Solaris Trusted Extensions Administrator's Procedures
    
Numbers and Symbols
 
 -o nobanner option to lp command ( Index Term Link )
    
A
 
 access, See computer access
 
 access policy
  devices ( Index Term Link )
  Discretionary Access Control (DAC) ( Index Term Link ) ( Index Term Link )
  Mandatory Access Control (MAC) ( Index Term Link )
 
 accessing
  administrative tools ( Index Term Link )
  audit records by label ( Index Term Link )
  devices ( Index Term Link )
  global zone ( Index Term Link )
  home directories ( Index Term Link )
  printers ( Index Term Link )
  remote multilevel desktop ( Index Term Link )
  Solaris Management Console ( Index Term Link )
  ZFS dataset mounted in lower-level zone from higher-level zone ( Index Term Link )
 
 accessing the X server ( Index Term Link )
 
 account locking, preventing ( Index Term Link )
 
 accounts
  See roles
  See also users
  creating ( Index Term Link )
  planning ( Index Term Link )
 
 accreditation checks ( Index Term Link )
 
 accreditation ranges, label_encodings file ( Index Term Link )
 
 Action failed. Reconnect to Solaris Zone? ( Index Term Link )
 
 add_allocatable command ( Index Term Link )
 
 adding
  default routes for labeled zones ( Index Term Link )
  LDAP toolbox ( Index Term Link )
  local role with roleadd ( Index Term Link )
  local user with useradd ( Index Term Link )
  network databases to LDAP server ( Index Term Link )
  nscd daemon to every labeled zone ( Index Term Link )
  roles ( Index Term Link )
  shared network interfaces ( Index Term Link )
  Trusted Extensions to a Solaris system ( Index Term Link )
  users by using lpaddent ( Index Term Link )
  users who can assume roles ( Index Term Link )
  zone-specific network interface ( Index Term Link )
  zone-specific nscd daemon ( Index Term Link )
 
 Additional Trusted Extensions Configuration Tasks ( Index Term Link )
 
 ADMIN_HIGH label ( Index Term Link )
 
 ADMIN_LOW label
  lowest label ( Index Term Link )
  protecting administrative files ( Index Term Link )
 
 administering
  account locking ( Index Term Link )
  assigning device authorizations ( Index Term Link )
  auditing in Trusted Extensions ( Index Term Link )
  changing label of information ( Index Term Link )
  convenient authorizations for users ( Index Term Link )
  device allocation ( Index Term Link )
  device authorizations ( Index Term Link )
  devices ( Index Term Link ) ( Index Term Link )
  file systems
   mounting ( Index Term Link )
   overview ( Index Term Link )
   troubleshooting ( Index Term Link )
  files
   backing up ( Index Term Link )
   restoring ( Index Term Link )
  from the global zone ( Index Term Link )
  hiding labels from users ( Index Term Link )
  labeled printing ( Index Term Link )
  LDAP ( Index Term Link )
  mail ( Index Term Link )
  multilevel ports ( Index Term Link )
  network in Trusted Extensions ( Index Term Link )
  network of users ( Index Term Link )
  PostScript printing ( Index Term Link )
  printing in Trusted Extensions ( Index Term Link )
  printing interoperability with Trusted Solaris 8 ( Index Term Link )
  quick reference for administrators ( Index Term Link )
  remote host database ( Index Term Link )
  remote host templates ( Index Term Link )
  remotely ( Index Term Link )
  remotely by a role ( Index Term Link )
  remotely from command line ( Index Term Link )
  remotely with Solaris Management Console ( Index Term Link ) ( Index Term Link )
  routes with security attributes ( Index Term Link )
  serial line for login ( Index Term Link )
  sharing file systems ( Index Term Link )
  startup files for users ( Index Term Link )
  system files ( Index Term Link )
  third-party software ( Index Term Link )
  timeout when relabeling information ( Index Term Link )
  trusted network databases ( Index Term Link )
  trusted networking ( Index Term Link )
  unlabeled printing ( Index Term Link )
  user privileges ( Index Term Link )
  users ( Index Term Link ) ( Index Term Link )
  zones ( Index Term Link )
  zones from Trusted JDS ( Index Term Link )
 
 Administering Trusted Extensions Remotely (Task Map) ( Index Term Link )
 
 administrative labels ( Index Term Link )
 
 administrative roles, See roles
 
 Administrative Roles tool ( Index Term Link )
 
 administrative tools
  accessing ( Index Term Link )
  commands ( Index Term Link )
  configuration files ( Index Term Link )
  description ( Index Term Link )
  Device Manager ( Index Term Link )
  label builder ( Index Term Link )
  Labeled Zone Manager ( Index Term Link )
  Solaris Management Console ( Index Term Link ) ( Index Term Link )
  txzonemgr script ( Index Term Link )
 
 allocate command ( Index Term Link )
 
 Allocate Device authorization ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 allocate error state, correcting ( Index Term Link )
 
 allocating, using Device Manager ( Index Term Link )
 
 allocating devices
  for copying data ( Index Term Link )
  tape drive ( Index Term Link )
 
 Always Print Banner checkbox ( Index Term Link )
 
 applications
  evaluating for security ( Index Term Link )
  installing ( Index Term Link )
  trusted and trustworthy ( Index Term Link )
 
 assigning
  editor as the trusted editor ( Index Term Link )
  privileges to users ( Index Term Link )
  rights profiles ( Index Term Link )
 
 Assume Role menu item ( Index Term Link )
 
 assuming, roles ( Index Term Link )
 
 atohexlabel command ( Index Term Link ) ( Index Term Link )
 
 audio devices, preventing remote allocation ( Index Term Link )
 
 audit classes for Trusted Extensions, list of new X audit classes ( Index Term Link )
 
 audit events for Trusted Extensions, list of ( Index Term Link )
 
 audit planning ( Index Term Link )
 
 audit policy in Trusted Extensions ( Index Term Link )
 
 audit records in Trusted Extensions, policy ( Index Term Link )
 
 Audit Review profile, reviewing audit records ( Index Term Link )
 
 Audit Tasks of the System Administrator ( Index Term Link )
 
 audit tokens for Trusted Extensions
  label token ( Index Term Link )
  list of ( Index Term Link )
  xatom token ( Index Term Link )
  xclient token ( Index Term Link )
  xcolormap token ( Index Term Link )
  xcursor token ( Index Term Link )
  xfont token ( Index Term Link )
  xgc token ( Index Term Link )
  xpixmap token ( Index Term Link )
  xproperty token ( Index Term Link )
  xselect token ( Index Term Link )
  xwindow token ( Index Term Link )
 
 auditconfig command ( Index Term Link )
 
 auditing, planning ( Index Term Link )
 
 auditing in Trusted Extensions
  additional audit events ( Index Term Link )
  additional audit policies ( Index Term Link )
  additional audit tokens ( Index Term Link )
  additions to existing auditing commands ( Index Term Link )
  differences from Solaris auditing ( Index Term Link )
  reference ( Index Term Link )
  roles for administering ( Index Term Link )
  security administrator tasks ( Index Term Link )
  system administrator tasks ( Index Term Link )
  tasks ( Index Term Link )
  X audit classes ( Index Term Link )
 
 auditreduce command ( Index Term Link )
 
 authorizations
  adding new device authorizations ( Index Term Link )
  Allocate Device ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  assigning ( Index Term Link )
  assigning device authorizations ( Index Term Link )
  authorizing a user or role to change label ( Index Term Link )
  Configure Device Attributes ( Index Term Link )
  convenient for users ( Index Term Link )
  creating customized device authorizations ( Index Term Link )
  creating local and remote device authorizations ( Index Term Link )
  customizing for devices ( Index Term Link )
  granted ( Index Term Link )
  Print PostScript ( Index Term Link )
  Print Postscript ( Index Term Link )
  profiles that include device allocation authorizations ( Index Term Link )
  Revoke or Reclaim Device ( Index Term Link ) ( Index Term Link )
  solaris.print.nobanner ( Index Term Link )
  solaris.print.ps ( Index Term Link )
 
 authorizing
  device allocation ( Index Term Link )
  PostScript printing ( Index Term Link )
  unlabeled printing ( Index Term Link )
 
 automount command ( Index Term Link )
    
B
 
 backing up, previous system before installation ( Index Term Link )
 
 Backing Up, Sharing, and Mounting Labeled Files (Task Map) ( Index Term Link )
 
 banner pages
  description of labeled ( Index Term Link )
  difference from trailer page ( Index Term Link )
  printing without labels ( Index Term Link )
  typical ( Index Term Link )
 
 body pages
  description of labeled ( Index Term Link )
  unlabeled for all users ( Index Term Link )
  unlabeled for specific users ( Index Term Link )
    
C
 
 Cannot reach global zone ( Index Term Link )
 
 CD-ROM drives, accessing ( Index Term Link )
 
 Change Password menu item
  description ( Index Term Link )
  using to change root password ( Index Term Link )
 
 changing
  IDLETIME keyword ( Index Term Link )
  labels by authorized users ( Index Term Link )
  rules for label changes ( Index Term Link )
  security level of data ( Index Term Link )
  system security defaults ( Index Term Link )
  user privileges ( Index Term Link )
 
 checking
  label_encodings file ( Index Term Link )
  roles are working ( Index Term Link )
 
 checklists for initial setup team ( Index Term Link )
 
 chk_encodings command ( Index Term Link ) ( Index Term Link )
 
 choosing, See selecting
 
 classification label component ( Index Term Link )
 
 clearances, label overview ( Index Term Link )
 
 collecting information
  before enabling Trusted Extensions ( Index Term Link )
  for LDAP service ( Index Term Link )
  planning Trusted Extensions configuration ( Index Term Link )
 
 colors, indicating label of workspace ( Index Term Link )
 
 commands
  executing with privilege ( Index Term Link )
  troubleshooting networking ( Index Term Link )
  trusted_edit trusted editor ( Index Term Link )
 
 commercial applications, evaluating ( Index Term Link )
 
 Common Tasks in Trusted Extensions (Task Map) ( Index Term Link )
 
 compartment label component ( Index Term Link )
 
 component definitions, label_encodings file ( Index Term Link )
 
 computer access
  administrator responsibilities ( Index Term Link )
  restricting ( Index Term Link )
 
 Computers and Networks tool
  adding known hosts ( Index Term Link ) ( Index Term Link )
  modifying tnrhdb database ( Index Term Link )
 
 Computers and Networks tool set ( Index Term Link )
 
 configuration files, copying ( Index Term Link )
 
 Configure Device Attributes authorization ( Index Term Link )
 
 configuring
  access to headless Trusted Extensions ( Index Term Link )
  as a role or as superuser? ( Index Term Link )
  auditing ( Index Term Link )
  authorizations for devices ( Index Term Link )
  devices ( Index Term Link )
  labeled printing ( Index Term Link )
  LDAP for Trusted Extensions ( Index Term Link )
  LDAP proxy server for Trusted Extensions clients ( Index Term Link )
  network interfaces ( Index Term Link )
  routes with security attributes ( Index Term Link )
  serial line for login ( Index Term Link )
  Solaris Management Console for LDAP ( Index Term Link )
  startup files for users ( Index Term Link )
  Trusted Extensions labeled zones ( Index Term Link )
  Trusted Extensions software ( Index Term Link )
  trusted network ( Index Term Link )
 
 Configuring an LDAP Proxy Server on a Trusted Extensions Host (Task Map) ( Index Term Link )
 
 Configuring an LDAP Server on a Trusted Extensions Host (Task Map) ( Index Term Link )
 
 Configuring Labeled IPsec (Task Map) ( Index Term Link )
 
 Configuring Labeled Printing (Task Map) ( Index Term Link )
 
 Configuring Routes and Checking Network Information in Trusted Extensions (Task Map) ( Index Term Link )
 
 Configuring the Solaris Management Console for LDAP (Task Map) ( Index Term Link )
 
 configuring Trusted Extensions
  checklist for install team ( Index Term Link )
  headless access ( Index Term Link )
  initial procedures ( Index Term Link )
  labeled zones ( Index Term Link )
  task maps ( Index Term Link )
 
 Configuring Trusted Network Databases (Task Map) ( Index Term Link )
 
 controlling, See restricting
 
 .copy_files file
  description ( Index Term Link )
  setting up for users ( Index Term Link ) ( Index Term Link )
  startup file ( Index Term Link )
 
 Create a new zone menu item ( Index Term Link )
 
 creating
  accounts ( Index Term Link )
  accounts during or after configuration ( Index Term Link )
  authorizations for devices ( Index Term Link )
  home directories ( Index Term Link ) ( Index Term Link )
  home directory server ( Index Term Link )
  labeled zones ( Index Term Link )
  LDAP client ( Index Term Link )
  LDAP proxy server for Trusted Extensions clients ( Index Term Link )
  LDAP toolbox ( Index Term Link )
  local role with roleadd ( Index Term Link )
  local user with useradd ( Index Term Link )
  roles ( Index Term Link )
  users who can assume roles ( Index Term Link )
  zones ( Index Term Link )
 
 Creating Labeled Zones ( Index Term Link )
 
 credentials, registering LDAP with the Solaris Management Console ( Index Term Link )
 
 customizing
  device authorizations ( Index Term Link )
  label_encodings file ( Index Term Link )
  unlabeled printing ( Index Term Link )
  user accounts ( Index Term Link )
 
 Customizing Device Authorizations in Trusted Extensions (Task Map) ( Index Term Link )
 
 Customizing User Environment for Security (Task Map) ( Index Term Link )
 
 cut and paste, and labels ( Index Term Link )
 
 cutting and pasting, configuring rules for label changes ( Index Term Link )
    
D
 
 DAC, See discretionary access control (DAC)
 
 databases
  in LDAP ( Index Term Link )
  trusted network ( Index Term Link )
 
 datasets, See ZFS
 
 deallocate command ( Index Term Link )
 
 deallocating, forcing ( Index Term Link )
 
 debugging, See troubleshooting
 
 deciding
  to configure as a role or as superuser ( Index Term Link )
  to use a Sun-supplied encodings file ( Index Term Link )
 
 decisions to make
  based on site security policy ( Index Term Link )
  before enabling Trusted Extensions ( Index Term Link )
 
 default routes, specifying for labeled zones ( Index Term Link )
 
 deleting, labeled zones ( Index Term Link )
 
 desktops
  accessing multilevel remotely ( Index Term Link )
  logging in to a failsafe session ( Index Term Link )
  workspace color changes ( Index Term Link )
 
 /dev/kmem kernel image file, security violation ( Index Term Link )
 
 developer responsibilities ( Index Term Link )
 
 device allocation
  authorizing ( Index Term Link )
  overview ( Index Term Link )
  profiles that include allocation authorizations ( Index Term Link )
 
 device-clean scripts
  adding to devices ( Index Term Link )
  requirements ( Index Term Link )
 
 Device Manager
  administrative tool ( Index Term Link )
  description ( Index Term Link )
  use by administrators ( Index Term Link )
 
 devices
  access policy ( Index Term Link )
  accessing ( Index Term Link )
  adding customized authorizations ( Index Term Link )
  adding device_clean script ( Index Term Link )
  administering ( Index Term Link )
  administering with Device Manager ( Index Term Link )
  allocating ( Index Term Link )
  configuring devices ( Index Term Link )
  configuring serial line ( Index Term Link )
  creating new authorizations ( Index Term Link )
  in Trusted Extensions ( Index Term Link )
  policy defaults ( Index Term Link )
  preventing remote allocation of audio ( Index Term Link )
  protecting ( Index Term Link )
  protecting nonallocatable ( Index Term Link )
  reclaiming ( Index Term Link )
  setting label range for nonallocatable ( Index Term Link )
  setting policy ( Index Term Link )
  troubleshooting ( Index Term Link )
  using ( Index Term Link )
 
 dfstab file, for public zone ( Index Term Link )
 
 differences
  administrative interfaces in Trusted Extensions ( Index Term Link )
  between Trusted Extensions and Solaris auditing ( Index Term Link )
  between Trusted Extensions and Solaris OS ( Index Term Link )
  defaults in Trusted Extensions ( Index Term Link )
  extending Solaris interfaces ( Index Term Link )
  limited options in Trusted Extensions ( Index Term Link )
 
 directories
  accessing lower-level ( Index Term Link )
  authorizing a user or role to change label of ( Index Term Link )
  for naming service setup ( Index Term Link )
  mounting ( Index Term Link )
  sharing ( Index Term Link )
 
 disabling, Trusted Extensions ( Index Term Link )
 
 discretionary access control (DAC) ( Index Term Link )
 
 diskettes, accessing ( Index Term Link )
 
 displaying
  labels of file systems in labeled zone ( Index Term Link )
  status of every zone ( Index Term Link )
 
 DOI, remote host templates ( Index Term Link )
 
 domain of interpretation (DOI), entry in /etc/system file ( Index Term Link )
 
 dominance of labels ( Index Term Link )
 
 Downgrade DragNDrop or CutPaste Info authorization ( Index Term Link )
 
 Downgrade File Label authorization ( Index Term Link )
 
 downgrading labels, configuring rules for selection confirmer ( Index Term Link )
 
 dpadm service ( Index Term Link )
 
 DragNDrop or CutPaste without viewing contents authorization ( Index Term Link )
 
 dsadm service ( Index Term Link )
 
 dtsession command, running updatehome ( Index Term Link )
 
 dtterm terminal, forcing the sourcing of .profile ( Index Term Link )
    
E
 
 editing
  system files ( Index Term Link )
  using trusted editor ( Index Term Link )
 
 enabling
  DOI different from 1 ( Index Term Link )
  dpadm service ( Index Term Link )
  dsadm service ( Index Term Link )
  IPv6 network ( Index Term Link )
  keyboard shutdown ( Index Term Link )
  labeld service ( Index Term Link )
  LDAP administration from a client ( Index Term Link )
  login to labeled zone ( Index Term Link )
  Trusted Extensions on a Solaris system ( Index Term Link )
 
 encodings file, See label_encodings file
 
 error messages, troubleshooting ( Index Term Link )
 
 /etc/default/kbd file, how to edit ( Index Term Link )
 
 /etc/default/login file, how to edit ( Index Term Link )
 
 /etc/default/passwd file, how to edit ( Index Term Link )
 
 /etc/default/print file ( Index Term Link )
 
 /etc/dfs/dfstab file for public zone ( Index Term Link )
 
 /etc/hosts file ( Index Term Link ) ( Index Term Link )
 
 /etc/security/policy.conf file
  defaults ( Index Term Link )
  enabling PostScript printing ( Index Term Link )
  how to edit ( Index Term Link )
  modifying ( Index Term Link )
 
 /etc/security/tsol/label_encodings file ( Index Term Link )
 
 /etc/system file
  modifying for DOI different from 1 ( Index Term Link )
  modifying for IPv6 network ( Index Term Link )
 
 evaluating programs for security ( Index Term Link )
 
 exporting, See sharing
    
F
 
 failsafe session, logging in ( Index Term Link )
 
 fallback mechanism
  for remote hosts ( Index Term Link )
  in tnrhdb ( Index Term Link )
  using for network configuration ( Index Term Link )
 
 file systems
  mounting in global and labeled zones ( Index Term Link )
  NFS mounts ( Index Term Link )
  sharing ( Index Term Link )
  sharing in global and labeled zones ( Index Term Link )
 
 files
  accessing from dominating labels ( Index Term Link )
  authorizing a user or role to change label of ( Index Term Link )
  backing up ( Index Term Link )
  .copy_files ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  copying from removable media ( Index Term Link )
  editing with trusted editor ( Index Term Link )
  /etc/default/kbd ( Index Term Link )
  /etc/default/login ( Index Term Link )
  /etc/default/passwd ( Index Term Link )
  /etc/default/print ( Index Term Link )
  /etc/security/policy.conf ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  getmounts ( Index Term Link )
  getzonelabels ( Index Term Link )
  .gtkrc-mine ( Index Term Link )
  .link_files ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  loopback mounting ( Index Term Link )
  office-install-directory/VCL.xcu ( Index Term Link )
  policy.conf ( Index Term Link )
  PostScript ( Index Term Link )
  preventing access from dominating labels ( Index Term Link )
  relabeling privileges ( Index Term Link )
  resolv.conf ( Index Term Link )
  restoring ( Index Term Link )
  sel_config file ( Index Term Link )
  startup ( Index Term Link )
  tsoljdsselmgr ( Index Term Link )
  /usr/bin/tsoljdsselmgr ( Index Term Link )
  /usr/lib/lp/postscript/tsol_separator.ps ( Index Term Link )
  /usr/sbin/txzonemgr ( Index Term Link ) ( Index Term Link )
  /usr/share/gnome/sel_config ( Index Term Link )
  VCL.xcu ( Index Term Link )
 
 files and file systems
  mounting ( Index Term Link )
  naming ( Index Term Link )
  sharing ( Index Term Link )
 
 finding
  label equivalent in hexadecimal ( Index Term Link )
  label equivalent in text format ( Index Term Link )
 
 Firefox, lengthening timeout when relabeling ( Index Term Link )
 
 floppies, See diskettes
 
 floppy disks, See diskettes
    
G
 
 gateways
  accreditation checks ( Index Term Link )
  example of ( Index Term Link )
 
 getlabel command ( Index Term Link )
 
 getmounts script ( Index Term Link )
 
 Getting Started as a Trusted Extensions Administrator (Task Map) ( Index Term Link )
 
 getzonelabels script ( Index Term Link )
 
 getzonepath command ( Index Term Link )
 
 global zone
  difference from labeled zones ( Index Term Link )
  entering ( Index Term Link )
  exiting ( Index Term Link )
  remote login by users ( Index Term Link )
 
 GNOME ToolKit (GTK) library, lengthening timeout when relabeling ( Index Term Link )
 
 groups
  deletion precautions ( Index Term Link )
  security requirements ( Index Term Link )
 
 .gtkrc-mine file ( Index Term Link )
    
H
 
 Handling Devices in Trusted Extensions (Task Map) ( Index Term Link )
 
 Handling Other Tasks in the Solaris Management Console (Task Map) ( Index Term Link )
 
 hardware planning ( Index Term Link )
 
 Headless System Configuration in Trusted Extensions (Task Map) ( Index Term Link )
 
 hextoalabel command ( Index Term Link ) ( Index Term Link )
 
 hiding labels from users ( Index Term Link )
 
 home directories
  accessing ( Index Term Link )
  creating ( Index Term Link ) ( Index Term Link )
  creating server for ( Index Term Link )
  logging in and getting ( Index Term Link )
 
 host types
  networking ( Index Term Link ) ( Index Term Link )
  remote host templates ( Index Term Link )
  table of templates and protocols ( Index Term Link )
 
 hosts
  assigning a template ( Index Term Link ) ( Index Term Link )
  assigning to security template ( Index Term Link )
  entering in network files ( Index Term Link )
  networking concepts ( Index Term Link )
 
 hot key, regaining control of desktop focus ( Index Term Link )
    
I
 
 IDLECMD keyword, changing default ( Index Term Link )
 
 IDLETIME keyword, changing default ( Index Term Link )
 
 ifconfig command ( Index Term Link ) ( Index Term Link )
 
 ikeadm command ( Index Term Link )
 
 importing, software ( Index Term Link )
 
 in.iked command ( Index Term Link )
 
 initial setup team, checklist for configuring Trusted Extensions ( Index Term Link )
 
 initializing, Solaris Management Console ( Index Term Link )
 
 installation menu, Create a new zone ( Index Term Link )
 
 installing
  label_encodings file ( Index Term Link )
  Solaris OS for Trusted Extensions ( Index Term Link )
  Sun Java System Directory Server ( Index Term Link )
 
 interfaces
  assigning to security template ( Index Term Link )
  verifying they are up ( Index Term Link )
 
 internationalizing, See localizing
 
 interoperability, Trusted Solaris 8 and printing ( Index Term Link )
 
 IP addresses
  fallback mechanism in tnrhdb ( Index Term Link )
  in tnrhdb database ( Index Term Link )
  in tnrhdb file ( Index Term Link )
 
 ipseckey command ( Index Term Link ) ( Index Term Link )
 
 IPv6
  entry in /etc/system file ( Index Term Link )
  troubleshooting ( Index Term Link )
    
J
 
 Java archive (JAR) files, installing ( Index Term Link )
    
K
 
 key combinations, testing if grab is trusted ( Index Term Link )
 
 keyboard shutdown, enabling ( Index Term Link )
 
 kmem kernel image file ( Index Term Link )
    
L
 
 label audit token ( Index Term Link )
 
 label_encodings file
  checking ( Index Term Link )
  contents ( Index Term Link )
  installing ( Index Term Link )
  localizing ( Index Term Link )
  modifying ( Index Term Link )
  reference for labeled printing ( Index Term Link )
  source of accreditation ranges ( Index Term Link )
 
 label ranges
  restricting printer label range ( Index Term Link )
  setting on frame buffers ( Index Term Link )
  setting on printers ( Index Term Link )
 
 labeld service ( Index Term Link )
  disabling ( Index Term Link )
 
 labeled printing
  banner pages ( Index Term Link )
  body pages ( Index Term Link )
  PostScript files ( Index Term Link )
  removing label ( Index Term Link )
  removing PostScript restriction ( Index Term Link )
  without banner page ( Index Term Link ) ( Index Term Link )
 
 Labeled Zone Manager, See txzonemgr script
 
 labeled zones, See zones
 
 labeling
  turning on labels ( Index Term Link )
  zones ( Index Term Link )
 
 labels
  See also label ranges
  authorizing a user or role to change label of data ( Index Term Link )
  classification component ( Index Term Link )
  compartment component ( Index Term Link )
  configuring rules for label changes ( Index Term Link )
  default in remote host templates ( Index Term Link )
  described ( Index Term Link )
  determining text equivalents ( Index Term Link )
  displaying in hexadecimal ( Index Term Link )
  displaying labels of file systems in labeled zone ( Index Term Link )
  dominance ( Index Term Link )
  downgrading and upgrading ( Index Term Link )
  hiding from users ( Index Term Link )
  of processes ( Index Term Link )
  of user processes ( Index Term Link )
  on printer output ( Index Term Link )
  overview ( Index Term Link )
  planning ( Index Term Link )
  printing without page labels ( Index Term Link )
  relationships ( Index Term Link )
  repairing in internal databases ( Index Term Link )
  specifying for zones ( Index Term Link )
  troubleshooting ( Index Term Link )
  well-formed ( Index Term Link )
 
 LDAP
  displaying entries ( Index Term Link )
  enabling administration from a client ( Index Term Link )
  managing the naming service ( Index Term Link )
  naming service for Trusted Extensions ( Index Term Link )
  planning ( Index Term Link )
  starting ( Index Term Link )
  stopping ( Index Term Link )
  troubleshooting ( Index Term Link )
  Trusted Extensions databases ( Index Term Link )
 
 LDAP configuration
  creating client ( Index Term Link )
  for Trusted Extensions ( Index Term Link )
  Sun Ray servers, and ( Index Term Link )
 
 LDAP server
  collecting information for ( Index Term Link )
  configuring multilevel port ( Index Term Link )
  configuring naming service ( Index Term Link )
  configuring proxy for Trusted Extensions clients ( Index Term Link )
  creating proxy for Trusted Extensions clients ( Index Term Link )
  installing in Trusted Extensions ( Index Term Link )
  planning for separation of duty ( Index Term Link )
  protecting log files ( Index Term Link )
  registering credentials with Solaris Management Console ( Index Term Link )
 
 lengthening timeout, for relabeling ( Index Term Link )
 
 limiting, defined hosts on the network ( Index Term Link )
 
 .link_files file
  description ( Index Term Link )
  setting up for users ( Index Term Link )
  startup file ( Index Term Link )
 
 list_devices command ( Index Term Link )
 
 localizing, changing labeled printer output ( Index Term Link )
 
 log files, protecting Directory Server logs ( Index Term Link )
 
 logging in
  to a home directory server ( Index Term Link )
  using rlogin command ( Index Term Link )
 
 login
  by roles ( Index Term Link )
  configuring serial line ( Index Term Link )
  remote ( Index Term Link )
  remote by roles ( Index Term Link )
 
 logout, requiring ( Index Term Link )
 
 lpaddent command ( Index Term Link )
    
M
 
 MAC, See mandatory access control (MAC)
 
 mail
  administering ( Index Term Link )
  implementation in Trusted Extensions ( Index Term Link )
  multilevel ( Index Term Link )
 
 man pages, quick reference for Trusted Extensions administrators ( Index Term Link )
 
 managing, See administering
 
 Managing Devices in Trusted Extensions (Task Map) ( Index Term Link )
 
 Managing Printing in Trusted Extensions (Task Map) ( Index Term Link )
 
 Managing Software in Trusted Extensions (Tasks) ( Index Term Link )
 
 Managing Trusted Networking (Task Map) ( Index Term Link )
 
 Managing Users and Rights With the Solaris Management Console (Task Map) ( Index Term Link )
 
 Managing Zones (Task Map) ( Index Term Link )
 
 mandatory access control (MAC)
  enforcing on the network ( Index Term Link )
  in Trusted Extensions ( Index Term Link )
 
 maximum labels, remote host templates ( Index Term Link )
 
 media, copying files from removable ( Index Term Link )
 
 minimum labels, remote host templates ( Index Term Link )
 
 MLPs, See multilevel ports (MLPs)
 
 modifying, label_encodings file ( Index Term Link )
 
 mounting
  file systems ( Index Term Link )
  files by loopback mounting ( Index Term Link )
  overview ( Index Term Link )
  troubleshooting ( Index Term Link )
  ZFS dataset on labeled zone ( Index Term Link )
 
 Mozilla, lengthening timeout when relabeling ( Index Term Link )
 
 multiheaded system, trusted stripe ( Index Term Link )
 
 multilevel mounts, NFS protocol versions ( Index Term Link )
 
 multilevel ports (MLPs)
  administering ( Index Term Link )
  example of NFSv3 MLP ( Index Term Link )
  example of web proxy MLP ( Index Term Link )
 
 multilevel printing
  accessing by print client ( Index Term Link )
  configuring ( Index Term Link )
 
 multilevel server, planning ( Index Term Link )
    
N
 
 name service cache daemon, See nscd daemon
 
 names, specifying for zones ( Index Term Link )
 
 names of file systems ( Index Term Link )
 
 naming, zones ( Index Term Link )
 
 naming services
  databases unique to Trusted Extensions ( Index Term Link )
  LDAP ( Index Term Link )
  managing LDAP ( Index Term Link )
 
 net_mac_aware privilege ( Index Term Link )
 
 netstat command ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 network
  See Trusted Extensions network
  See trusted network
 
 network databases
  description ( Index Term Link )
  in LDAP ( Index Term Link )
 
 network packets ( Index Term Link )
 
 networking concepts ( Index Term Link )
 
 NFS mounts
  accessing lower-level directories ( Index Term Link )
  in global and labeled zones ( Index Term Link )
 
 No route available ( Index Term Link )
 
 nonallocatable devices
  protecting ( Index Term Link )
  setting label range ( Index Term Link )
 
 nscd daemon, adding to every labeled zone ( Index Term Link )
    
O
 
 office-install-directory/VCL.xcu ( Index Term Link )
 
 OpenOffice, See StarOffice
    
P
 
 packages, accessing the media ( Index Term Link )
 
 passwords
  assigning ( Index Term Link )
  Change Password menu item ( Index Term Link ) ( Index Term Link )
  changing for root ( Index Term Link )
  changing user passwords ( Index Term Link )
  storage ( Index Term Link )
  testing if password prompt is trusted ( Index Term Link )
 
 plabel command ( Index Term Link )
 
 planning
  See also Trusted Extensions use
  account creation ( Index Term Link )
  administration strategy ( Index Term Link )
  auditing ( Index Term Link )
  data migration ( Index Term Link )
  hardware ( Index Term Link )
  labels ( Index Term Link )
  LDAP naming service ( Index Term Link )
  network ( Index Term Link )
  NFS server ( Index Term Link )
  printing ( Index Term Link )
  Trusted Extensions ( Index Term Link )
  Trusted Extensions configuration strategy ( Index Term Link )
  zones ( Index Term Link )
 
 policy.conf file
  changing defaults ( Index Term Link )
  changing Trusted Extensions keywords ( Index Term Link )
  defaults ( Index Term Link )
  how to edit ( Index Term Link )
 
 PostScript
  enabling to print ( Index Term Link )
  printing restrictions in Trusted Extensions ( Index Term Link )
 
 preventing, See protecting
 
 Print Postscript authorization ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 Print without Banner authorization ( Index Term Link ) ( Index Term Link )
 
 Print without Label authorization ( Index Term Link )
 
 printer output, See printing
 
 printers, setting label range ( Index Term Link )
 
 printing
  adding conversion filters ( Index Term Link )
  and label_encodings file ( Index Term Link )
  authorizations for unlabeled output from a public system ( Index Term Link )
  configuring for multilevel labeled output ( Index Term Link )
  configuring for print client ( Index Term Link )
  configuring labeled zone ( Index Term Link )
  configuring labels and text ( Index Term Link )
  configuring public print jobs ( Index Term Link )
  in local language ( Index Term Link )
  internationalizing labeled output ( Index Term Link )
  interoperability with Trusted Solaris 8 ( Index Term Link )
  labeling a Solaris print server ( Index Term Link )
  localizing labeled output ( Index Term Link )
  managing ( Index Term Link )
  model scripts ( Index Term Link )
  planning ( Index Term Link )
  PostScript files ( Index Term Link )
  PostScript restrictions in Trusted Extensions ( Index Term Link )
  preventing labels on output ( Index Term Link )
  public jobs from a Solaris print server ( Index Term Link )
  removing PostScript restriction ( Index Term Link )
  restricting label range ( Index Term Link )
  using a Solaris print server ( Index Term Link )
  without labeled banners and trailers ( Index Term Link ) ( Index Term Link )
  without page labels ( Index Term Link ) ( Index Term Link )
 
 privileges
  changing defaults for users ( Index Term Link )
  non-obvious reasons for requiring ( Index Term Link )
  removing proc_info from basic set ( Index Term Link )
  restricting users' ( Index Term Link )
  when executing commands ( Index Term Link )
 
 proc_info privilege, removing from basic set ( Index Term Link )
 
 procedures, See tasks and task maps
 
 processes
  labels of ( Index Term Link )
  labels of user processes ( Index Term Link )
  preventing users from seeing others' processes ( Index Term Link )
 
 profiles, See rights profiles
 
 programs, See applications
 
 protecting
  devices ( Index Term Link ) ( Index Term Link )
  devices from remote allocation ( Index Term Link )
  file systems by using non-proprietary names ( Index Term Link )
  files at lower labels from being accessed ( Index Term Link )
  from access by arbitrary hosts ( Index Term Link )
  information with labels ( Index Term Link )
  labeled hosts from contact by arbitrary unlabeled hosts ( Index Term Link )
  nonallocatable devices ( Index Term Link )
 
 publications, security and UNIX ( Index Term Link )
    
R
 
 real UID of root, required for applications ( Index Term Link )
 
 rebooting
  activating labels ( Index Term Link )
  enabling login to labeled zone ( Index Term Link )
 
 Reducing Printing Restrictions in Trusted Extensions (Task Map) ( Index Term Link )
 
 regaining control of desktop focus ( Index Term Link )
 
 registering, LDAP credentials with the Solaris Management Console ( Index Term Link )
 
 regular users, See users
 
 relabeling information ( Index Term Link )
 
 remote administration
  defaults ( Index Term Link )
  methods ( Index Term Link )
 
 remote host templates
  assigning ( Index Term Link )
  assigning to hosts ( Index Term Link )
  creating ( Index Term Link )
  tool for administering ( Index Term Link )
 
 remote hosts, using fallback mechanism in tnrhdb ( Index Term Link )
 
 Remote Login authorization ( Index Term Link )
 
 remote logins, enabling for roles ( Index Term Link )
 
 remote multilevel desktop, accessing ( Index Term Link )
 
 removable media, mounting ( Index Term Link )
 
 remove_allocatable command ( Index Term Link )
 
 removing
  labels on printer output ( Index Term Link )
  zone-specific nscd daemon ( Index Term Link )
 
 removing Trusted Extensions, See disabling
 
 repairing, labels in internal databases ( Index Term Link )
 
 requirements for Trusted Extensions
  Solaris installation options ( Index Term Link )
  Solaris installed systems ( Index Term Link )
 
 resolv.conf file, loading during configuration ( Index Term Link )
 
 restoring control of desktop focus ( Index Term Link )
 
 restricting
  access to computer based on label ( Index Term Link )
  access to devices ( Index Term Link )
  access to global zone ( Index Term Link )
  access to lower-level files ( Index Term Link )
  access to printers with labels ( Index Term Link )
  mounts of lower-level files ( Index Term Link )
  printer access with labels ( Index Term Link )
  printer label range ( Index Term Link )
  remote access ( Index Term Link )
 
 Revoke or Reclaim Device authorization ( Index Term Link ) ( Index Term Link )
 
 rights, See rights profiles
 
 rights profiles
  assigning ( Index Term Link )
  Convenient Authorizations ( Index Term Link )
  customizing for separation of duty ( Index Term Link )
  with Allocate Device authorization ( Index Term Link )
  with device allocation authorizations ( Index Term Link )
  with new device authorizations ( Index Term Link )
 
 Rights tool ( Index Term Link )
 
 roadmaps
  Task Map: Configuring Trusted Extensions ( Index Term Link )
  Task Map: Preparing a Solaris System for Trusted Extensions ( Index Term Link )
  Task Map: Preparing For and Enabling Trusted Extensions ( Index Term Link )
 
 role workspace, global zone ( Index Term Link )
 
 roleadd command ( Index Term Link )
 
 roles
  adding local role with roleadd ( Index Term Link )
  administering auditing ( Index Term Link )
  administering remotely ( Index Term Link ) ( Index Term Link )
  assigning rights ( Index Term Link )
  assuming ( Index Term Link ) ( Index Term Link )
  creating ( Index Term Link )
  creating Security Administrator ( Index Term Link )
  determining when to create ( Index Term Link )
  leaving role workspace ( Index Term Link )
  logging in remotely ( Index Term Link )
  remote login ( Index Term Link )
  role assumption from unlabeled host ( Index Term Link )
  separation of duty ( Index Term Link ) ( Index Term Link )
  trusted application access ( Index Term Link )
  verifying they work ( Index Term Link )
  workspaces ( Index Term Link )
 
 root passwords, required in Trusted Extensions ( Index Term Link )
 
 root UID, required for applications ( Index Term Link )
 
 route command ( Index Term Link ) ( Index Term Link )
 
 routing ( Index Term Link )
  accreditation checks ( Index Term Link )
  commands in Trusted Extensions ( Index Term Link )
  concepts ( Index Term Link )
  example of ( Index Term Link )
  specifying default routes for labeled zones ( Index Term Link )
  static with security attributes ( Index Term Link )
  tables ( Index Term Link ) ( Index Term Link )
  using route command ( Index Term Link )
    
S
 
 scripts
  getmounts ( Index Term Link )
  getzonelabels ( Index Term Link )
  /usr/sbin/txzonemgr ( Index Term Link ) ( Index Term Link )
 
 secure attention, key combination ( Index Term Link )
 
 security
  initial setup team ( Index Term Link )
  publications ( Index Term Link )
  root password ( Index Term Link )
  site security policy ( Index Term Link )
 
 Security Administrator role
  administering network of users ( Index Term Link )
  administering PostScript restriction ( Index Term Link )
  administering printer security ( Index Term Link )
  assigning authorizations to users ( Index Term Link )
  audit tasks ( Index Term Link )
  configuring a device ( Index Term Link )
  configuring serial line for login ( Index Term Link )
  creating ( Index Term Link )
  creating Convenient Authorizations rights profile ( Index Term Link )
  enabling unlabeled body pages from a public system ( Index Term Link )
  enforcing security ( Index Term Link )
  protecting nonallocatable devices ( Index Term Link )
 
 security administrators, See Security Administrator role
 
 security attributes ( Index Term Link )
  modifying defaults for all users ( Index Term Link )
  modifying user defaults ( Index Term Link )
  setting for remote hosts ( Index Term Link )
  using in routing ( Index Term Link )
 
 security information, on printer output ( Index Term Link )
 
 security label set, remote host templates ( Index Term Link )
 
 security mechanisms
  extensible ( Index Term Link )
  Solaris ( Index Term Link )
 
 security policy
  auditing ( Index Term Link )
  training users ( Index Term Link )
  users and devices ( Index Term Link )
 
 security templates, See remote host templates
 
 Security Templates tool ( Index Term Link ) ( Index Term Link )
  assigning templates ( Index Term Link )
  modifying tnrhdb ( Index Term Link ) ( Index Term Link )
  using ( Index Term Link )
 
 sel_config file ( Index Term Link )
  configuring selection transfer rules ( Index Term Link )
 
 selecting, audit records by label ( Index Term Link )
 
 Selection Manager
  changing timeout ( Index Term Link )
  configuring rules for selection confirmer ( Index Term Link )
 
 Selection Manager application ( Index Term Link )
 
 separation of duty
  creating rights profiles ( Index Term Link )
  planning for ( Index Term Link )
  planning for LDAP ( Index Term Link )
 
 serial line, configuring for logins ( Index Term Link )
 
 service management framework (SMF)
  dpadm ( Index Term Link )
  dsadm ( Index Term Link )
  labeld service ( Index Term Link )
 
 session range ( Index Term Link )
 
 sessions, failsafe ( Index Term Link )
 
 setlabel command ( Index Term Link )
 
 sharing, ZFS dataset from labeled zone ( Index Term Link )
 
 Shutdown authorization ( Index Term Link )
 
 similarities
  between Trusted Extensions and Solaris auditing ( Index Term Link )
  between Trusted Extensions and Solaris OS ( Index Term Link )
 
 single-label operation ( Index Term Link )
 
 single-label printing, configuring for a zone ( Index Term Link )
 
 site security policy
  common violations ( Index Term Link )
  personnel recommendations ( Index Term Link )
  physical access recommendations ( Index Term Link )
  recommendations ( Index Term Link )
  tasks involved ( Index Term Link )
  Trusted Extensions configuration decisions ( Index Term Link )
  understanding ( Index Term Link )
 
 smtnrhdb command ( Index Term Link )
 
 smtnrhtp command ( Index Term Link )
 
 smtnzonecfg command ( Index Term Link )
 
 snoop command ( Index Term Link ) ( Index Term Link )
 
 software
  administering third-party ( Index Term Link )
  importing ( Index Term Link )
  installing Java programs ( Index Term Link )
 
 Solaris installation options, requirements ( Index Term Link )
 
 Solaris installed systems, requirements for Trusted Extensions ( Index Term Link )
 
 Solaris Management Console
  administering trusted network ( Index Term Link )
  administering users ( Index Term Link )
  Computers and Networks tool ( Index Term Link )
  configuring for LDAP ( Index Term Link )
  configuring LDAP toolbox ( Index Term Link )
  description of tools and toolboxes ( Index Term Link )
  enabling LDAP toolbox to be used ( Index Term Link )
  initializing ( Index Term Link )
  loading a Trusted Extensions toolbox ( Index Term Link )
  registering LDAP credentials ( Index Term Link )
  Security Templates tool ( Index Term Link ) ( Index Term Link )
  starting ( Index Term Link )
  toolboxes ( Index Term Link )
  troubleshooting ( Index Term Link ) ( Index Term Link )
  Trusted Network Zones tool ( Index Term Link )
  working with Sun Java System Directory Server ( Index Term Link )
 
 Solaris OS
  differences from Trusted Extensions ( Index Term Link )
  differences from Trusted Extensions auditing ( Index Term Link )
  similarities with Trusted Extensions ( Index Term Link )
  similarities with Trusted Extensions auditing ( Index Term Link )
 
 solaris.print.nobanner authorization ( Index Term Link ) ( Index Term Link )
 
 solaris.print.ps authorization ( Index Term Link )
 
 solaris.print.unlabeled authorization ( Index Term Link )
 
 Solaris Trusted Extensions, See Trusted Extensions
 
 StarOffice, lengthening timeout when relabeling ( Index Term Link )
 
 startup files, procedures for customizing ( Index Term Link )
 
 Stop-A, enabling ( Index Term Link )
 
 Sun Java System Directory Server, See LDAP server
 
 Sun Ray systems
  enabling initial contact between client and server ( Index Term Link )
  LDAP servers, and ( Index Term Link )
  preventing users from seeing others' processes ( Index Term Link )
  tnrhdb address for client contact ( Index Term Link )
  web site for documentation ( Index Term Link )
 
 System Administrator role
  adding device_clean script ( Index Term Link )
  adding print conversion filters ( Index Term Link )
  administering printers ( Index Term Link )
  audit tasks ( Index Term Link )
  reclaiming a device ( Index Term Link )
  restricting ( Index Term Link )
  reviewing audit records ( Index Term Link )
 
 system files
  editing ( Index Term Link ) ( Index Term Link )
  Solaris /etc/default/print ( Index Term Link )
  Solaris policy.conf ( Index Term Link )
  Trusted Extensions sel_config ( Index Term Link )
  Trusted Extensions tsol_separator.ps ( Index Term Link )
    
T
 
 tape devices
  accessing ( Index Term Link )
  allocating ( Index Term Link )
 
 tar command ( Index Term Link )
 
 Task Map: Configuring Trusted Extensions ( Index Term Link )
 
 Task Map: Preparing a Solaris System for Trusted Extensions ( Index Term Link )
 
 Task Map: Preparing For and Enabling Trusted Extensions ( Index Term Link )
 
 tasks and task maps
  Additional Trusted Extensions Configuration Tasks ( Index Term Link )
  Administering Trusted Extensions Remotely (Task Map) ( Index Term Link )
  Audit Tasks of the Security Administrator ( Index Term Link )
  Audit Tasks of the System Administrator ( Index Term Link )
  Backing Up, Sharing, and Mounting Labeled Files (Task Map) ( Index Term Link )
  Common Tasks in Trusted Extensions (Task Map) ( Index Term Link )
  Configuring an LDAP Proxy Server on a Trusted Extensions Host (Task Map) ( Index Term Link )
  Configuring an LDAP Server on a Trusted Extensions Host (Task Map) ( Index Term Link )
  Configuring Labeled IPsec (Task Map) ( Index Term Link )
  Configuring Labeled Printing (Task Map) ( Index Term Link )
  Configuring Routes and Checking Network Information in Trusted Extensions (Task Map) ( Index Term Link )
  Configuring the Solaris Management Console for LDAP (Task Map) ( Index Term Link )
  Configuring Trusted Network Databases (Task Map) ( Index Term Link )
  Creating Labeled Zones ( Index Term Link )
  Customizing Device Authorizations in Trusted Extensions (Task Map) ( Index Term Link )
  Customizing User Environment for Security (Task Map) ( Index Term Link )
  Getting Started as a Trusted Extensions Administrator (Task Map) ( Index Term Link )
  Handling Devices in Trusted Extensions (Task Map) ( Index Term Link )
  Handling Other Tasks in the Solaris Management Console (Task Map) ( Index Term Link )
  Headless System Configuration in Trusted Extensions (Task Map) ( Index Term Link )
  Managing Devices in Trusted Extensions (Task Map) ( Index Term Link )
  Managing Printing in Trusted Extensions (Task Map) ( Index Term Link )
  Managing Software in Trusted Extensions (Tasks) ( Index Term Link )
  Managing Trusted Networking (Task Map) ( Index Term Link )
  Managing Users and Rights With the Solaris Management Console ( Index Term Link )
  Managing Zones (Task Map) ( Index Term Link )
  Reducing Printing Restrictions in Trusted Extensions (Task Map) ( Index Term Link )
  Troubleshooting the Trusted Network (Task Map) ( Index Term Link )
  Using Devices in Trusted Extensions (Tasks Map) ( Index Term Link )
 
 tcp_listen=true LDAP setting ( Index Term Link )
 
 text label equivalents, determining ( Index Term Link )
 
 Thunderbird, lengthening timeout when relabeling ( Index Term Link )
 
 tnchkdb command
  description ( Index Term Link )
  summary ( Index Term Link )
 
 tnctl command
  description ( Index Term Link )
  summary ( Index Term Link )
  updating kernel cache ( Index Term Link )
  using ( Index Term Link )
 
 tnd command
  description ( Index Term Link )
  summary ( Index Term Link )
 
 tninfo command
  description ( Index Term Link )
  summary ( Index Term Link )
  using ( Index Term Link ) ( Index Term Link )
 
 tnrhdb database
  0.0.0.0 host address ( Index Term Link ) ( Index Term Link )
  0.0.0.0 wildcard address ( Index Term Link )
  adding to ( Index Term Link )
  configuring ( Index Term Link )
  entry for Sun Ray servers ( Index Term Link )
  fallback mechanism ( Index Term Link ) ( Index Term Link )
  tool for administering ( Index Term Link )
  wildcard address ( Index Term Link )
 
 tnrhtp database
  adding to ( Index Term Link )
  tool for administering ( Index Term Link )
 
 toolboxes
  adding LDAP server to tsol_ldap.tbx ( Index Term Link )
  defined ( Index Term Link )
  loading in Trusted Extensions ( Index Term Link )
  Scope=LDAP ( Index Term Link )
 
 tools, See administrative tools
 
 trailer pages, See banner pages
 
 translation, See localizing
 
 troubleshooting
  accessing X server ( Index Term Link )
  failed login ( Index Term Link )
  IPv6 configuration ( Index Term Link )
  LDAP ( Index Term Link )
  mounted file systems ( Index Term Link )
  network ( Index Term Link )
  reclaiming a device ( Index Term Link )
  repairing labels in internal databases ( Index Term Link )
  Solaris Management Console ( Index Term Link ) ( Index Term Link )
  Trusted Extensions configuration ( Index Term Link )
  trusted network ( Index Term Link )
  verifying interface is up ( Index Term Link )
  viewing ZFS dataset mounted in lower-level zone ( Index Term Link )
 
 Troubleshooting the Trusted Network (Task Map) ( Index Term Link )
 
 trusted applications, in a role workspace ( Index Term Link )
 
 trusted_edit trusted editor ( Index Term Link )
 
 trusted editor
  assigning your favorite editor ( Index Term Link )
  starting ( Index Term Link )
 
 Trusted Extensions
  See also Trusted Extensions planning
  collecting information before enabling ( Index Term Link )
  decisions to make before enabling ( Index Term Link )
  differences from Solaris administrator's perspective ( Index Term Link )
  differences from Solaris auditing ( Index Term Link )
  differences from Solaris OS ( Index Term Link )
  disabling ( Index Term Link )
  enabling ( Index Term Link )
  man pages quick reference ( Index Term Link )
  memory requirements ( Index Term Link )
  planning configuration strategy ( Index Term Link )
  planning for ( Index Term Link )
  planning hardware ( Index Term Link )
  planning network ( Index Term Link )
  preparing for ( Index Term Link ) ( Index Term Link )
  quick reference to administration ( Index Term Link )
  results before configuration ( Index Term Link )
  separation of duty ( Index Term Link )
  similarities with Solaris auditing ( Index Term Link )
  similarities with Solaris OS ( Index Term Link )
  two-role configuration strategy ( Index Term Link )
 
 Trusted Extensions configuration
  adding network databases to LDAP server ( Index Term Link )
  changing default DOI value ( Index Term Link )
  databases for LDAP ( Index Term Link )
  division of tasks ( Index Term Link )
  evaluated configuration ( Index Term Link )
  headless systems ( Index Term Link )
  initial procedures ( Index Term Link )
  initial setup team responsibilities ( Index Term Link )
  labeled zones ( Index Term Link )
  LDAP ( Index Term Link )
  reboot to activate labels ( Index Term Link )
  task maps ( Index Term Link )
  troubleshooting ( Index Term Link )
 
 Trusted Extensions network
  adding zone-specific interface ( Index Term Link )
  adding zone-specific nscd daemon ( Index Term Link )
  enabling IPv6 ( Index Term Link )
  planning ( Index Term Link )
  removing zone-specific nscd daemon ( Index Term Link )
  specifying default routes for labeled zones ( Index Term Link )
 
 Trusted Extensions requirements
  root password ( Index Term Link )
  Solaris installation ( Index Term Link )
  Solaris installed systems ( Index Term Link )
 
 trusted grab, key combination ( Index Term Link )
 
 trusted network
  0.0.0.0 tnrhdb entry ( Index Term Link )
  administering with Solaris Management Console ( Index Term Link )
  checking syntax of files ( Index Term Link )
  concepts ( Index Term Link )
  default labeling ( Index Term Link )
  editing local files ( Index Term Link )
  example of routing ( Index Term Link )
  host types ( Index Term Link )
  labels and MAC enforcement ( Index Term Link )
  using templates ( Index Term Link )
 
 Trusted Network tools
  description ( Index Term Link )
  using ( Index Term Link )
 
 Trusted Network Zones tool
  configuring a multilevel port ( Index Term Link )
  configuring a multilevel print server ( Index Term Link )
  creating a multilevel port ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link )
 
 Trusted Path, Device Manager ( Index Term Link )
 
 trusted path attribute, when available ( Index Term Link )
 
 Trusted Path menu, Assume Role ( Index Term Link )
 
 trusted programs
  adding ( Index Term Link )
  defined ( Index Term Link )
 
 trusted stripe
  on multiheaded system ( Index Term Link )
  warping pointer to ( Index Term Link )
 
 trustworthy programs ( Index Term Link )
 
 tsol_ldap.tbx file ( Index Term Link )
 
 tsol_separator.ps file
  configurable values ( Index Term Link )
  customizing labeled printing ( Index Term Link )
 
 tsoljdsselmgr application ( Index Term Link )
 
 txzonemgr script ( Index Term Link ) ( Index Term Link )
    
U
 
 unlabeled printing, configuring ( Index Term Link )
 
 updatehome command ( Index Term Link ) ( Index Term Link )
 
 Upgrade DragNDrop or CutPaste Info authorization ( Index Term Link )
 
 Upgrade File Label authorization ( Index Term Link )
 
 upgrading labels, configuring rules for selection confirmer ( Index Term Link )
 
 User Accounts tool ( Index Term Link )
 
 useradd command ( Index Term Link )
 
 users
  accessing devices ( Index Term Link ) ( Index Term Link )
  accessing printers ( Index Term Link )
  adding from NIS server ( Index Term Link )
  adding local user with useradd ( Index Term Link )
  assigning authorizations to ( Index Term Link )
  assigning labels ( Index Term Link )
  assigning passwords ( Index Term Link )
  assigning rights ( Index Term Link )
  assigning roles to ( Index Term Link )
  authorizations for ( Index Term Link )
  Change Password menu item ( Index Term Link )
  changing default privileges ( Index Term Link )
  creating ( Index Term Link )
  creating initial users ( Index Term Link )
  customizing environment ( Index Term Link )
  deletion precautions ( Index Term Link )
  labels of processes ( Index Term Link )
  lengthening timeout when relabeling ( Index Term Link )
  logging in remotely to the global zone ( Index Term Link )
  logging in to a failsafe session ( Index Term Link )
  modifying security defaults ( Index Term Link )
  modifying security defaults for all users ( Index Term Link )
  planning for ( Index Term Link )
  preventing account locking ( Index Term Link )
  preventing from seeing others' processes ( Index Term Link )
  printing ( Index Term Link )
  removing some privileges ( Index Term Link )
  requiring two roles to create user ( Index Term Link )
  requiring two roles to create users ( Index Term Link )
  restoring control of desktop focus ( Index Term Link )
  security precautions ( Index Term Link )
  security training ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  session range ( Index Term Link )
  setting up skeleton directories ( Index Term Link )
  startup files ( Index Term Link )
  using .copy_files file ( Index Term Link )
  using .link_files file ( Index Term Link )
  using devices ( Index Term Link )
 
 Using Devices in Trusted Extensions (Task Map) ( Index Term Link )
 
 /usr/bin/tsoljdsselmgr application ( Index Term Link )
 
 /usr/dt/bin/trusted_edit trusted editor ( Index Term Link )
 
 /usr/lib/lp/postscript/tsol_separator.ps file, labeling printer output ( Index Term Link )
 
 /usr/local/scripts/getmounts script ( Index Term Link )
 
 /usr/local/scripts/getzonelabels script ( Index Term Link )
 
 /usr/sbin/txzonemgr script ( Index Term Link ) ( Index Term Link )
 
 /usr/sbin/txzonemgr script ( Index Term Link ) ( Index Term Link )
 
 /usr/share/gnome/sel_config file ( Index Term Link )
 
 utadm command, default Sun Ray server configuration ( Index Term Link )
    
V
 
 VCL.xcu file ( Index Term Link )
 
 verifying
  interface is up ( Index Term Link )
  label_encodings file ( Index Term Link )
  roles are working ( Index Term Link )
  syntax of network databases ( Index Term Link )
  zone status ( Index Term Link )
 
 viewing, See accessing
 
 virtual network computing (vnc), See Xvnc systems running Trusted Extensions
    
W
 
 well-formed labels ( Index Term Link )
 
 wildcard address, See fallback mechanism
 
 workspaces
  color changes ( Index Term Link )
  colors indicating label of ( Index Term Link )
  global zone ( Index Term Link )
    
X
 
 X audit classes ( Index Term Link )
 
 xatom audit token ( Index Term Link )
 
 xc audit class ( Index Term Link )
 
 xclient audit token ( Index Term Link )
 
 xcolormap audit token ( Index Term Link )
 
 xcursor audit token ( Index Term Link )
 
 xfont audit token ( Index Term Link )
 
 xgc audit token ( Index Term Link )
 
 xp audit class ( Index Term Link )
 
 xpixmap audit token ( Index Term Link )
 
 xproperty audit token ( Index Term Link )
 
 xs audit class ( Index Term Link )
 
 xselect audit token ( Index Term Link )
 
 Xvnc systems running Trusted Extensions
  remote access to ( Index Term Link ) ( Index Term Link )
 
 xwindow audit token ( Index Term Link )
 
 xx audit class ( Index Term Link )
    
Z
 
 zenity script ( Index Term Link )
 
 ZFS
  adding dataset to labeled zone ( Index Term Link )
  fast zone creation method ( Index Term Link )
  mounting dataset read-write on labeled zone ( Index Term Link )
  viewing mounted dataset read-only from higher-level zone ( Index Term Link )
 
 /zone/public/etc/dfs/dfstab file ( Index Term Link )
 
 zones
  adding network interface ( Index Term Link )
  adding nscd daemon to each labeled zone ( Index Term Link )
  administering ( Index Term Link )
  administering from Trusted JDS ( Index Term Link )
  creating MLP ( Index Term Link )
  creating MLP for NFSv3 ( Index Term Link )
  deciding creation method ( Index Term Link )
  deleting ( Index Term Link )
  displaying labels of file systems ( Index Term Link )
  displaying status ( Index Term Link )
  enabling login to ( Index Term Link )
  global ( Index Term Link )
  in Trusted Extensions ( Index Term Link )
  isolating with default routes ( Index Term Link )
  managing ( Index Term Link )
  net_mac_aware privilege ( Index Term Link )
  removing nscd daemon from labeled zones ( Index Term Link )
  specifying default routes ( Index Term Link )
  specifying labels ( Index Term Link )
  specifying names ( Index Term Link )
  tool for labeling ( Index Term Link )
  troubleshooting access ( Index Term Link )
  txzonemgr script ( Index Term Link )
  /usr/sbin/txzonemgr script ( Index Term Link )
  verifying status ( Index Term Link )