payShield 10K Installation and User Guide
© Thales Group
Page 69
All Rights Reserved
For example, if the security domain is shared over 8 Smart Cards, and the quorum is set to 3, any three
security officers out of the eight would need to be present to rebuild the Customer Trust Authority (CTA).
If the security domain is
shared over just 3 Smart Cards
, for example, there is less flexibility. The
same
three security officers
would need to be readily available.
•
Total Number of Security Domain Shares:
This is the number of Smart Cards onto which the CTA shares will be distributed. Valid values are 3-9.
•
Size of Security Domain Shares Quorum:
This is the number of Smart Cards holding CTA shares that must be present in order to reassemble a CTA
to perform various operations (including commissioning a payShield). The minimum value is 3.
•
Country, State, Locality, Organization, Common Name, Unit, Email:
These are parameters that are included in the X.509 certificate corresponding to the CTA. The Common
Name is the only required parameter and should concisely describe the security domain.