Trusted Extensions Configuration and Administration

Exit Print View

Updated: July 2014
 
 

No Privilege Overrides for MAC Read-Write Policy

The MAC policy for reading and writing files has no privilege overrides. Single-level datasets can only be mounted read-write if the label of the zone equals the label of the dataset. For read-only mounts, the zone label must dominate the dataset label. For multilevel datasets, all files and directories must be dominated by the mlslabel property, which defaults to ADMIN_HIGH. For multilevel datasets, MAC policy is enforced at the file and directory level. MAC policy enforcement is invisible to all users. Users cannot see an object unless they have MAC access to the object.

    The following summarizes the share and mount policies in Trusted Extensions for single-level datasets:

  • For a Trusted Extensions system to mount a file system on another Trusted Extensions system, the server and the client must have compatible remote host templates of type cipso.

  • For a Trusted Extensions system to mount a file system from an untrusted system, the single label that is assigned to the untrusted system by the Trusted Extensions system must match the label of the global zone.

    Similarly, for a labeled zone to mount a file system from an untrusted system, the single label that is assigned to the untrusted system by the Trusted Extensions system must match the label of the mounting zone.

  • Files whose labels differ from the mounting zone and are mounted with LOFS can be viewed, but cannot be modified. For details on NFS mounts, see NFS Server and Client Configuration in Trusted Extensions.

    The following summarizes the share and mount policies in Trusted Extensions for multilevel datasets:

  • For a Trusted Extensions system to share a multilevel dataset with another system, the NFS server must be configured as a multilevel service.

  • For a Trusted Extensions system to share a multilevel dataset with labeled zones on it own system, the global zone must LOFS mount the dataset in the zones.

    The labeled zone has write access to those LOFS-mounted files and directories whose label matches the zone's label, and has read access to the files and directories that it dominates. MAC policy is enforced at the individual file and directory level.