Oracle Solaris Trusted Extensions Configuration Guide
    
A
 
 accessing the X server ( Index Term Link )
 
 accounts
  creating ( Index Term Link )
  planning ( Index Term Link )
 
 Action failed. Reconnect to Solaris Zone? ( Index Term Link )
 
 actions, See administrative actions
 
 adding
  default routes for labeled zones ( Index Term Link )
  LDAP toolbox ( Index Term Link )
  local role with roleadd ( Index Term Link )
  local user with useradd ( Index Term Link )
  network databases to LDAP server ( Index Term Link )
  nscd daemon to every labeled zone ( Index Term Link )
  roles ( Index Term Link )
  shared network interfaces ( Index Term Link )
  Trusted Extensions to a Solaris system ( Index Term Link )
  users by using lpaddent ( Index Term Link )
  users who can assume roles ( Index Term Link )
  zone-specific network interface ( Index Term Link )
  zone-specific nscd daemon ( Index Term Link )
 
 Additional Trusted Extensions Configuration Tasks ( Index Term Link )
 
 addresses
  sharing between global and labeled zones ( Index Term Link )
  specifying one IP address per system ( Index Term Link ) ( Index Term Link )
 
 administering, remotely by a role ( Index Term Link )
 
 administrative actions
  Check Encodings ( Index Term Link )
  Clone Zone ( Index Term Link )
  Configure Zone ( Index Term Link )
  Copy Zone ( Index Term Link )
  Create LDAP Client ( Index Term Link )
  Initialize Zone for LDAP ( Index Term Link )
  Install Zone ( Index Term Link )
  Share Logical Interface ( Index Term Link )
  Share Physical Interface ( Index Term Link )
  Shut Down Zone ( Index Term Link )
  Start Zone ( Index Term Link )
  Zone Terminal Console ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 allocating devices
  for copying data ( Index Term Link )
  tape drive ( Index Term Link )
 
 Associating Network Interfaces With Zones by Using CDE Actions (Task Map) ( Index Term Link )
 
 audit planning ( Index Term Link )
 
 auditing, planning ( Index Term Link )
    
B
 
 backing up, previous system before installation ( Index Term Link )
 
 booting
  zones ( Index Term Link ) ( Index Term Link )
    
C
 
 Cannot reach global zone ( Index Term Link )
 
 Check Encodings action ( Index Term Link )
 
 checking
  label_encodings file ( Index Term Link )
  roles are working ( Index Term Link )
 
 checklists for initial setup team ( Index Term Link )
 
 chk_encodings command ( Index Term Link )
 
 Clone Zone action ( Index Term Link )
 
 collecting information
  before enabling Trusted Extensions ( Index Term Link )
  for LDAP service ( Index Term Link )
  planning Trusted Extensions configuration ( Index Term Link )
 
 configuration files, copying ( Index Term Link )
 
 Configure Zone action ( Index Term Link )
 
 configuring
  access to headless Trusted Extensions ( Index Term Link )
  as a role or as superuser? ( Index Term Link )
  LDAP for Trusted Extensions ( Index Term Link )
  LDAP proxy server for Trusted Extensions clients ( Index Term Link )
  network interfaces ( Index Term Link )
  Solaris Management Console for LDAP ( Index Term Link )
  Trusted Extensions labeled zones ( Index Term Link ) ( Index Term Link )
  Trusted Extensions software ( Index Term Link )
 
 Configuring an LDAP Proxy Server on a Trusted Extensions Host (Task Map) ( Index Term Link )
 
 Configuring an LDAP Server on a Trusted Extensions Host (Task Map) ( Index Term Link )
 
 Configuring the Solaris Management Console for LDAP (Task Map) ( Index Term Link )
 
 configuring Trusted Extensions
  checklist for install team ( Index Term Link )
  headless access ( Index Term Link )
  initial procedures ( Index Term Link )
  labeled zones ( Index Term Link ) ( Index Term Link )
  task maps ( Index Term Link )
 
 console window, troubleshooting not opening ( Index Term Link )
 
 Copy Zone action ( Index Term Link )
 
 Create a new zone menu item ( Index Term Link ) ( Index Term Link )
 
 Create LDAP Client action ( Index Term Link )
 
 creating
  accounts ( Index Term Link )
  accounts during or after configuration ( Index Term Link )
  home directories ( Index Term Link )
  home directory server ( Index Term Link )
  labeled zones ( Index Term Link )
  LDAP client ( Index Term Link )
  LDAP proxy server for Trusted Extensions clients ( Index Term Link )
  LDAP toolbox ( Index Term Link )
  local role with roleadd ( Index Term Link )
  local user with useradd ( Index Term Link )
  roles ( Index Term Link )
  users who can assume roles ( Index Term Link )
  zones ( Index Term Link ) ( Index Term Link )
 
 Creating Labeled Zones ( Index Term Link )
 
 Creating the Labeled Zones by Using CDE Actions (Task Map) ( Index Term Link )
 
 credentials, registering LDAP with the Solaris Management Console ( Index Term Link )
    
D
 
 deciding
  to configure as a role or as superuser ( Index Term Link )
  to use a Sun-supplied encodings file ( Index Term Link )
 
 decisions to make
  based on site security policy ( Index Term Link )
  before enabling Trusted Extensions ( Index Term Link )
 
 default routes, specifying for labeled zones ( Index Term Link )
 
 deleting, labeled zones ( Index Term Link )
 
 directories, for naming service setup ( Index Term Link )
 
 disabling, Trusted Extensions ( Index Term Link )
 
 domain of interpretation (DOI), entry in /etc/system file ( Index Term Link )
 
 dpadm service ( Index Term Link )
 
 dsadm service ( Index Term Link )
    
E
 
 enabling
  DOI different from 1 ( Index Term Link )
  dpadm service ( Index Term Link )
  dsadm service ( Index Term Link )
  IPv6 network ( Index Term Link )
  labeld service ( Index Term Link )
  LDAP administration from a client ( Index Term Link )
  login to labeled zone ( Index Term Link )
  Trusted Extensions on a Solaris system ( Index Term Link )
 
 encodings file, See label_encodings file
 
 error messages
  troubleshooting ( Index Term Link ) ( Index Term Link )
 
 /etc/system file
  modifying for DOI different from 1 ( Index Term Link )
  modifying for IPv6 network ( Index Term Link )
    
F
 
 files
  copying from removable media ( Index Term Link )
  resolv.conf ( Index Term Link )
    
H
 
 hardware planning ( Index Term Link )
 
 Headless System Configuration in Trusted Extensions (Task Map) ( Index Term Link )
 
 home directories
  creating ( Index Term Link )
  creating server for ( Index Term Link )
  logging in and getting ( Index Term Link )
    
I
 
 initial setup team, checklist for configuring Trusted Extensions ( Index Term Link )
 
 Initialize Zone for LDAP action ( Index Term Link )
 
 initializing
  Solaris Management Console ( Index Term Link )
  zones ( Index Term Link )
  zones for LDAP ( Index Term Link )
 
 Install Zone action ( Index Term Link )
  troubleshooting ( Index Term Link )
 
 installation menu
  Create a new zone ( Index Term Link ) ( Index Term Link )
  Zone Console ( Index Term Link )
 
 installing
  label_encodings file ( Index Term Link )
  Solaris OS for Trusted Extensions ( Index Term Link )
  Sun Java System Directory Server ( Index Term Link )
  zones ( Index Term Link ) ( Index Term Link )
 
 IPv6
  entry in /etc/system file ( Index Term Link )
  troubleshooting ( Index Term Link )
    
L
 
 label_encodings file
  checking ( Index Term Link )
  installing ( Index Term Link )
  localizing ( Index Term Link )
  modifying ( Index Term Link )
 
 labeld service ( Index Term Link )
  disabling ( Index Term Link )
  troubleshooting ( Index Term Link )
 
 Labeled Zone Manager, See txzonemgr script
 
 labeling
  turning on labels ( Index Term Link )
  zones ( Index Term Link ) ( Index Term Link )
 
 labels
  assigning to named zones ( Index Term Link ) ( Index Term Link )
  on trusted stripe ( Index Term Link )
  planning ( Index Term Link )
  specifying for zones ( Index Term Link ) ( Index Term Link )
 
 LDAP
  enabling administration from a client ( Index Term Link )
  planning ( Index Term Link )
 
 LDAP configuration
  creating client ( Index Term Link )
  for Trusted Extensions ( Index Term Link )
  Sun Ray servers, and ( Index Term Link )
 
 LDAP server
  collecting information for ( Index Term Link )
  configuring multilevel port ( Index Term Link )
  configuring naming service ( Index Term Link )
  configuring proxy for Trusted Extensions clients ( Index Term Link )
  creating proxy for Trusted Extensions clients ( Index Term Link )
  installing in Trusted Extensions ( Index Term Link )
  planning for separation of duty ( Index Term Link )
  protecting log files ( Index Term Link )
  registering credentials with Solaris Management Console ( Index Term Link )
 
 log files, protecting Directory Server logs ( Index Term Link )
 
 logging in
  to a home directory server ( Index Term Link )
  using rlogin command ( Index Term Link )
 
 login, remote ( Index Term Link )
 
 lpaddent command ( Index Term Link )
    
M
 
 media, copying files from removable ( Index Term Link )
 
 modifying, label_encodings file ( Index Term Link )
 
 multilevel server, planning ( Index Term Link )
    
N
 
 name service cache daemon, See nscd daemon
 
 names
  specifying for zones ( Index Term Link ) ( Index Term Link )
 
 naming
  zones ( Index Term Link ) ( Index Term Link )
 
 network, See Trusted Extensions network
 
 No route available ( Index Term Link )
 
 nscd daemon, adding to every labeled zone ( Index Term Link )
    
P
 
 planning
  See also Trusted Extensions use
  account creation ( Index Term Link )
  administration strategy ( Index Term Link )
  auditing ( Index Term Link )
  data migration ( Index Term Link )
  hardware ( Index Term Link )
  labels ( Index Term Link )
  LDAP naming service ( Index Term Link )
  network ( Index Term Link )
  NFS server ( Index Term Link )
  printing ( Index Term Link )
  Trusted Extensions ( Index Term Link )
  Trusted Extensions configuration strategy ( Index Term Link )
  zones ( Index Term Link )
 
 Preparing to Create Zones by Using CDE Actions (Task Map) ( Index Term Link )
 
 printing, planning ( Index Term Link )
 
 publications, security and UNIX ( Index Term Link )
    
R
 
 rebooting
  activating labels ( Index Term Link )
  enabling login to labeled zone ( Index Term Link )
 
 registering, LDAP credentials with the Solaris Management Console ( Index Term Link )
 
 remote logins, enabling for roles ( Index Term Link )
 
 removing, zone-specific nscd daemon ( Index Term Link )
 
 removing Trusted Extensions, See disabling
 
 requirements for Trusted Extensions
  Solaris installation options ( Index Term Link )
  Solaris installed systems ( Index Term Link )
 
 resolv.conf file, loading during configuration ( Index Term Link )
 
 rights profiles, customizing for separation of duty ( Index Term Link )
 
 roadmaps
  Task Map: Configuring Trusted Extensions ( Index Term Link )
  Task Map: Preparing a Solaris System for Trusted Extensions ( Index Term Link )
  Task Map: Preparing For and Enabling Trusted Extensions ( Index Term Link )
 
 roleadd command ( Index Term Link )
 
 roles
  adding local role with roleadd ( Index Term Link )
  creating Security Administrator ( Index Term Link )
  determining when to create ( Index Term Link )
  logging in remotely ( Index Term Link )
  separation of duty ( Index Term Link ) ( Index Term Link )
  verifying they work ( Index Term Link )
 
 root passwords, required in Trusted Extensions ( Index Term Link )
 
 routing, specifying default routes for labeled zones ( Index Term Link )
    
S
 
 screens, initial display ( Index Term Link )
 
 security
  initial setup team ( Index Term Link )
  publications ( Index Term Link )
  root password ( Index Term Link )
  site security policy ( Index Term Link )
 
 Security Administrator role, creating ( Index Term Link )
 
 separation of duty
  creating rights profiles ( Index Term Link )
  planning for ( Index Term Link )
  planning for LDAP ( Index Term Link )
 
 service management framework (SMF)
  dpadm ( Index Term Link )
  dsadm ( Index Term Link )
  labeld service ( Index Term Link )
 
 Share Logical Interface action ( Index Term Link )
 
 Share Physical Interface action ( Index Term Link )
 
 Shut Down Zone action ( Index Term Link )
 
 site security policy
  common violations ( Index Term Link )
  personnel recommendations ( Index Term Link )
  physical access recommendations ( Index Term Link )
  recommendations ( Index Term Link )
  tasks involved ( Index Term Link )
  Trusted Extensions configuration decisions ( Index Term Link )
  understanding ( Index Term Link )
 
 Solaris installation options, requirements ( Index Term Link )
 
 Solaris installed systems, requirements for Trusted Extensions ( Index Term Link )
 
 Solaris Management Console
  configuring for LDAP ( Index Term Link )
  configuring LDAP toolbox ( Index Term Link )
  enabling LDAP toolbox to be used ( Index Term Link )
  initializing ( Index Term Link )
  loading a Trusted Extensions toolbox ( Index Term Link )
  registering LDAP credentials ( Index Term Link )
  troubleshooting ( Index Term Link ) ( Index Term Link )
  using Trusted Network Zone Configuration tool ( Index Term Link ) ( Index Term Link )
  working with Sun Java System Directory Server ( Index Term Link )
 
 Solaris Trusted Extensions, See Trusted Extensions
 
 Start Zone action ( Index Term Link )
 
 starting
  zones ( Index Term Link ) ( Index Term Link )
 
 Sun Java System Directory Server, See LDAP server
 
 Sun Ray systems
  LDAP servers, and ( Index Term Link )
  web site for documentation ( Index Term Link )
 
 svcs: Pattern 'labeld' doesn't match any instances ( Index Term Link )
 
 System Administrator role, restricting ( Index Term Link )
    
T
 
 tape devices, allocating ( Index Term Link )
 
 Task Map: Configuring Trusted Extensions ( Index Term Link )
 
 Task Map: Preparing a Solaris System for Trusted Extensions ( Index Term Link )
 
 Task Map: Preparing For and Enabling Trusted Extensions ( Index Term Link )
 
 tasks and task maps
  Additional Trusted Extensions Configuration Tasks ( Index Term Link )
  Associating Network Interfaces With Zones by Using CDE Actions (Task Map) ( Index Term Link )
  Configuring an LDAP Proxy Server on a Trusted Extensions Host (Task Map) ( Index Term Link )
  Configuring an LDAP Server on a Trusted Extensions Host (Task Map) ( Index Term Link )
  Configuring the Solaris Management Console for LDAP (Task Map) ( Index Term Link )
  Creating Labeled Zones ( Index Term Link )
  Creating the Labeled Zones by Using CDE Actions (Task Map) ( Index Term Link )
  Headless System Configuration in Trusted Extensions (Task Map) ( Index Term Link )
  Preparing to Create Zones by Using CDE Actions (Task Map) ( Index Term Link )
 
 tcp_listen=true LDAP setting ( Index Term Link )
 
 toolboxes
  adding LDAP server to tsol_ldap.tbx ( Index Term Link )
  loading in Trusted Extensions ( Index Term Link )
  Scope=LDAP ( Index Term Link )
 
 troubleshooting
  accessing X server ( Index Term Link )
  console window not opening ( Index Term Link )
  Installation of these packages generated errors: SUNWpkgname ( Index Term Link ) ( Index Term Link )
  IPv6 configuration ( Index Term Link )
  Solaris Management Console ( Index Term Link ) ( Index Term Link )
  Solaris release that supports the labeld service ( Index Term Link )
  Trusted Extensions configuration ( Index Term Link )
  Trusted Network Zones Properties ( Index Term Link )
 
 Trusted Extensions
  See also Trusted Extensions planning
  collecting information before enabling ( Index Term Link )
  decisions to make before enabling ( Index Term Link )
  differences from Solaris administrator's perspective ( Index Term Link )
  disabling ( Index Term Link )
  enabling ( Index Term Link )
  memory requirements ( Index Term Link )
  planning configuration strategy ( Index Term Link )
  planning for ( Index Term Link )
  planning hardware ( Index Term Link )
  planning network ( Index Term Link )
  preparing for ( Index Term Link ) ( Index Term Link )
  results before configuration ( Index Term Link )
  separation of duty ( Index Term Link )
  two-role configuration strategy ( Index Term Link )
 
 Trusted Extensions configuration
  adding network databases to LDAP server ( Index Term Link )
  changing default DOI value ( Index Term Link )
  databases for LDAP ( Index Term Link )
  division of tasks ( Index Term Link )
  evaluated configuration ( Index Term Link )
  headless systems ( Index Term Link )
  initial procedures ( Index Term Link )
  initial setup team responsibilities ( Index Term Link )
  labeled zones ( Index Term Link ) ( Index Term Link )
  LDAP ( Index Term Link )
  reboot to activate labels ( Index Term Link )
  task maps ( Index Term Link )
  troubleshooting ( Index Term Link )
 
 Trusted Extensions network
  adding zone-specific interface ( Index Term Link )
  adding zone-specific nscd daemon ( Index Term Link )
  enabling IPv6 ( Index Term Link )
  planning ( Index Term Link )
  removing zone-specific nscd daemon ( Index Term Link )
  specifying default routes for labeled zones ( Index Term Link )
 
 Trusted Extensions requirements
  root password ( Index Term Link )
  Solaris installation ( Index Term Link )
  Solaris installed systems ( Index Term Link )
 
 Trusted Network Zones tool
  assigning labels to named zones ( Index Term Link ) ( Index Term Link )
  troubleshooting ( Index Term Link )
 
 tsol_ldap.tbx file ( Index Term Link )
 
 txzonemgr script ( Index Term Link ) ( Index Term Link )
    
U
 
 useradd command ( Index Term Link )
 
 users
  adding from NIS server ( Index Term Link )
  adding local user with useradd ( Index Term Link )
  creating initial users ( Index Term Link )
  requiring two roles to create user ( Index Term Link )
  requiring two roles to create users ( Index Term Link )
 
 /usr/sbin/txzonemgr script ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
    
V
 
 verifying
  label_encodings file ( Index Term Link )
  roles are working ( Index Term Link )
  zone status ( Index Term Link )
    
W
 
 workspaces, initial display ( Index Term Link )
    
Z
 
 zenity script ( Index Term Link )
 
 ZFS, unsupported but fast zone creation method ( Index Term Link )
 
 ZFS pools, creating for cloning zones ( Index Term Link )
 
 Zone Console, output ( Index Term Link )
 
 Zone Terminal Console action
  output ( Index Term Link ) ( Index Term Link )
  using ( Index Term Link )
 
 zones
  adding network interface ( Index Term Link )
  adding nscd daemon to each labeled zone ( Index Term Link )
  associating zone names with labels ( Index Term Link ) ( Index Term Link )
  booting ( Index Term Link ) ( Index Term Link )
  creating ( Index Term Link )
  creating ZFS pool for cloning ( Index Term Link )
  customizing ( Index Term Link )
  deciding creation method ( Index Term Link )
  deleting ( Index Term Link )
  enabling login to ( Index Term Link )
  halting ( Index Term Link )
  initializing ( Index Term Link )
  initializing for LDAP ( Index Term Link )
  installing ( Index Term Link ) ( Index Term Link )
  isolating with default routes ( Index Term Link )
  removing nscd daemon from labeled zones ( Index Term Link )
  showing zone activity ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  shutting down ( Index Term Link )
  specifying a shared IP address ( Index Term Link )
  specifying default routes ( Index Term Link )
  specifying labels ( Index Term Link ) ( Index Term Link )
  specifying names ( Index Term Link ) ( Index Term Link )
  specifying one IP address for all zones ( Index Term Link ) ( Index Term Link )
  starting ( Index Term Link )
  troubleshooting access ( Index Term Link )
  troubleshooting installation ( Index Term Link )
  txzonemgr script ( Index Term Link )
  /usr/sbin/txzonemgr script ( Index Term Link ) ( Index Term Link )
  verifying status ( Index Term Link )