This section defines the functional and technical requirements for the use of electronic and digital signatures in the registration of compliance documents. These specifications shall be implemented by a Data Registry as a condition of approval of the Data Registry by the Commission.
- Authorized Users of Data Registries who must sign Compliance Documents either as the Documentation Author, or Field Technician, or as the Registration Signer (responsible person).
- Registration Providers who must implement the electronic and digital signature specifications into the Data Registry user interface to provide Electronic Signature capabilities to the Authorized Users of the Data Registry, and must append their digital signature to all registered compliance documents created in their Data Registry.
- Commission Compliance Document Repository which must receive Registered Compliance Documents and Compliance Registration Packages transmitted from the Data Registries and will process the digital signature to validate the sender and the contents.
- Persons or Software Entities who Validate Electronic Documents who may receive electronic copies of registered documents made available by the Data Registries and will process the digital signature to validate the sender and the contents.
- Compliance Software Tools that export Compliance Documents and Compliance Registration Packages for transmittal to the Data Registries that must subsequently be electronically signed and registered in the Data Registry.
The electronic and digital signature requirements of the Data Registry consist of the following major functions:
The Data Registry shall provide electronic signature capability to authorized users.
The Data Registry shall ensure that compliance documents are complete and the data entered conforms to the data validation rules for the applicable document prior to making the documents available for registration signing.
The Data Registry shall provide functionality for authorized users to select, review, and sign compliance documents as a Documentation Author, Field Technician, or Registration Signer.
The Data Registry shall apply the Registration Provider's Digital Signature to compliance documents electronically signed by the registration signer when concluding the document registration procedure in the Data Registry. The Registration Provider's digital signature shall be based on a digital certificate issued by a certificate authority approved by the California Secretary of State.
The function of the Registration Provider's digital certificate is to provide verification from an approved certificate authority that the document came from the Registration Provider's Data Registry and to provide automated document verification to persons or agencies that receive electronic submittals of these registered documents.
Additional guidance for use of digital signatures and digital certificates shall be given in the Data Registry Requirements Manual.
The Data Registry, upon completion of the registration procedure, shall immediately and automatically transmit a copy of the completed Registered Compliance Document and Compliance Registration Package to the Commission Compliance Document Repository, which will process the Registration Provider's digital signature to validate the sender and the compliance document contents.
Additional guidance for use of digital certificates for validation of document authenticity shall be given in the Data Registry Requirements Manual.
The Data Registry shall retain a copy of the completed Registered Compliance Document and Compliance Registration Packageand make the Registered Compliance Document available for use by authorized users of the registry who may access a copy of the registered document and may subsequently process the Registration Provider's digital signature to verify the sender and the compliance document contents.
The Data Registry shall process the completed Compliance Registration Package from Compliance software tools approved by the Energy Commission for use in the Compliance Document Registration process in accordance with the specifications in Section JA7.7.1.6.
If the Data Registry allows use of External Digital Data Sources (EDDS) as an alternative to keyed- in data input for document registration procedures, the requirements in Section JA7.7.1.2 shall be met.
Additional guidance for receiving and processing output from compliance software and EDDS may be given in the Data Registry Requirements Manual.
There are four categories of users who will participate in the electronic and digital signature functionality:
This is a heterogeneous category composed of HERS Raters, building designers, building contractors, installation contractors, energy consultants, homeowners, and others.
This category consists of each approved Registration Provider.
These users will need to apply decryption processing using the digital certificate to identify the sender and verify the contents of the received Registered Compliance Document and Compliance Registration Package. The Commission Compliance Document Repository is a main user in this category. Also, users who take advantage of digital signature automated verification capabilities to verify the authenticity of Registered Compliance Document and Compliance Registration Package received as electronic submittals from various other participants in the compliance documentation process will be another main user in this category.
Title 24 compliance software tools are the main users in this Category.
The electronic compliance documents exported from the compliance software tools that are approved by the Energy Commission must be formatted to provide a standardized location for the visible aspects of electronic signatures, digital signature appearances, and other aspects of registration information such as registration numbering, and registration date/time stamps.
The Data Registry shall be capable of appending the visible aspects of electronic and digital signatures and other required registration information to the correct locations in the signature blocks and footers on the imported compliance documents during the subsequent electronic signature and registration procedures.
The Data Registry shall implement the capability to append the visible aspects of the required document registration information to the signature blocks and footers on compliance documents in these locations.
Detailed guidance for appending the required document registration information may be described in the Data Registry Requirements Manual.
The digital signature technology including the hash algorithm and asymmetric key encryption used shall be consistent across all Data Registries because the Commission Compliance Document Repository will not support multiple approaches.
Detailed guidance for use of digital signature technology and digital certificates shall be given in the Data Registry Requirements manual.
All Data Registries shall utilize the same informational content, graphical layout and formatting unique to the applicable type of compliance document when displaying the completed compliance documents for review and signing as part of the registration process. These document layouts shall conform to the informational content, graphical layout and formatting approved by the Commission. Additional detailed guidance regarding informational content, graphical layout and formatting will be presented in the Data Registry Requirements Manual.
The Data Registry shall provide electronic signature capability to authorized users who have the role of Documentation Author, Field Technician, or Registration Signer. A Field Technician Signature is required only on registered Certificate of Acceptance Documentation. A Certificate of Acceptance document requires that there be both a Documentation Author signature and a Field Technician signature prior to registration signing. The Data Registry shall not register a Certificate of Acceptance document that has been recorded (or is expected to be recorded) by an Acceptance Test Technician Certification Provider.
The Data Registry shall check that compliance documents are complete and shall perform the required data validation for the document before making them available for signing and/or registering. Data must be validated with an XML schema approved by the Commission. Additional guidance for the data validation for each document shall be provided in the Data Registry Requirements Manual.
Any applicable error messages shall be posted indicating the actions necessary as prerequisite to completion of the registration process.
The Data Registry shall provide functionality for authorized users to select, review and sign compliance documents as a documentation author, field technician, or registration signer.
The Data Registry shall apply the Registration Provider digital signature to compliance documents electronically signed by the registration signer.
The Registration Provider shall ensure that PDF reader freeware can verify the digital signature of the registered PDF documents. The Registration Provider shall make available a procedure that allows users to securely acquire the digital certificate issued by the Data Registry's approved certificate authority. The procedure may add the certificate to the user's local root certificate store if necessary.
“Digitally signed by [Data Registry Provider’s name]. This digital signature is provided in order to secure the content of this registered document, and in no way implies Registration Provider responsibility for the accuracy of the information".
Other information such as graphic(s), watermark(s), date, or time stamps are not required for the digital signature appearance.
The Data Registry, upon completion of the registration procedure, shall immediately and automatically transmit a copy of the completed Registered Compliance Document and Compliance Registration Package to the Commission Compliance Document Repository which will process the Registration Provider's digital signature using the Registration Provider's digital certificate to verify the sender and the compliance document contents.
The Registration Provider shall retain a copy of the completed Registered Compliance Document and Compliance Registration Package. The Registration Provider shall make the Registered Compliance Document available for use by authorized users of the registry who may print a hard copy, or access an electronic copy of the registered document and may subsequently process the Registration Provider's digital signature using their digital certificate to verify the sender and the compliance document contents.
The Data Registry shall process the Compliance Registration Package transmitted from Title 24, Part 6 performance compliance software tools approved by the Energy Commission, and shall process transmittals from external digital data sources described in Section JA7.7.1.2 when approved in accordance with the requirements in Section JA7.8 for use in compliance document registration processes.
There may be alternate means by which Compliance Software tools or other external digital data sources communicate with Data Registries, such as by data streaming. Use of such alternate means shall not be allowed unless approved by the Energy Commission.