Compliance & Trust
Trust & Compliance Centre
DDSign operates as an Electronic Certification Service Provider (E-CSP) under the Kenya Information and Communications Act CAP411A. This page publishes the information required to be disclosed to subscribers, relying parties, and the user community.
Company Information
- Legal Name
- Centric Global Limited
- Trading Name
- DDSign
- Jurisdiction
- Dubai Silicon Oasis, Dubai, UAE
- E-CSP Regulatory Basis
- Kenya ICT Act CAP411A
- Primary Contact
- Info@centglob.com
- Phone
- +254 715 663 018
Certificate Lifecycle Procedures
Registration
Subscribers register via the DDSign platform by providing verified email and identity information. Upon registration, account credentials are created and the subscriber receives a confirmation email. Certificate issuance requires successful account verification.
Issuance
Certificates are issued upon verified request through the signing workflow. Subscribers must validate certificate accuracy upon receipt. Any inaccuracy must be reported immediately to Info@centglob.com so that the certificate can be revoked and re-issued. Certificate validity periods: TSA — 10 years; CA — 20 years; Signer — 2 years.
Renewal
Subscribers are notified by email at 90, 30, and 7 days before certificate expiry. Renewal requires re-authentication through the original registration channel. Expired certificates are not valid for signature verification.
Suspension
A certificate may be suspended pending investigation of a suspected compromise or policy violation.
Suspended certificates appear in the Certificate Revocation List (CRL) with reason code
certificateHold.
Suspension is lifted if investigation confirms no compromise; otherwise the certificate is revoked.
Subscribers are notified of suspension by email.
Revocation
Certificates are revoked in cases of: confirmed key compromise; inaccurate certificate information; subscriber request; cessation of operations; or CSP certificate compromise. Revocation is permanent and irreversible. Revoked certificates are published in the CRL within one hour of revocation. To request revocation, contact Info@centglob.com or use the support form.
CRL & Certificate Status
CRL Update Interval
24 hours
NextUpdate set per RFC 5280
Emergency CRL Update
< 1 hour
On confirmed key compromise
Relying parties must check certificate revocation status before accepting any signed document. The CRL is digitally signed by the DDSign CA and updated at least every 24 hours. Revocation reason codes follow RFC 5280 (keyCompromise, superseded, cessationOfOperation, certificateHold, unspecified). OCSP support is planned for a future release.
Relying Party Guide
A relying party is any person or system that accepts a DDSign-signed document as evidence of a signature. Before relying on any signed document, you must verify all of the following:
-
1
Verify issuer signature
Confirm the document signature was created by a certificate issued by the DDSign CA. The CA certificate fingerprint is available on request from Info@centglob.com.
-
2
Check validity period
Confirm that the signing certificate was valid (not expired) at the time of signing. Use the embedded RFC 3161 timestamp as the reference time.
-
3
Check revocation status
Download the current CRL and confirm the certificate serial number does not appear as revoked or suspended. CRL is updated every 24 hours.
-
4
Confirm permitted usage
The certificate
KeyUsageandExtendedKeyUsageextensions define permitted uses. Do not rely on a certificate for purposes outside its stated usage parameters. -
5
Observe reliance limits
Reliance on any single signature transaction is limited to USD 1,000 unless a higher limit is expressly agreed. See Terms of Service §4.
Subscriber Private Key Protection
As a subscriber, you are responsible for the security of your private signing key. Compromise of your private key allows an attacker to forge your signature. Follow these requirements:
Never share your private key
Your private key must not be shared with any person, system, or service — including DDSign support staff. We will never ask for your private key.
Store keys in a secure location
Store private key files with restrictive permissions (Unix: chmod 600). Prefer hardware tokens or password-protected key stores. Do not store keys in version control, cloud storage, or email.
Report suspected compromise immediately
If you suspect your private key has been compromised, contact us immediately at Info@centglob.com or +254 715 663 018 so your certificate can be revoked without delay.
Securely delete keys when no longer needed
When a certificate expires or is revoked, securely erase the corresponding private key using a tool that overwrites the key material (e.g., shred on Linux, or use a dedicated key management tool).
Incident Reporting
Report security incidents, suspected key compromises, or certificate misuse immediately using any of the channels below. DDSign is required to notify the Communications Authority of Kenya within 24 hours of a confirmed incident.