to each subscriber
at the time of issuance of Personal ID-Cert Class 1 or Organizational
ID-Cert Class 2 or Organizational ID-Cert Class 5. 3. If
an encipherment certificate is requested separately from a subscriber
application, a fee of HK$79 (1 Year) / HK$119 (2 Year) / HK$139 (3 Year) per
encipherment certificate is payable. 4. A
service charge of HK$130 is payable for each subscriber application, where
the applicant has requested to deliver the certificate and to complete
the identity verification process at a special location within Hong Kong
nominated by the subscriber and this location is outside the Digi-Sign
offices. |
|||
|
For Super SSL Certificates and Premium-Cert, please contact the Digi-Sign Hotline: (852) 2917 8833 for details. |
|||
Administrative
Charge: Request to Access Personal Information
|
|||
| Important
Notice
The
above fees and charges are current at the time of publication. Digi-Sign
reserves the right to vary the rates, fees and charges herein without
prior notice. |
|||
| Service Level | |||
|
Digi-Sign pledges to notify the applicants of the result of the subscriber applications within three working days of the decision to approve or reject the subscriber applications upon receipt of all necessary information and supporting documents from the applicants. For Super SSL Certificates and Premium-Cert, please contact the Digi-Sign Hotline: (852) 2917 8833 for details. |