Skip to content

Compliance & Trust

Trust & Compliance Centre

DDSign operates as an Electronic Certification Service Provider (E-CSP) under the Kenya Information and Communications Act CAP411A. This page publishes the information required to be disclosed to subscribers, relying parties, and the user community.

Company Information

Legal Name
Centric Global Limited
Trading Name
DDSign
Jurisdiction
Dubai Silicon Oasis, Dubai, UAE
E-CSP Regulatory Basis
Kenya ICT Act CAP411A
Primary Contact
Info@centglob.com

Certificate Lifecycle Procedures

Registration

Subscribers register via the DDSign platform by providing verified email and identity information. Upon registration, account credentials are created and the subscriber receives a confirmation email. Certificate issuance requires successful account verification.

Issuance

Certificates are issued upon verified request through the signing workflow. Subscribers must validate certificate accuracy upon receipt. Any inaccuracy must be reported immediately to Info@centglob.com so that the certificate can be revoked and re-issued. Certificate validity periods: TSA — 10 years; CA — 20 years; Signer — 2 years.

Renewal

Subscribers are notified by email at 90, 30, and 7 days before certificate expiry. Renewal requires re-authentication through the original registration channel. Expired certificates are not valid for signature verification.

Suspension

A certificate may be suspended pending investigation of a suspected compromise or policy violation. Suspended certificates appear in the Certificate Revocation List (CRL) with reason code certificateHold. Suspension is lifted if investigation confirms no compromise; otherwise the certificate is revoked. Subscribers are notified of suspension by email.

Revocation

Certificates are revoked in cases of: confirmed key compromise; inaccurate certificate information; subscriber request; cessation of operations; or CSP certificate compromise. Revocation is permanent and irreversible. Revoked certificates are published in the CRL within one hour of revocation. To request revocation, contact Info@centglob.com or use the support form.

CRL & Certificate Status

CRL Update Interval

24 hours

NextUpdate set per RFC 5280

Emergency CRL Update

< 1 hour

On confirmed key compromise

Relying parties must check certificate revocation status before accepting any signed document. The CRL is digitally signed by the DDSign CA and updated at least every 24 hours. Revocation reason codes follow RFC 5280 (keyCompromise, superseded, cessationOfOperation, certificateHold, unspecified). OCSP support is planned for a future release.

Relying Party Guide

A relying party is any person or system that accepts a DDSign-signed document as evidence of a signature. Before relying on any signed document, you must verify all of the following:

  1. 1

    Verify issuer signature

    Confirm the document signature was created by a certificate issued by the DDSign CA. The CA certificate fingerprint is available on request from Info@centglob.com.

  2. 2

    Check validity period

    Confirm that the signing certificate was valid (not expired) at the time of signing. Use the embedded RFC 3161 timestamp as the reference time.

  3. 3

    Check revocation status

    Download the current CRL and confirm the certificate serial number does not appear as revoked or suspended. CRL is updated every 24 hours.

  4. 4

    Confirm permitted usage

    The certificate KeyUsage and ExtendedKeyUsage extensions define permitted uses. Do not rely on a certificate for purposes outside its stated usage parameters.

  5. 5

    Observe reliance limits

    Reliance on any single signature transaction is limited to USD 1,000 unless a higher limit is expressly agreed. See Terms of Service §4.

Subscriber Private Key Protection

As a subscriber, you are responsible for the security of your private signing key. Compromise of your private key allows an attacker to forge your signature. Follow these requirements:

Never share your private key

Your private key must not be shared with any person, system, or service — including DDSign support staff. We will never ask for your private key.

Store keys in a secure location

Store private key files with restrictive permissions (Unix: chmod 600). Prefer hardware tokens or password-protected key stores. Do not store keys in version control, cloud storage, or email.

Report suspected compromise immediately

If you suspect your private key has been compromised, contact us immediately at Info@centglob.com or +254 715 663 018 so your certificate can be revoked without delay.

Securely delete keys when no longer needed

When a certificate expires or is revoked, securely erase the corresponding private key using a tool that overwrites the key material (e.g., shred on Linux, or use a dedicated key management tool).

Incident Reporting

Report security incidents, suspected key compromises, or certificate misuse immediately using any of the channels below. DDSign is required to notify the Communications Authority of Kenya within 24 hours of a confirmed incident.