Circular No. 41/2017/TT-BTTTT stipulates digital signatures for electronic documents, including technical requirements and functions of signing software and signature verification software, as well as the responsibilities of agencies and organizations in using and managing digital signatures. This Circular takes effect from February 5, 2018.
Scope of application
Agencies and organizations currently using or planning to use electronically signed documents.
Key points
- Technical requirements and functions of signing software and signature verification software
- Responsibilities of the head of agencies and organizations in managing and using digital signatures
- List of standards for electronic document formats and digital signatures recommended for application.
- Process for transitioning from current software to new software that meets the requirements of this Circular.
- Responsibilities of the Department of Information and Communications, specialized units in information technology in disseminating and reporting on the implementation of this Circular.
🌐 Social impact of this document
- Enhancing security for electronically signed documents
- Ensuring compatibility between signing software and signature verification software
- Improving management and usage efficiency of digital signatures in agencies and organizations.
❓ Frequently asked questions
Is this Circular mandatory for all agencies and organizations?
This Circular requires agencies and organizations currently using or planning to use electronically signed documents to comply with its provisions.
What technical standards are recommended for application in this Circular?
The list of standards for electronic document formats and digital signatures includes standards such as PKCS#1, FIPS PUB 180-4, XML Encryption Syntax and Processing, and many other standards.
How long is the transition period from current software to new software?
At the latest within 12 months from the date this Circular takes effect (i.e., until February 5, 2019), agencies and organizations must upgrade and supplement signing software and signature verification software to meet the requirements.
Full text
|
MINISTRY OF INFORMATION AND COMMUNICATION |
SOCIALIST REPUBLIC OF VIET NAM |
|
Number: 41/2017/TT-BTTTT |
Hanoi, December 19, 2017 |
CIRCULAR
REGULATIONS ON THE USE OF DIGITAL SIGNATURES FOR ELECTRONIC DOCUMENTS IN STATE ORGANIZATIONS
________
Pursuant to the Law on Electronic Transactions dated November 29, 2005;
Pursuant to the Law on Information Technology dated June 29, 2006;
Pursuant to Decree No. 26/2007/NĐ-CP dated February 15, 2007 of the Government detailing the implementation of the Law on Electronic Transactions regarding digital signatures and digital signature certification services; Decree No. 106/2011/NĐ-CP dated November 23, 2011 amending and supplementing certain articles of Decree No. 26/2007/NĐ-CP of the Government dated February 15, 2007; Decree No. 170/2013/NĐ-CP dated November 13, 2013 amending and supplementing certain articles of Decree No. 26/2007/NĐ-CP dated February 15, 2007 and Decree No. 106/2011/NĐ-CP dated November 23, 2011 of the Government;
Pursuant to Decree No. 64/2007/NĐ-CP dated April 10, 2007 of the Government on the application of information technology in state agency activities;
Pursuant to the Government Decree No. 01/2013/NĐ-CP dated January 3, 2013 detailing certain provisions of the Law on Archives;
Pursuant to Decree No. 17/2017/NĐ-CP dated February 17, 2017, issued by the Government, on the functions, tasks, powers, and organizational structure of the Ministry of Information and Communications;
The Minister of Information and Communications issues this Circular regulating the use of digital signatures for electronic documents in state organizations.
PART I
GENERAL PROVISIONS
Article 1. Scope of Regulation
1. This Circular regulates the signing, verification of digital signatures on electronic documents; technical requirements and functions of digital signature software, digital signature verification software for electronic documents in state organizations.
2. This Circular does not regulate the use of digital signatures for electronic documents containing information listed in the State Secrets Directory.
Article 2. Applicability
1. This Circular applies to agencies and organizations (including: Ministries, ministerial-level agencies, government-affiliated agencies, People's Committees at all levels, units funded from the State budget) and related organizations and individuals using digital signatures for electronic documents of state organizations.
2. Other agencies and organizations are encouraged to apply.
Article 3. Explanation of Terms
In this Circular, the following terms are understood as follows:
1. "Organizational digital certificate" means a digital certificate issued by a service provider for digital signature certification to the head of an organization in accordance with the provisions of the law.
2. "Individual digital certificate" means a digital certificate issued by a service provider for digital signature certification to state officials and persons authorized by organizations in accordance with the law on management and use of seals.
3. "Seal secret key" means the secret key corresponding to the organizational digital certificate.
4. "Personal secret key" means the secret key corresponding to the individual digital certificate.
5. "Organizational digital signature" means a digital signature created when using the seal secret key.
6. "Personal digital signature" means a digital signature created when using the personal secret key.
7. "Digital signature software" means a software program with the function of digitally signing electronic documents.
8. "Digital signature verification software" means a software program with the function of verifying the validity of digital signatures on electronic documents.
9. "Authenticity of digitally signed electronic document" means an electronic document verified through a digital signature attached to the electronic document that identifies the signer or the organization that has signed the electronic document.
10. "Integrity of digitally signed electronic document" means an electronic document whose content remains unchanged throughout the process of exchange, processing, and storage after being digitally signed.
11. "Online Certificate Status Protocol (OCSP) system" means a system providing a service allowing the determination of the current status of a digital certificate.
12. "Secret key storage device" means a physical device containing the secret key and digital certificate of the subscriber.
Article 4. Principles for using digital signatures on electronic documents
1. A digital signature must be attached to an electronic document after it has been signed.
2. An electronically signed document must ensure authenticity and integrity throughout the process of exchange, processing, and storage of the signed electronic document.
Article 5. Management of personal secret keys and seal secret keys
1. The authorized person signing digitally is responsible for safely managing their personal secret key.
2. The head of the agency or organization is responsible for assigning the archivist to manage and use the seal secret key according to regulations.
3. Equipment storing the seal secret key must be securely kept at the agency or organization's headquarters.
Chapter II
REGULATIONS ON DIGITAL SIGNING AND VERIFYING DIGITAL SIGNATURES ON ELECTRONIC DOCUMENTS IN STATE ORGANIZATIONS
Article 6. Digital signing on electronic documents
1. Digital signing is carried out through digital signing software; successful or unsuccessful signing of an electronic document must be reported through the software.
2. Digital signing on electronic documents
a) In cases where the authorized person signs an electronic document, through digital signing software, the authorized person uses their personal secret key to sign the electronic document;
b) In cases where the agency or organization signs an electronic document, through digital signing software, the archivist assigned uses the agency or organization's seal secret key to sign the electronic document;
3. Displaying information about the digital signature of the authorized person and the agency or organization's digital signature on the electronic document shall be implemented in accordance with the regulations of the Ministry of Home Affairs.
4. Information about the authorized person signing digitally, the agency or organization signing digitally must be managed in the database accompanying the digital signing software. The content of the managed information is stipulated in Clause 4, Article 1, Decree No. 106/2011/NĐ-CP dated November 23, 2011 of the Government.
Article 7. Verifying digital signatures on electronic documents
1. Verifying digital signatures on electronic documents is carried out as follows:
a) Decrypting the digital signature using the corresponding public key;
b) Checking and verifying the signer's information on the digital certificate attached to the electronic document; checking and verifying the signer's information is carried out in accordance with Article 8 of this Circular;
c) Checking the integrity of the digitally signed electronic document.
2. A digital signature on an electronic document is valid when the verification of the digital certificate information of the signer at the time of signing is still effective, the digital signature is created correctly by the corresponding private key on the digital certificate, and the electronic document ensures integrity.
3. Information about the signer; the agency or organization signing on the electronic document must be managed in the database accompanying the digital signature verification software. The content of the managed information is stipulated in Clause 4, Article 1, Decree No. 106/2011/NĐ-CP dated November 23, 2011 of the Government.
Article 8. Verifying the validity of digital certificates
1. Verifying the validity of digital certificates at the time of signing is carried out in the following steps:
a) Checking the validity of the digital certificate through the list of revoked digital certificates (CRL) published at the time of signing or checking the validity of the digital certificate by online certificate status checking method (OCSP) in online mode;
b) The verification of the digital certificate of the signer on the electronic document must verify down to the original certificate authority service provider (Root CA).
2. A digital certificate is valid when meeting all of the following criteria:
a) Valid at the time of signing;
b) Compliant with the scope of use of the digital certificate and the legal responsibility of the signer;
c) The status of the digital certificate is active at the time of signing.
3. A digital certificate is not valid if it does not meet one of the criteria specified in Clause 2 of this Article.
Article 9. Information stored with signed electronic documents
1. Information stored with signed electronic documents includes:
a) For outgoing documents:
- The digital signature certificate of the signer at the time of signing;
- A list of revoked digital signature certificates at the time of signing by the service provider of digital signature verification;
- The regulation on verification by the service provider of digital signature verification at the time of signing;
- Information about the responsibility of the signer;
- Valid timestamp authentication at the time of signing.
b) For incoming documents:
- Corresponding digital signature certificates for each digital signature on the incoming electronic document;
- A list of revoked digital signature certificates at the time of signing by the service provider of digital signature verification;
- The regulation on verification by the service provider of digital signature verification at the time of signing;
- Information about the responsibility of the signer;
- Valid timestamp authentication at the time of receipt.
3. Information stored with signed electronic documents managed by digital signature software and digital signature verification software shall be consistent with the retention period of the electronic document as prescribed.
Article 10. Revocation of information stored with signed electronic documents
1. Information stored with signed electronic documents is revoked simultaneously with the electronic document.
2. The revocation of information stored with signed electronic documents shall not affect other electronic documents and ensure the normal operation of the system.
3. Revocation of information stored with signed electronic documents is carried out by software.
Chapter III
TECHNICAL REQUIREMENTS AND FUNCTIONS FOR DIGITAL SIGNATURE SOFTWARE AND DIGITAL SIGNATURE VERIFICATION SOFTWARE
Article 11. Technical requirements and functions for digital signature software
Digital signature software is independent software or a component (module) of software that meets the following requirements:
1. Complies with technical standards and regulations stipulated in the annex to this Circular;
2. Has functions for signing electronic documents that comply with the provisions of Clauses 2, 3, and 4 of Article 6 of this Circular;
3. Has a function to check the validity of digital signature certificates as provided for in Article 8 of this Circular;
4. Has a function to manage information stored with signed electronic documents as provided for in Article 9 of this Circular;
5. Has a function to revoke information stored with signed electronic documents as provided for in Article 10 of this Circular;
6. Has a function to notify (in writing or by symbol) the signer whether the signing of the electronic document was successful or not;
7. Supports the installation and integration of original digital signature certificates issued by the digital signature verification organization to sign electronic documents into the digital signature software to verify the validity of digital signature certificates on electronic documents;
8. Stamps the time at the moment of signing.
Article 12. Technical requirements and functions for digital signature verification software
Digital signature verification software is independent software or a component (module) of software that has functions to verify digital signatures on electronic documents that meet the following requirements:
1. Complies with technical standards and regulations stipulated in the annex to this Circular;
2. Has a function to verify digital signatures on electronic documents as provided for in Clauses 1, 2, and 3 of Article 7 of this Circular;
3. Has a function to manage information stored with signed electronic documents as provided for in Article 9 of this Circular;
4. Has a function to revoke information accompanying signed electronic documents as provided for in Article 10 of this Circular;
5. Supports the installation and integration of original digital signature certificates issued by the digital signature verification service provider to sign electronic documents into the digital signature verification software to verify digital signatures on electronic documents;
6. Has a function to notify the verifier whether the digital signature verification result is valid or invalid;
7. Stamps the time at the moment of receiving incoming documents.
Chapter IV
IMPLEMENTATION
Article 13. Responsibilities of organizations providing digital signature certification services
1. Maintain complete, accurate, up-to-date, and publicly disclose all of the following information on the organization's electronic website (website) providing digital signature certification services, which must ensure operation 24 hours a day, 7 days a week (to support determining the validity of digital signatures on electronic documents)
a) Information related to temporary suspension, revocation of digital certificates and revoked digital certificates of subscribers;
b) Information related to digital certificates of subscribers, list of valid or expired digital certificates;
c) Certification regulations of the organization providing digital signature certification services.
2. Disclose technical specifications (both documentation and tools) related to the organization providing digital signature certification services and digital signature standards; provide original digital certificates of the organization providing digital signature certification services to software developers to integrate into digital signature verification software.
3. Encourage organizations providing digital signature certification services to provide online certificate status checking services (OCSP).
4. Provide time stamping services.
Article 14. Responsibilities of agencies and organizations using digital signatures for electronic documents.
1. Apply digital signature software, digital signature verification software as prescribed in Articles 11 and 12 of this Circular.
2. Implement network connection according to the provisions of Clause 3, Article 8 of Decree No. 64/2007/ND-CP dated April 10, 2007 of the Government to ensure security, confidentiality, and high availability.
3. Organize management of software products (by version) with digital signature functions, digital signature verification functions, store information accompanying signed electronic documents corresponding to digital signature technical standards and norms that the software supports to ensure readiness, compatibility, and security during the use of stored signed electronic documents.
Article 15. Responsibilities of heads of agencies and organizations using digital signatures
1. Fulfill the responsibilities of the head as prescribed in Clause 1, Article 8 of Decree No. 64/2007/ND-CP dated April 10, 2007 of the Government.
2. Regularly inspect to ensure that the management and use of digital signatures and digital certificates at their agencies and organizations comply with this Circular and other relevant regulations.
3. Based on organizational requirements, business operations, and ensuring information security in electronic transactions, propose issuance, revocation, and suspension of individual digital certificates and agency or organization digital certificates under their management.
4. When there is a request to convert stored signed electronic documents to a new file format (for reasons of information security or obsolescence of hardware and software), develop a plan and obtain approval from the specialized agency responsible for information technology, ensuring compatibility and verification of the validity of digital signatures.
Article 16. Transitional Provisions
Within twelve months from the date this Circular takes effect, agencies and organizations currently using digital signature and digital signature verification software that do not meet the technical requirements and functions stipulated in this Circular shall upgrade and supplement digital signature software and digital signature verification software to comply with the regulations.
Article 17. Implementation Provisions
1. The National Electronic Certification Center is responsible for leading and coordinating with the Legal Department and relevant units to guide and provide technical support for the implementation of the contents of this Circular.
2. Provincial Departments of Information and Communications, specialized units on information technology of Ministries, ministerial-level agencies, and government agencies have the responsibility:
a) To disseminate the implementation of the provisions of this Circular;
b) Annually report to the Ministry of Information and Communications (National Electronic Certification Center) on the situation of using digital signatures for electronic documents at agencies and organizations.
Article 18. Effective Date
1. This Circular takes effect from February 5, 2018.
2. The Director of the Office, the Director of the National Electronic Certification Center, agencies, organizations, and individuals concerned are responsible for implementing this Circular.
4. During the implementation process, if there are difficulties or obstacles, agencies, organizations, and individuals should promptly reflect them to the Ministry of Information and Communications (National Electronic Certification Center) for consideration and resolution./.
|
Place of Receipt: |
THE MINISTER |
ANNEX
LIST OF STANDARDS
ON DIGITAL SIGNATURES AND FORMATS OF SIGNED ELECTRONIC DOCUMENTS
(Issued together with Circular No. 41/2017/TT-BTTTT dated 19 the 12 NAME OF ORGANIZATION/UNIT/
|
Serial Number |
Type of standard |
Standard Code |
Full Name of Standard |
Applicable to|||energy |
|
1 |
Standard for signedcouncillORSa) Trip tickets are printed with face values corresponding to the amount charged for one-time use of the service for each type of vehicle;periodelectronic documentsệSigned electronic document (meeting the requirements of Article 6 of this Circular) |
|||
|
1.1 |
(.pdf) |
Portable Document Format (.pdf) - Version 1.4 or higher |
Mandatory application |
Standards for documents, spreadsheets, presentations, graphic images in the list of technical standards for ICT applications in state agencies. |
|
1.2 |
Encouraged application |
Digital signature standardPublic Key Cryptography Standard (PKCS#1) RSA Cryptography Standard (Version 2.1 or higher) |
TCVN 7635:2007 |
|
|
2 |
Cryptographic Techniques - Digital Signatures. |
|||
|
2.1 |
Secure Hash Function Standard |
FIPS PUB 180-4 |
Secure Hash Standard |
Standards for documents, spreadsheets, presentations, graphic images in the list of technical standards for ICT applications in state agencies. |
|
Mandatory application of SHA-256, 384, 512 hash functions. |
Secure XML Message Transmission |
|||
|
2.2 |
XML Encryption Syntax and Processingrime Minister cXML Signature Syntax and Processing |
XML Key Management |
XKMS |
XML Key Management Specification version 2.0 |
|
2.3 |
Cryptographic Message Syntax for Signing and Encrypting Files, amended and supplemented by Decree No. 109/2025/NĐ-CP and Decree No. 193/2025/NĐ-CPPKCS#7 v |
.5 (RFC 2315) |
.5 (RFC 2315) |
Standards for documents, spreadsheets, presentations, graphic images in the list of technical standards for ICT applications in state agencies. |
|
Cryptographic message syntax for file-based signing and encrypting |
Cryptographic message syntax for file-based signing and encrypting |
Standards for documents, spreadsheets, presentations, graphic images in the list of technical standards for ICT applications in state agencies. |
||
|
2.4 |
Time stamping service standard |
Time stamping protocol v2.0 |
RFC 3161 |
Standards for documents, spreadsheets, presentations, graphic images in the list of technical standards for ICT applications in state agencies. |
|
2.5 |
Internet X.509 Public Key Infrastructure - Time Stamp Protocol |
Time stamping service1ISO/IEC |
Information technology - Security techniques - Time Stamping services - Part 1: Framework |
Standards for documents, spreadsheets, presentations, graphic images in the list of technical standards for ICT applications in state agencies. |
|
3 |
- Apply the trio of standards: ISO/IEC 18014-1:2008; ISO/IEC 18014-2:2009; ISO/IEC 18014-3:2009.of the Government stipulating functions, tasks, powers, and organizational structure of the Ministry of Home AffairsInformation technology - Security techniques - Time Stamping services - Part 2: Mechanisms producing independent tokens |
|||
|
3.1 |
Timestamp issuance protocol |
RFC 3161 |
Internet X.509 Public Key Infrastructure - Time Stamp Protocol |
Standards for documents, spreadsheets, presentations, graphic images in the list of technical standards for ICT applications in state agencies. |
|
3.2 |
Timestamp service |
ISO/IEC |
Information technology - Security techniques - Timestamp services - Part 1: Framework |
Standards for documents, spreadsheets, presentations, graphic images in the list of technical standards for ICT applications in state agencies. - Apply the triad of standards: ISO/IEC 18014-1:2008; ISO/IEC 18014-2:2009; ISO/IEC 18014-3:2009. |
|
ISO/IEC |
Information technology - Security techniques - Timestamp services - Part 2: Mechanisms producing independent tokens |
|||
|
ISO/IEC |
Công nghệ thông tin - Kỹ thuật bảo mật - Dịch vụ đóng dấu thời gian Phần 3: Các cơ chế sản xuất các token liên kết-Timestamp services - Part 3: Mechanisms producing linked tokens |
|||
Original document (PDF)
Download
Relations map
Click a document to open. A red border = a relation that changes validity.
Translations
This document is available in the following languages: