Solaris Trusted Extensions Administrator's Procedures

Planning for Zones in Trusted Extensions

Trusted Extensions software is added to the Solaris OS in the global zone. You then configure non-global zones that are labeled. You can create one labeled zone for every unique label, though you do not need to create a zone for every label.

Part of zone configuration is configuring the network. Labeled zones must be configured to communicate with the global zone and with other zones on the network.

Trusted Extensions Zones and Solaris Zones

Labeled zones differ from typical Solaris zones. Labeled zones are primarily used to segregate data. In Trusted Extensions, regular users cannot remotely log in to a labeled zone. The only interactive interface to a labeled zone is by using the zone console. Only root can gain access to the zone console.

Zone Creation in Trusted Extensions

To create a labeled zone involves copying the entire Solaris OS, and then starting the services for the Solaris OS in every zone. The process can be time-consuming. A faster process is to create one zone, then to clone the contents of that zone. The following table describes your options for zone creation in Trusted Extensions.

Zone Creation Method 

Effort Required 

Characteristics of This Method 

Create each labeled zone from scratch. 

Configure, initialize, install, customize, and boot each labeled zone. 

  • This method is useful for creating one or two additional zones. The zones can be upgraded.

  • This method is time-consuming.

Create additional labeled zones from a ZFS snapshot of the first labeled zone.

Configure, initialize, install, and customize one zone. Use this zone as a ZFS snapshot for additional labeled zones. 

  • This method is the fastest method. This method makes every zone a file system, and thus provides isolation.