Solaris Trusted Extensions Administrator's Procedures
只搜尋這本書
查看這本書:
以 PDF 格式下載這本書 (2609 KB)
Numbers and Symbols
-o nobanner option to lp command ( Index Term Link )
A
access, See computer access
access policy
devices ( Index Term Link )
Discretionary Access Control (DAC) ( Index Term Link ) ( Index Term Link )
Mandatory Access Control (MAC) ( Index Term Link )
accessing
Admin Editor action ( Index Term Link )
administrative tools ( Index Term Link )
audit records by label ( Index Term Link )
devices ( Index Term Link )
global zone ( Index Term Link )
home directories ( Index Term Link )
printers ( Index Term Link )
remote multilevel desktop ( Index Term Link )
Solaris Management Console ( Index Term Link )
trusted CDE actions ( Index Term Link )
ZFS dataset mounted in lower-level zone from higher-level zone ( Index Term Link )
account locking, preventing ( Index Term Link )
accounts
See roles
See also users
accreditation checks ( Index Term Link )
accreditation ranges, label_encodings file ( Index Term Link )
actions
See also individual actions by name
adding new Trusted CDE actions ( Index Term Link )
Admin Editor ( Index Term Link )
Device Allocation Manager ( Index Term Link )
list of trusted CDE ( Index Term Link )
Name Service Switch ( Index Term Link )
Print Manager ( Index Term Link )
restricted by rights profiles ( Index Term Link )
use differences between CDE and Trusted CDE ( Index Term Link )
add_allocatable command ( Index Term Link )
Add Allocatable Device action ( Index Term Link )
Admin Editor action ( Index Term Link )
opening ( Index Term Link )
ADMIN_HIGH label ( Index Term Link )
ADMIN_LOW label
lowest label ( Index Term Link )
protecting administrative files ( Index Term Link )
administering
account locking ( Index Term Link )
assigning device authorizations ( Index Term Link )
audio device to play music ( Index Term Link )
auditing in Trusted Extensions ( Index Term Link )
changing label of information ( Index Term Link )
convenient authorizations for users ( Index Term Link )
device allocation ( Index Term Link )
device authorizations ( Index Term Link )
devices ( Index Term Link ) ( Index Term Link )
file systems
mounting ( Index Term Link )
overview ( Index Term Link )
troubleshooting ( Index Term Link )
files
backing up ( Index Term Link )
restoring ( Index Term Link )
from the global zone ( Index Term Link )
hiding labels from users ( Index Term Link )
labeled printing ( Index Term Link )
LDAP ( Index Term Link )
mail ( Index Term Link )
multilevel ports ( Index Term Link )
network in Trusted Extensions ( Index Term Link )
network of users ( Index Term Link )
PostScript printing ( Index Term Link )
printing in Trusted Extensions ( Index Term Link )
printing interoperability with Trusted Solaris 8 ( Index Term Link )
quick reference for administrators ( Index Term Link )
remote host database ( Index Term Link )
remote host templates ( Index Term Link )
remotely ( Index Term Link )
remotely from command line ( Index Term Link )
remotely with dtappsession ( Index Term Link )
remotely with Solaris Management Console ( Index Term Link ) ( Index Term Link )
routes with security attributes ( Index Term Link )
serial line for login ( Index Term Link )
sharing file systems ( Index Term Link )
startup files for users ( Index Term Link )
Sun Ray printing ( Index Term Link )
system files ( Index Term Link )
third-party software ( Index Term Link )
timeout when relabeling information ( Index Term Link )
trusted network databases ( Index Term Link )
trusted networking ( Index Term Link )
unlabeled printing ( Index Term Link )
user privileges ( Index Term Link )
users ( Index Term Link ) ( Index Term Link )
zones ( Index Term Link )
zones from Trusted JDS ( Index Term Link )
Administering Trusted Extensions Remotely (Task Map) ( Index Term Link )
administrative actions
See also actions
accessing ( Index Term Link )
in CDE ( Index Term Link )
in Trusted_Extensions folder ( Index Term Link )
list of trusted CDE ( Index Term Link )
naming services ( Index Term Link )
starting remotely ( Index Term Link ) ( Index Term Link )
trusted ( Index Term Link )
administrative labels ( Index Term Link )
administrative roles, See roles
Administrative Roles tool ( Index Term Link )
administrative tools
accessing ( Index Term Link )
commands ( Index Term Link )
description ( Index Term Link )
Device Allocation Manager ( Index Term Link )
in Trusted_Extensions folder ( Index Term Link )
label builder ( Index Term Link )
Labeled Zone Manager ( Index Term Link )
Solaris Management Console ( Index Term Link ) ( Index Term Link )
Trusted CDE actions ( Index Term Link )
txzonemgr script ( Index Term Link )
allocate command ( Index Term Link )
Allocate Device authorization ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
allocate error state, correcting ( Index Term Link )
allocating, using Device Allocation Manager ( Index Term Link )
Always Print Banner checkbox ( Index Term Link )
applications
evaluating for security ( Index Term Link )
installing ( Index Term Link )
trusted and trustworthy ( Index Term Link )
assigning
editor as the trusted editor ( Index Term Link )
privileges to users ( Index Term Link )
rights profiles ( Index Term Link )
Assume Role menu item ( Index Term Link )
assuming, roles ( Index Term Link )
atohexlabel command ( Index Term Link ) ( Index Term Link )
audio devices
automatically starting an audio player ( Index Term Link )
preventing remote allocation ( Index Term Link )
audit_class file, action for editing ( Index Term Link )
Audit Classes action ( Index Term Link )
audit classes for Trusted Extensions, list of new X audit classes ( Index Term Link )
Audit Control action ( Index Term Link )
audit_control file, action for editing ( Index Term Link )
audit_event file ( Index Term Link )
Audit Events action ( Index Term Link )
audit events for Trusted Extensions, list of ( Index Term Link )
audit policy in Trusted Extensions ( Index Term Link )
audit records in Trusted Extensions, policy ( Index Term Link )
Audit Review profile, reviewing audit records ( Index Term Link )
Audit Startup action ( Index Term Link )
audit_startup command, action for editing ( Index Term Link )
Audit Tasks of the System Administrator ( Index Term Link )
audit tokens for Trusted Extensions
label token ( Index Term Link )
list of ( Index Term Link )
xatom token ( Index Term Link )
xclient token ( Index Term Link )
xcolormap token ( Index Term Link )
xcursor token ( Index Term Link )
xfont token ( Index Term Link )
xgc token ( Index Term Link )
xpixmap token ( Index Term Link )
xproperty token ( Index Term Link )
xselect token ( Index Term Link )
xwindow token ( Index Term Link )
auditconfig command ( Index Term Link )
auditing in Trusted Extensions
additional audit events ( Index Term Link )
additional audit policies ( Index Term Link )
additional audit tokens ( Index Term Link )
additions to existing auditing commands ( Index Term Link )
differences from Solaris auditing ( Index Term Link )
reference ( Index Term Link )
roles for administering ( Index Term Link )
security administrator tasks ( Index Term Link )
system administrator tasks ( Index Term Link )
tasks ( Index Term Link )
X audit classes ( Index Term Link )
auditreduce command ( Index Term Link )
authorizations
adding new device authorizations ( Index Term Link )
Allocate Device ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
assigning ( Index Term Link )
assigning device authorizations ( Index Term Link )
authorizing a user or role to change label ( Index Term Link )
Configure Device Attributes ( Index Term Link )
convenient for users ( Index Term Link )
creating customized device authorizations ( Index Term Link )
creating local and remote device authorizations ( Index Term Link )
customizing for devices ( Index Term Link )
granted ( Index Term Link )
Print Postscript ( Index Term Link )
Print PostScript ( Index Term Link )
profiles that include device allocation authorizations ( Index Term Link )
Revoke or Reclaim Device ( Index Term Link ) ( Index Term Link )
solaris.print.nobanner ( Index Term Link )
solaris.print.ps ( Index Term Link )
authorizing
device allocation ( Index Term Link )
PostScript printing ( Index Term Link )
unlabeled printing ( Index Term Link )
automount command ( Index Term Link )
B
Backing Up, Sharing, and Mounting Labeled Files (Task Map) ( Index Term Link )
banner pages
description of labeled ( Index Term Link )
difference from trailer page ( Index Term Link )
printing without labels ( Index Term Link )
typical ( Index Term Link )
body pages
description of labeled ( Index Term Link )
unlabeled for all users ( Index Term Link )
unlabeled for specific users ( Index Term Link )
C
cascade printing ( Index Term Link )
CD-ROM drives
accessing ( Index Term Link )
playing music automatically ( Index Term Link )
CDE actions, See actions
Change Password menu item
description ( Index Term Link )
using to change root password ( Index Term Link )
changing
IDLETIME keyword ( Index Term Link )
labels by authorized users ( Index Term Link )
rules for label changes ( Index Term Link )
security level of data ( Index Term Link )
Selection Confirmer defaults ( Index Term Link )
system security defaults ( Index Term Link )
user privileges ( Index Term Link )
Check Encodings action ( Index Term Link )
Check TN Files action ( Index Term Link )
chk_encodings command ( Index Term Link )
action for invoking ( Index Term Link )
choosing, See selecting
classification label component ( Index Term Link )
clearances, label overview ( Index Term Link )
Clone Zone action ( Index Term Link )
colors, indicating label of workspace ( Index Term Link )
commands
executing with privilege ( Index Term Link )
troubleshooting networking ( Index Term Link )
trusted_edit trusted editor ( Index Term Link )
commercial applications, evaluating ( Index Term Link )
Common Tasks in Trusted Extensions (Task Map) ( Index Term Link )
compartment label component ( Index Term Link )
component definitions, label_encodings file ( Index Term Link )
computer access
administrator responsibilities ( Index Term Link )
restricting ( Index Term Link )
Computers and Networks tool
adding known hosts ( Index Term Link ) ( Index Term Link )
modifying tnrhdb database ( Index Term Link )
Computers and Networks tool set ( Index Term Link )
Configure Device Attributes authorization ( Index Term Link )
Configure Selection Confirmation action ( Index Term Link )
Configure Zone action ( Index Term Link )
configuring
audio device to play music ( Index Term Link )
auditing ( Index Term Link )
authorizations for devices ( Index Term Link )
devices ( Index Term Link )
labeled printing ( Index Term Link )
routes with security attributes ( Index Term Link )
serial line for login ( Index Term Link )
startup files for users ( Index Term Link )
trusted network ( Index Term Link )
Configuring Labeled Printing (Task Map) ( Index Term Link )
Configuring Routes and Checking Network Information in Trusted Extensions (Task Map) ( Index Term Link )
Configuring Trusted Network Databases (Task Map) ( Index Term Link )
controlling, See restricting
.copy_files file
description ( Index Term Link )
setting up for users ( Index Term Link ) ( Index Term Link )
startup file ( Index Term Link )
Copy Zone action ( Index Term Link )
Create LDAP Client action ( Index Term Link )
creating
authorizations for devices ( Index Term Link )
home directories ( Index Term Link )
customizing
device authorizations ( Index Term Link )
label_encodings file ( Index Term Link )
unlabeled printing ( Index Term Link )
user accounts ( Index Term Link )
Customizing Device Authorizations in Trusted Extensions (Task Map) ( Index Term Link )
Customizing User Environment for Security (Task Map) ( Index Term Link )
cut and paste, and labels ( Index Term Link )
cutting and pasting, configuring rules for label changes ( Index Term Link )
D
DAC, See discretionary access control (DAC)
databases
devices ( Index Term Link )
in LDAP ( Index Term Link )
trusted network ( Index Term Link )
datasets, See ZFS
deallocate command ( Index Term Link )
deallocating, forcing ( Index Term Link )
debugging, See troubleshooting
desktops
accessing multilevel remotely ( Index Term Link )
logging in to a failsafe session ( Index Term Link )
workspace color changes ( Index Term Link )
/dev/kmem kernel image file, security violation ( Index Term Link )
developer responsibilities ( Index Term Link )
device allocation
authorizing ( Index Term Link )
overview ( Index Term Link )
preventing File Manager display ( Index Term Link )
profiles that include allocation authorizations ( Index Term Link )
Device Allocation Manager
administrative tool ( Index Term Link )
description ( Index Term Link )
use by administrators ( Index Term Link )
device-clean scripts
adding to devices ( Index Term Link )
requirements ( Index Term Link )
device databases, action for editing ( Index Term Link )
devices
access policy ( Index Term Link )
accessing ( Index Term Link )
adding customized authorizations ( Index Term Link )
adding device_clean script ( Index Term Link )
administering ( Index Term Link )
administering with Device Allocation Manager ( Index Term Link )
allocating ( Index Term Link )
automatically starting an audio player ( Index Term Link )
configuring devices ( Index Term Link )
configuring serial line ( Index Term Link )
creating new authorizations ( Index Term Link )
in Trusted Extensions ( Index Term Link )
policy defaults ( Index Term Link )
preventing remote allocation of audio ( Index Term Link )
protecting ( Index Term Link )
protecting nonallocatable ( Index Term Link )
reclaiming ( Index Term Link )
setting label range for nonallocatable ( Index Term Link )
setting policy ( Index Term Link )
setting up audio ( Index Term Link )
troubleshooting ( Index Term Link )
using ( Index Term Link )
dfstab file
action for editing ( Index Term Link )
for public zone ( Index Term Link )
differences
administrative interfaces in Trusted Extensions ( Index Term Link )
between Trusted Extensions and Solaris auditing ( Index Term Link )
between Trusted Extensions and Solaris OS ( Index Term Link )
defaults in Trusted Extensions ( Index Term Link )
extending Solaris interfaces ( Index Term Link )
limited options in Trusted Extensions ( Index Term Link )
directories
accessing lower-level ( Index Term Link )
authorizing a user or role to change label of ( Index Term Link )
mounting ( Index Term Link )
sharing ( Index Term Link )
discretionary access control (DAC) ( Index Term Link )
diskettes, accessing ( Index Term Link )
displaying
labels of file systems in labeled zone ( Index Term Link )
status of every zone ( Index Term Link )
DOI, remote host templates ( Index Term Link )
dominance of labels ( Index Term Link )
Downgrade DragNDrop or CutPaste Info authorization ( Index Term Link )
Downgrade File Label authorization ( Index Term Link )
downgrading labels, configuring rules for selection confirmer ( Index Term Link )
DragNDrop or CutPaste without viewing contents authorization ( Index Term Link )
dtappsession command ( Index Term Link )
dtsession command, running updatehome ( Index Term Link )
dtterm terminal, forcing the sourcing of .profile ( Index Term Link )
dtwm command ( Index Term Link )
E
Edit Encodings action ( Index Term Link )
editing
system files ( Index Term Link )
using trusted editor ( Index Term Link )
enabling
DOI different from 1 ( Index Term Link )
keyboard shutdown ( Index Term Link )
/etc/default/kbd file, how to edit ( Index Term Link )
/etc/default/login file, how to edit ( Index Term Link )
/etc/default/passwd file, how to edit ( Index Term Link )
/etc/default/print file ( Index Term Link )
/etc/dfs/dfstab file ( Index Term Link )
/etc/dfs/dfstab file for public zone ( Index Term Link )
/etc/dt/config/sel_config file ( Index Term Link ) ( Index Term Link )
/etc/hosts file ( Index Term Link ) ( Index Term Link )
/etc/motd file, action for editing ( Index Term Link )
/etc/nsswitch.conf file ( Index Term Link )
/etc/resolv.conf file ( Index Term Link )
/etc/rmmount.conf file ( Index Term Link ) ( Index Term Link )
/etc/security/audit_class file ( Index Term Link )
/etc/security/audit_control file ( Index Term Link )
/etc/security/audit_event file ( Index Term Link )
/etc/security/audit_startup file ( Index Term Link )
/etc/security/policy.conf file
defaults ( Index Term Link )
enabling PostScript printing ( Index Term Link )
how to edit ( Index Term Link )
modifying ( Index Term Link )
/etc/security/tsol/label_encodings file ( Index Term Link )
evaluating programs for security ( Index Term Link )
exporting, See sharing
F
failsafe session, logging in ( Index Term Link )
fallback mechanism
for remote hosts ( Index Term Link )
in tnrhdb ( Index Term Link )
using for network configuration ( Index Term Link )
File Manager, preventing display after device allocation ( Index Term Link )
file systems
mounting in global and labeled zones ( Index Term Link )
NFS mounts ( Index Term Link )
NFSv3 ( Index Term Link )
sharing ( Index Term Link )
sharing in global and labeled zones ( Index Term Link )
files
accessing from dominating labels ( Index Term Link )
authorizing a user or role to change label of ( Index Term Link )
backing up ( Index Term Link )
.copy_files ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
editing with trusted editor ( Index Term Link )
/etc/default/kbd ( Index Term Link )
/etc/default/login ( Index Term Link )
/etc/default/passwd ( Index Term Link )
/etc/default/print ( Index Term Link )
/etc/dfs/dfstab ( Index Term Link )
/etc/dt/config/sel_config ( Index Term Link )
/etc/motd ( Index Term Link )
/etc/nsswitch.conf ( Index Term Link )
/etc/resolv.conf ( Index Term Link )
/etc/rmmount.conf ( Index Term Link )
/etc/security/audit_class ( Index Term Link )
/etc/security/audit_control ( Index Term Link )
/etc/security/audit_event ( Index Term Link )
/etc/security/audit_startup ( Index Term Link )
/etc/security/policy.conf ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
/etc/security/tsol/label_encodings ( Index Term Link )
getmounts ( Index Term Link )
getzonelabels ( Index Term Link )
.gtkrc-mine ( Index Term Link )
.link_files ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
loopback mounting ( Index Term Link )
office-install-directory/VCL.xcu ( Index Term Link )
policy.conf ( Index Term Link )
PostScript ( Index Term Link )
preventing access from dominating labels ( Index Term Link )
relabeling privileges ( Index Term Link )
restoring ( Index Term Link )
sel_config file ( Index Term Link )
startup ( Index Term Link )
/usr/dt/config/sel_config ( Index Term Link ) ( Index Term Link )
/usr/lib/lp/postscript/tsol_separator.ps ( Index Term Link )
/usr/sbin/txzonemgr ( Index Term Link ) ( Index Term Link )
VCL.xcu ( Index Term Link )
files and file systems
mounting ( Index Term Link )
naming ( Index Term Link )
sharing ( Index Term Link )
finding
label equivalent in hexadecimal ( Index Term Link )
label equivalent in text format ( Index Term Link )
Firefox, lengthening timeout when relabeling ( Index Term Link )
floppies, See diskettes
floppy disks, See diskettes
Front Panel, Device Allocation Manager ( Index Term Link )
G
gateways
accreditation checks ( Index Term Link )
example of ( Index Term Link )
getlabel command ( Index Term Link )
getmounts script ( Index Term Link )
Getting Started as a Trusted Extensions Administrator (Task Map) ( Index Term Link )
getzonelabels script ( Index Term Link )
getzonepath command ( Index Term Link )
global zone
difference from labeled zones ( Index Term Link )
entering ( Index Term Link )
exiting ( Index Term Link )
remote login by users ( Index Term Link )
GNOME ToolKit (GTK) library, lengthening timeout when relabeling ( Index Term Link )
groups
deletion precautions ( Index Term Link )
security requirements ( Index Term Link )
.gtkrc-mine file ( Index Term Link )
H
Handling Devices in Trusted Extensions (Task Map) ( Index Term Link )
Handling Other Tasks in the Solaris Management Console (Task Map) ( Index Term Link )
hextoalabel command ( Index Term Link ) ( Index Term Link )
hiding labels from users ( Index Term Link )
home directories
accessing ( Index Term Link )
creating ( Index Term Link )
host types
networking ( Index Term Link ) ( Index Term Link )
remote host templates ( Index Term Link )
table of templates and protocols ( Index Term Link )
hosts
assigning a template ( Index Term Link ) ( Index Term Link )
assigning to security template ( Index Term Link )
entering in network files ( Index Term Link )
networking concepts ( Index Term Link )
hot key, regaining control of desktop focus ( Index Term Link )
I
icon visibility
in the File Manager ( Index Term Link )
in the Workspace Menu ( Index Term Link )
IDLECMD keyword, changing default ( Index Term Link )
IDLETIME keyword, changing default ( Index Term Link )
ifconfig command ( Index Term Link ) ( Index Term Link )
importing, software ( Index Term Link )
Initialize Zone for LDAP action ( Index Term Link )
Install Zone action ( Index Term Link )
interfaces
assigning to security template ( Index Term Link )
verifying they are up ( Index Term Link )
internationalizing, See localizing
interoperability, Trusted Solaris 8 and printing ( Index Term Link )
IP addresses
fallback mechanism in tnrhdb ( Index Term Link )
in tnrhdb database ( Index Term Link )
in tnrhdb file ( Index Term Link )
J
Java archive (JAR) files, installing ( Index Term Link )
K
key combinations, testing if grab is trusted ( Index Term Link )
keyboard shutdown, enabling ( Index Term Link )
kmem kernel image file ( Index Term Link )
L
label audit token ( Index Term Link )
label_encodings file
action for editing and checking ( Index Term Link )
contents ( Index Term Link )
reference for labeled printing ( Index Term Link )
source of accreditation ranges ( Index Term Link )
label ranges
restricting printer label range ( Index Term Link )
setting on frame buffers ( Index Term Link )
setting on printers ( Index Term Link )
labeled printing
banner pages ( Index Term Link )
body pages ( Index Term Link )
PostScript files ( Index Term Link )
removing label ( Index Term Link )
removing PostScript restriction ( Index Term Link )
Sun Ray clients ( Index Term Link )
without banner page ( Index Term Link ) ( Index Term Link )
labeled zones, See zones
labels
See also label ranges
authorizing a user or role to change label of data ( Index Term Link )
classification component ( Index Term Link )
compartment component ( Index Term Link )
configuring rules for label changes ( Index Term Link )
default in remote host templates ( Index Term Link )
described ( Index Term Link )
determining text equivalents ( Index Term Link )
displaying in hexadecimal ( Index Term Link )
displaying labels of file systems in labeled zone ( Index Term Link )
dominance ( Index Term Link )
downgrading and upgrading ( Index Term Link )
hiding from users ( Index Term Link )
of processes ( Index Term Link )
of user processes ( Index Term Link )
on printer output ( Index Term Link )
overview ( Index Term Link )
printing without page labels ( Index Term Link )
relationships ( Index Term Link )
repairing in internal databases ( Index Term Link )
troubleshooting ( Index Term Link )
well-formed ( Index Term Link )
LDAP
action for creating global zone clients ( Index Term Link )
displaying entries ( Index Term Link )
naming service for Trusted Extensions ( Index Term Link )
starting ( Index Term Link )
stopping ( Index Term Link )
troubleshooting ( Index Term Link )
Trusted Extensions databases ( Index Term Link )
lengthening timeout, for relabeling ( Index Term Link )
limiting, defined hosts on the network ( Index Term Link )
.link_files file
description ( Index Term Link )
setting up for users ( Index Term Link )
startup file ( Index Term Link )
list_devices command ( Index Term Link )
localizing, changing labeled printer output ( Index Term Link )
login
by roles ( Index Term Link )
configuring serial line ( Index Term Link )
remote by roles ( Index Term Link )
logout, requiring ( Index Term Link )
M
MAC, See mandatory access control (MAC)
mail
administering ( Index Term Link )
implementation in Trusted Extensions ( Index Term Link )
multilevel ( Index Term Link )
man pages, quick reference for Trusted Extensions administrators ( Index Term Link )
managing, See administering
Managing Devices in Trusted Extensions (Task Map) ( Index Term Link )
Managing Printing in Trusted Extensions (Task Map) ( Index Term Link )
Managing Software in Trusted Extensions (Tasks) ( Index Term Link )
Managing Trusted Networking (Task Map) ( Index Term Link )
Managing Users and Rights With the Solaris Management Console (Task Map) ( Index Term Link )
Managing Zones (Task Map) ( Index Term Link )
mandatory access control (MAC)
enforcing on the network ( Index Term Link )
in Trusted Extensions ( Index Term Link )
maximum labels, remote host templates ( Index Term Link )
minimum labels, remote host templates ( Index Term Link )
MLPs, See multilevel ports (MLPs)
modifying, sel_config file ( Index Term Link )
motd file, action for editing ( Index Term Link )
mounting
file systems ( Index Term Link )
files by loopback mounting ( Index Term Link )
NFSv3 file systems ( Index Term Link )
overview ( Index Term Link )
troubleshooting ( Index Term Link )
ZFS dataset on labeled zone ( Index Term Link )
Mozilla, lengthening timeout when relabeling ( Index Term Link )
multiheaded system, trusted stripe ( Index Term Link )
multilevel mounts, NFS protocol versions ( Index Term Link )
multilevel ports (MLPs)
administering ( Index Term Link )
example of NFSv3 MLP ( Index Term Link )
example of web proxy MLP ( Index Term Link )
multilevel printing
accessing by print client ( Index Term Link )
configuring ( Index Term Link )
Sun Ray clients ( Index Term Link )
N
Name Service Switch action ( Index Term Link ) ( Index Term Link )
names of file systems ( Index Term Link )
naming services
actions for managing ( Index Term Link )
databases unique to Trusted Extensions ( Index Term Link )
LDAP ( Index Term Link )
net_mac_aware privilege ( Index Term Link )
netstat command ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
network, See trusted network
network databases
action for checking ( Index Term Link )
description ( Index Term Link )
in LDAP ( Index Term Link )
network packets ( Index Term Link )
networking concepts ( Index Term Link )
NFS mounts
accessing lower-level directories ( Index Term Link )
in global and labeled zones ( Index Term Link )
nonallocatable devices
protecting ( Index Term Link )
setting label range ( Index Term Link )
nsswitch.conf file, action for editing ( Index Term Link )
O
office-install-directory/VCL.xcu ( Index Term Link )
OpenOffice, See StarOffice
P
packages, accessing the media ( Index Term Link )
passwords
assigning ( Index Term Link )
Change Password menu item ( Index Term Link ) ( Index Term Link )
changing for root ( Index Term Link )
changing user passwords ( Index Term Link )
storage ( Index Term Link )
testing if password prompt is trusted ( Index Term Link )
plabel command ( Index Term Link )
policy.conf file
changing defaults ( Index Term Link )
changing Trusted Extensions keywords ( Index Term Link )
defaults ( Index Term Link )
how to edit ( Index Term Link )
PostScript
enabling to print ( Index Term Link )
printing restrictions in Trusted Extensions ( Index Term Link )
preventing, See protecting
Print Manager action, Always Print Banner checkbox ( Index Term Link )
Print Postscript authorization ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
Print without Banner authorization ( Index Term Link ) ( Index Term Link )
Print without Label authorization ( Index Term Link )
printer output, See printing
printers, setting label range ( Index Term Link )
printing
adding conversion filters ( Index Term Link )
and label_encodings file ( Index Term Link )
authorizations for unlabeled output from a public system ( Index Term Link )
configuring for multilevel labeled output ( Index Term Link )
configuring for print client ( Index Term Link )
configuring for Sun Ray clients ( Index Term Link )
configuring labeled zone ( Index Term Link )
configuring labels and text ( Index Term Link )
configuring public print jobs ( Index Term Link )
in local language ( Index Term Link )
internationalizing labeled output ( Index Term Link )
interoperability with Trusted Solaris 8 ( Index Term Link )
labeling a Solaris print server ( Index Term Link )
localizing labeled output ( Index Term Link )
managing ( Index Term Link )
model scripts ( Index Term Link )
PostScript files ( Index Term Link )
PostScript restrictions in Trusted Extensions ( Index Term Link )
preventing labels on output ( Index Term Link )
public jobs from a Solaris print server ( Index Term Link )
removing PostScript restriction ( Index Term Link )
restricting label range ( Index Term Link )
using a Solaris print server ( Index Term Link )
without labeled banners and trailers ( Index Term Link ) ( Index Term Link )
without page labels ( Index Term Link ) ( Index Term Link )
privileges
changing defaults for users ( Index Term Link )
non-obvious reasons for requiring ( Index Term Link )
removing proc_info from basic set ( Index Term Link )
restricting users' ( Index Term Link )
when executing commands ( Index Term Link )
proc_info privilege, removing from basic set ( Index Term Link )
procedures, See tasks and task maps
processes
labels of ( Index Term Link )
labels of user processes ( Index Term Link )
preventing users from seeing others' processes ( Index Term Link )
profiles, See rights profiles
programs, See applications
protecting
devices ( Index Term Link ) ( Index Term Link )
devices from remote allocation ( Index Term Link )
file systems by using non-proprietary names ( Index Term Link )
files at lower labels from being accessed ( Index Term Link )
from access by arbitrary hosts ( Index Term Link )
information with labels ( Index Term Link )
labeled hosts from contact by arbitrary unlabeled hosts ( Index Term Link )
nonallocatable devices ( Index Term Link )
R
real UID of root, required for applications ( Index Term Link )
Reducing Printing Restrictions in Trusted Extensions (Task Map) ( Index Term Link )
regaining control of desktop focus ( Index Term Link )
regular users, See users
relabeling information ( Index Term Link )
remote administration
defaults ( Index Term Link )
methods ( Index Term Link )
remote host templates
assigning ( Index Term Link )
assigning to hosts ( Index Term Link )
creating ( Index Term Link )
tool for administering ( Index Term Link )
remote hosts, using fallback mechanism in tnrhdb ( Index Term Link )
Remote Login authorization ( Index Term Link )
remote multilevel desktop, accessing ( Index Term Link )
removable media, mounting ( Index Term Link )
remove_allocatable command ( Index Term Link )
removing, labels on printer output ( Index Term Link )
repairing, labels in internal databases ( Index Term Link )
resolv.conf file, action for editing ( Index Term Link )
Restart Zone action ( Index Term Link )
restoring control of desktop focus ( Index Term Link )
restricting
access to computer based on label ( Index Term Link )
access to devices ( Index Term Link )
access to global zone ( Index Term Link )
access to lower-level files ( Index Term Link )
access to printers with labels ( Index Term Link )
actions by rights profiles ( Index Term Link )
mounts of lower-level files ( Index Term Link )
printer access with labels ( Index Term Link )
printer label range ( Index Term Link )
remote access ( Index Term Link )
Revoke or Reclaim Device authorization ( Index Term Link ) ( Index Term Link )
rights, See rights profiles
rights profiles
assigning ( Index Term Link )
controlling the use of actions ( Index Term Link )
Convenient Authorizations ( Index Term Link )
with Allocate Device authorization ( Index Term Link )
with device allocation authorizations ( Index Term Link )
with new device authorizations ( Index Term Link )
Rights tool ( Index Term Link )
rmmount.conf file ( Index Term Link ) ( Index Term Link )
role workspace, global zone ( Index Term Link )
roles
administering auditing ( Index Term Link )
administering remotely ( Index Term Link ) ( Index Term Link )
assigning rights ( Index Term Link )
assuming ( Index Term Link ) ( Index Term Link )
creating ( Index Term Link )
leaving role workspace ( Index Term Link )
remote login ( Index Term Link )
role assumption from unlabeled host ( Index Term Link )
trusted application access ( Index Term Link )
workspaces ( Index Term Link )
root UID, required for applications ( Index Term Link )
route command ( Index Term Link ) ( Index Term Link )
routing ( Index Term Link )
accreditation checks ( Index Term Link )
commands in Trusted Extensions ( Index Term Link )
concepts ( Index Term Link )
example of ( Index Term Link )
static with security attributes ( Index Term Link )
tables ( Index Term Link ) ( Index Term Link )
using route command ( Index Term Link )
S
scripts
getmounts ( Index Term Link )
getzonelabels ( Index Term Link )
/usr/sbin/txzonemgr ( Index Term Link ) ( Index Term Link )
secure attention, key combination ( Index Term Link )
Security Administrator role
administering network of users ( Index Term Link )
administering PostScript restriction ( Index Term Link )
administering printer security ( Index Term Link )
assigning authorizations to users ( Index Term Link )
audit tasks ( Index Term Link )
configuring a device ( Index Term Link )
configuring serial line for login ( Index Term Link )
creating Convenient Authorizations rights profile ( Index Term Link )
enabling unlabeled body pages from a public system ( Index Term Link )
enforcing security ( Index Term Link )
modifying window configuration files ( Index Term Link )
protecting nonallocatable devices ( Index Term Link )
security administrators, See Security Administrator role
security attributes ( Index Term Link )
modifying defaults for all users ( Index Term Link )
modifying user defaults ( Index Term Link )
setting for remote hosts ( Index Term Link )
using in routing ( Index Term Link )
security information, on printer output ( Index Term Link )
security label set, remote host templates ( Index Term Link )
security mechanisms
extensible ( Index Term Link )
Solaris ( Index Term Link )
security policy
auditing ( Index Term Link )
training users ( Index Term Link )
users and devices ( Index Term Link )
security templates, See remote host templates
Security Templates tool ( Index Term Link ) ( Index Term Link )
assigning templates ( Index Term Link )
modifying tnrhdb ( Index Term Link ) ( Index Term Link )
using ( Index Term Link )
sel_config file ( Index Term Link )
action for editing ( Index Term Link )
configuring selection transfer rules ( Index Term Link )
selecting, audit records by label ( Index Term Link )
Selection Confirmer, changing defaults ( Index Term Link )
Selection Manager
changing timeout ( Index Term Link )
configuring rules for selection confirmer ( Index Term Link )
serial line, configuring for logins ( Index Term Link )
service management facility (SMF), Trusted Extensions service ( Index Term Link )
session range ( Index Term Link )
sessions, failsafe ( Index Term Link )
Set Daily Message action ( Index Term Link )
Set Default Routes action ( Index Term Link )
Set DNS Servers action ( Index Term Link )
setlabel command ( Index Term Link )
Share Filesystems action ( Index Term Link )
Share Logical Interface action ( Index Term Link )
Share Physical Interface action ( Index Term Link )
sharing, ZFS dataset from labeled zone ( Index Term Link )
Shut Down Zone action ( Index Term Link )
Shutdown authorization ( Index Term Link )
similarities
between Trusted Extensions and Solaris auditing ( Index Term Link )
between Trusted Extensions and Solaris OS ( Index Term Link )
single-label operation ( Index Term Link )
single-label printing, configuring for a zone ( Index Term Link )
smtnrhdb command ( Index Term Link )
smtnrhtp command ( Index Term Link )
smtnzonecfg command ( Index Term Link )
snoop command ( Index Term Link ) ( Index Term Link )
software
administering third-party ( Index Term Link )
importing ( Index Term Link )
installing Java programs ( Index Term Link )
Solaris Management Console
administering trusted network ( Index Term Link )
administering users ( Index Term Link )
Computers and Networks tool ( Index Term Link )
description of tools and toolboxes ( Index Term Link )
Security Templates tool ( Index Term Link ) ( Index Term Link )
starting ( Index Term Link )
toolboxes ( Index Term Link )
Trusted Network Zones tool ( Index Term Link )
Solaris OS
differences from Trusted Extensions ( Index Term Link )
differences from Trusted Extensions auditing ( Index Term Link )
similarities with Trusted Extensions ( Index Term Link )
similarities with Trusted Extensions auditing ( Index Term Link )
solaris.print.nobanner authorization ( Index Term Link ) ( Index Term Link )
solaris.print.ps authorization ( Index Term Link )
solaris.print.unlabeled authorization ( Index Term Link )
StarOffice, lengthening timeout when relabeling ( Index Term Link )
Start Zone action ( Index Term Link )
startup files, procedures for customizing ( Index Term Link )
Stop-A, enabling ( Index Term Link )
Sun Ray systems
configuring network printer ( Index Term Link )
enabling initial contact between client and server ( Index Term Link )
preventing users from seeing others' processes ( Index Term Link )
System Administrator role
adding device_clean script ( Index Term Link )
adding print conversion filters ( Index Term Link )
administering printers ( Index Term Link )
audit tasks ( Index Term Link )
enabling music to play automatically ( Index Term Link )
preventing File Manager display ( Index Term Link )
reclaiming a device ( Index Term Link )
reviewing audit records ( Index Term Link )
system files
editing ( Index Term Link ) ( Index Term Link )
Solaris /etc/default/print ( Index Term Link )
Solaris policy.conf ( Index Term Link )
Trusted Extensions sel_config ( Index Term Link )
Trusted Extensions tsol_separator.ps ( Index Term Link )
T
tape devices, accessing ( Index Term Link )
tar command ( Index Term Link )
tasks and task maps
Administering Trusted Extensions Remotely (Task Map) ( Index Term Link )
Audit Tasks of the Security Administrator ( Index Term Link )
Audit Tasks of the System Administrator ( Index Term Link )
Backing Up, Sharing, and Mounting Labeled Files (Task Map) ( Index Term Link )
Common Tasks in Trusted Extensions (Task Map) ( Index Term Link )
Configuring Labeled Printing (Task Map) ( Index Term Link )
Configuring Routes and Checking Network Information in Trusted Extensions (Task Map) ( Index Term Link )
Configuring Trusted Network Databases (Task Map) ( Index Term Link )
Customizing Device Authorizations in Trusted Extensions (Task Map) ( Index Term Link )
Customizing User Environment for Security (Task Map) ( Index Term Link )
Getting Started as a Trusted Extensions Administrator (Task Map) ( Index Term Link )
Handling Devices in Trusted Extensions (Task Map) ( Index Term Link )
Handling Other Tasks in the Solaris Management Console (Task Map) ( Index Term Link )
Managing Devices in Trusted Extensions (Task Map) ( Index Term Link )
Managing Printing in Trusted Extensions (Task Map) ( Index Term Link )
Managing Software in Trusted Extensions (Tasks) ( Index Term Link )
Managing Trusted Networking (Task Map) ( Index Term Link )
Managing Users and Rights With the Solaris Management Console ( Index Term Link )
Managing Zones (Task Map) ( Index Term Link )
Reducing Printing Restrictions in Trusted Extensions (Task Map) ( Index Term Link )
Troubleshooting the Trusted Network (Task Map) ( Index Term Link )
Using Devices in Trusted Extensions (Tasks Map) ( Index Term Link )
text label equivalents, determining ( Index Term Link )
Thunderbird, lengthening timeout when relabeling ( Index Term Link )
tnchkdb command
action for checking ( Index Term Link )
description ( Index Term Link )
summary ( Index Term Link )
tnctl command
description ( Index Term Link )
summary ( Index Term Link )
updating kernel cache ( Index Term Link )
using ( Index Term Link )
tnd command
description ( Index Term Link )
summary ( Index Term Link )
tninfo command
description ( Index Term Link )
summary ( Index Term Link )
using ( Index Term Link ) ( Index Term Link )
tnrhdb database
0.0.0.0 host address ( Index Term Link ) ( Index Term Link )
0.0.0.0 wildcard address ( Index Term Link )
action for checking ( Index Term Link )
adding to ( Index Term Link )
configuring ( Index Term Link )
fallback mechanism ( Index Term Link ) ( Index Term Link )
tool for administering ( Index Term Link )
wildcard address ( Index Term Link )
tnrhtp database
action for checking ( Index Term Link )
adding to ( Index Term Link )
tool for administering ( Index Term Link )
toolboxes, defined ( Index Term Link )
tools, See administrative tools
Tools subpanel, Device Allocation Manager ( Index Term Link )
trailer pages, See banner pages
translation, See localizing
troubleshooting
failed login ( Index Term Link )
LDAP ( Index Term Link )
mounted file systems ( Index Term Link )
network ( Index Term Link )
reclaiming a device ( Index Term Link )
repairing labels in internal databases ( Index Term Link )
trusted network ( Index Term Link )
verifying interface is up ( Index Term Link )
viewing ZFS dataset mounted in lower-level zone ( Index Term Link )
Troubleshooting the Trusted Network (Task Map) ( Index Term Link )
trusted actions, in CDE ( Index Term Link )
trusted applications, in a role workspace ( Index Term Link )
trusted_edit trusted editor ( Index Term Link )
trusted editor
assigning your favorite editor ( Index Term Link )
starting ( Index Term Link )
Trusted Extensions
differences from Solaris auditing ( Index Term Link )
differences from Solaris OS ( Index Term Link )
man pages quick reference ( Index Term Link )
quick reference to administration ( Index Term Link )
similarities with Solaris auditing ( Index Term Link )
similarities with Solaris OS ( Index Term Link )
Trusted Extensions DOI, enabling DOI different from 1 ( Index Term Link )
Trusted_Extensions folder
location ( Index Term Link )
using actions in ( Index Term Link )
using Admin Editor from ( Index Term Link )
trusted grab, key combination ( Index Term Link )
trusted network
0.0.0.0 tnrhdb entry ( Index Term Link )
action for setting default routes ( Index Term Link )
administering with Solaris Management Console ( Index Term Link )
checking syntax of files ( Index Term Link )
concepts ( Index Term Link )
default labeling ( Index Term Link )
editing local files ( Index Term Link )
example of routing ( Index Term Link )
host types ( Index Term Link )
labels and MAC enforcement ( Index Term Link )
using templates ( Index Term Link )
Trusted Network tools
description ( Index Term Link )
using ( Index Term Link )
Trusted Network Zones tool
configuring a multilevel port ( Index Term Link )
configuring a multilevel print server ( Index Term Link )
creating a multilevel port ( Index Term Link )
description ( Index Term Link ) ( Index Term Link )
trusted path attribute, when available ( Index Term Link )
Trusted Path menu, Assume Role ( Index Term Link )
trusted processes
in the window system ( Index Term Link )
starting actions ( Index Term Link )
trusted programs
adding ( Index Term Link )
defined ( Index Term Link )
trusted stripe
on multiheaded system ( Index Term Link )
warping pointer to ( Index Term Link )
trustworthy programs ( Index Term Link )
tsol_separator.ps file
configurable values ( Index Term Link )
customizing labeled printing ( Index Term Link )
U
unlabeled printing, configuring ( Index Term Link )
updatehome command ( Index Term Link ) ( Index Term Link )
Upgrade DragNDrop or CutPaste Info authorization ( Index Term Link )
Upgrade File Label authorization ( Index Term Link )
upgrading labels, configuring rules for selection confirmer ( Index Term Link )
User Accounts tool ( Index Term Link )
users
accessing devices ( Index Term Link ) ( Index Term Link )
accessing printers ( Index Term Link )
assigning authorizations to ( Index Term Link )
assigning labels ( Index Term Link )
assigning passwords ( Index Term Link )
assigning rights ( Index Term Link )
assigning roles to ( Index Term Link )
authorizations for ( Index Term Link )
Change Password menu item ( Index Term Link )
changing default privileges ( Index Term Link )
creating ( Index Term Link )
customizing environment ( Index Term Link )
deletion precautions ( Index Term Link )
labels of processes ( Index Term Link )
lengthening timeout when relabeling ( Index Term Link )
logging in remotely to the global zone ( Index Term Link )
logging in to a failsafe session ( Index Term Link )
modifying security defaults ( Index Term Link )
modifying security defaults for all users ( Index Term Link )
planning for ( Index Term Link )
preventing account locking ( Index Term Link )
preventing from seeing others' processes ( Index Term Link )
printing ( Index Term Link )
removing some privileges ( Index Term Link )
restoring control of desktop focus ( Index Term Link )
security precautions ( Index Term Link )
security training ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
session range ( Index Term Link )
setting up skeleton directories ( Index Term Link )
startup files ( Index Term Link )
using .copy_files file ( Index Term Link )
using .link_files file ( Index Term Link )
using devices ( Index Term Link )
Using Devices in Trusted Extensions (Task Map) ( Index Term Link )
/usr/dt/bin/trusted_edit trusted editor ( Index Term Link )
/usr/dt/config/sel_config file ( Index Term Link ) ( Index Term Link )
/usr/lib/lp/postscript/tsol_separator.ps file, labeling printer output ( Index Term Link )
/usr/local/scripts/getmounts script ( Index Term Link )
/usr/local/scripts/getzonelabels script ( Index Term Link )
/usr/sbin/txzonemgr script ( Index Term Link ) ( Index Term Link )
utadm command, default Sun Ray server configuration ( Index Term Link )
V
VCL.xcu file ( Index Term Link )
verifying
interface is up ( Index Term Link )
syntax of network databases ( Index Term Link )
viewing, See accessing
virtual network computing (vnc), See Xvnc systems running Trusted Extensions
W
well-formed labels ( Index Term Link )
wildcard address, See fallback mechanism
window manager ( Index Term Link )
window system, trusted processes ( Index Term Link )
workspaces
color changes ( Index Term Link )
colors indicating label of ( Index Term Link )
global zone ( Index Term Link )
X
X audit classes ( Index Term Link )
xatom audit token ( Index Term Link )
xc audit class ( Index Term Link )
xclient audit token ( Index Term Link )
xcolormap audit token ( Index Term Link )
xcursor audit token ( Index Term Link )
xfont audit token ( Index Term Link )
xgc audit token ( Index Term Link )
xp audit class ( Index Term Link )
xpixmap audit token ( Index Term Link )
xproperty audit token ( Index Term Link )
xs audit class ( Index Term Link )
xselect audit token ( Index Term Link )
Xtsolusersession script ( Index Term Link )
Xvnc systems running Trusted Extensions
remote access to ( Index Term Link ) ( Index Term Link )
xwindow audit token ( Index Term Link )
xx audit class ( Index Term Link )
Z
ZFS
adding dataset to labeled zone ( Index Term Link )
mounting dataset read-write on labeled zone ( Index Term Link )
viewing mounted dataset read-only from higher-level zone ( Index Term Link )
/zone/public/etc/dfs/dfstab file ( Index Term Link )
Zone Terminal Console action ( Index Term Link )
zones
action for cloning ( Index Term Link )
action for configuring ( Index Term Link )
action for copying ( Index Term Link )
action for initializing ( Index Term Link )
action for installing ( Index Term Link )
action for restarting ( Index Term Link )
action for sharing logical interface ( Index Term Link )
action for sharing physical interface ( Index Term Link )
action for shutting down ( Index Term Link )
action for starting ( Index Term Link )
action for viewing from console ( Index Term Link )
administering ( Index Term Link )
administering from Trusted JDS ( Index Term Link )
creating MLP ( Index Term Link )
creating MLP for NFSv3 ( Index Term Link )
displaying labels of file systems ( Index Term Link )
displaying status ( Index Term Link )
global ( Index Term Link )
in Trusted Extensions ( Index Term Link )
managing ( Index Term Link )
net_mac_aware privilege ( Index Term Link )
tool for labeling ( Index Term Link )