Solaris Trusted Extensions User's Guide
    
A
 
 access control
  access control lists (ACLs) ( Index Term Link )
  discretionary access control (DAC) ( Index Term Link )
  mandatory access control (MAC) ( Index Term Link )
  permission bits ( Index Term Link )
 
 access control lists (ACLs) ( Index Term Link )
 
 accessing
  for read only ( Index Term Link )
  for reading and writing ( Index Term Link )
  for writing ( Index Term Link )
  initialization files at every label ( Index Term Link )
  lower-level home directories ( Index Term Link )
  man pages in Trusted Extensions ( Index Term Link )
  remote multilevel desktop ( Index Term Link )
 
 adding
  labeled workspace ( Index Term Link )
  workspaces ( Index Term Link )
 
 admin role, See System Administrator role
 
 Allocate Device menu item ( Index Term Link )
 
 allocating
  media for formatting ( Index Term Link )
  removable media ( Index Term Link )
 
 allocating a device ( Index Term Link )
  troubleshooting ( Index Term Link )
 
 Application Manager security in Trusted Extensions ( Index Term Link )
 
 Assume rolename role menu item ( Index Term Link )
 
 assuming a role ( Index Term Link )
 
 authorizations
  changing labels ( Index Term Link )
  for allocating devices ( Index Term Link )
  required to change label of data ( Index Term Link )
    
C
 
 calendar security in Trusted Extensions ( Index Term Link )
 
 CDE, trusted applications on Front Panel ( Index Term Link )
 
 Change Password menu item ( Index Term Link )
 
 Change Workspace Label menu item ( Index Term Link )
 
 changing
  labels by authorized users ( Index Term Link )
  security level of data ( Index Term Link ) ( Index Term Link )
  workspace label ( Index Term Link )
  your password ( Index Term Link )
 
 changing labels, troubleshooting ( Index Term Link )
 
 choosing
  a desktop ( Index Term Link ) ( Index Term Link )
  label or clearance during login ( Index Term Link )
 
 classification component of label, defined ( Index Term Link )
 
 clearances
  label type ( Index Term Link )
  setting at login ( Index Term Link ) ( Index Term Link )
  setting session ( Index Term Link )
 
 clock security in Trusted Extensions ( Index Term Link )
 
 compartment component of label, defined ( Index Term Link )
 
 containers, See zones
 
 copy-and-paste, effect on labels ( Index Term Link )
 
 .copy_files file
  creating ( Index Term Link )
  described ( Index Term Link )
  troubleshooting ( Index Term Link )
 
 creating
  $HOME/.copy_files file ( Index Term Link )
  $HOME/.link_files file ( Index Term Link )
 
 customizing
  desktop ( Index Term Link )
  Workspace Menu ( Index Term Link )
    
D
 
 data
  changing label of ( Index Term Link )
  determining label of ( Index Term Link )
  protecting with MAC ( Index Term Link )
 
 deallocating devices, basic procedure ( Index Term Link )
 
 desktops
  common tasks ( Index Term Link )
  in Trusted Extensions ( Index Term Link )
  keyboard focus ( Index Term Link )
  logging in remotely ( Index Term Link )
 
 determining
  label of a file ( Index Term Link )
  label of a window ( Index Term Link )
 
 Device Allocation Manager, deallocating devices ( Index Term Link )
 
 devices
  allocating ( Index Term Link )
  clearing prior to reuse ( Index Term Link )
  protecting ( Index Term Link )
  troubleshooting ( Index Term Link )
  using ( Index Term Link )
  using removable media ( Index Term Link )
 
 directories
  changing labels ( Index Term Link )
  visibility of home directories ( Index Term Link )
 
 discretionary access control (DAC), defined ( Index Term Link )
 
 dominance between labels ( Index Term Link )
 
 downgrading information ( Index Term Link )
 
 drag-and-drop, effect on labels ( Index Term Link )
    
E
 
 email, label enforcement ( Index Term Link )
 
 email instructions, user responsibilities ( Index Term Link )
    
F
 
 failsafe login ( Index Term Link )
 
 File Browser
  changing labels ( Index Term Link )
  displaying label of file ( Index Term Link )
  troubleshooting when it does not appear ( Index Term Link )
  viewing contents ( Index Term Link ) ( Index Term Link )
 
 File Manager
  changing file labels ( Index Term Link )
  changing labels ( Index Term Link )
  security in Trusted Extensions ( Index Term Link )
  troubleshooting when it does not appear ( Index Term Link )
  viewing contents ( Index Term Link )
 
 files
  $HOME/.copy_files ( Index Term Link ) ( Index Term Link )
  $HOME/.link_files ( Index Term Link ) ( Index Term Link )
  accessing initialization files at every label ( Index Term Link )
  changing labels ( Index Term Link )
  linking between File Managers at different labels ( Index Term Link )
  moving between File Managers ( Index Term Link )
  viewing in a workspace ( Index Term Link )
 
 finding
  calendar events at every label ( Index Term Link )
  online help for Trusted Extensions ( Index Term Link )
  Trusted Path menu ( Index Term Link ) ( Index Term Link )
 
 formatting, removable media ( Index Term Link )
 
 Front Panel
  description of trusted applications on ( Index Term Link )
  restoring when minimized ( Index Term Link )
    
H
 
 help in Trusted Extensions
  man pages ( Index Term Link )
  online help ( Index Term Link )
 
 home directories, visible from higher-level zone ( Index Term Link )
 
 hot key, regaining control of desktop focus ( Index Term Link )
    
I
 
 information, See data
 
 initialization files
  accessing at every label ( Index Term Link )
  troubleshooting when customized ( Index Term Link )
    
K
 
 key combinations, testing if grab is trusted ( Index Term Link )
    
L
 
 label ranges
  described ( Index Term Link )
  troubleshooting a workstation with a restricted range ( Index Term Link )
 
 labels
  See also clearances
  changing label of data ( Index Term Link )
  changing label of files ( Index Term Link )
  changing label on information ( Index Term Link )
  components ( Index Term Link )
  determining by window query ( Index Term Link )
  displayed in Trusted Extensions ( Index Term Link )
  displayed on desktop ( Index Term Link )
  dominance ( Index Term Link )
  labeled zones ( Index Term Link )
  means of protecting data ( Index Term Link )
  ranges ( Index Term Link )
  relationships ( Index Term Link )
  sample government labels ( Index Term Link )
  sample industry labels ( Index Term Link )
  sample label relationships ( Index Term Link )
  setting at login ( Index Term Link )
  setting clearance at login ( Index Term Link )
  setting session labels ( Index Term Link ) ( Index Term Link )
  types ( Index Term Link )
  visible on desktop ( Index Term Link )
 
 .link_files file
  creating ( Index Term Link )
  described ( Index Term Link )
  troubleshooting ( Index Term Link )
 
 linking files at different labels ( Index Term Link )
  by using .link_files ( Index Term Link )
 
 logging in
  at a different label ( Index Term Link )
  choosing a desktop ( Index Term Link ) ( Index Term Link )
  choosing a label or clearance ( Index Term Link )
  failsafe ( Index Term Link )
  five steps of ( Index Term Link )
  remotely to multilevel desktop ( Index Term Link )
  reviewing security settings ( Index Term Link )
  troubleshooting ( Index Term Link ) ( Index Term Link )
 
 logging out
  procedure ( Index Term Link )
  user responsibilities ( Index Term Link )
 
 login process, See logging in
    
M
 
 mail security in Trusted Extensions ( Index Term Link )
 
 Main Menu, Shut Down ( Index Term Link )
 
 man pages in Trusted Extensions ( Index Term Link )
 
 mandatory access control (MAC)
  defined ( Index Term Link )
  enforced for email ( Index Term Link )
 
 mounting, removable media ( Index Term Link )
 
 moving
  a window to a workspace at a different label ( Index Term Link )
  data to different label ( Index Term Link )
  file to different label ( Index Term Link )
 
 multiheaded system, trusted stripe ( Index Term Link )
 
 multilevel login
  remote ( Index Term Link )
  Trusted GNOME ( Index Term Link )
 
 multilevel sessions, defined ( Index Term Link )
    
N
 
 no trusted indicator, troubleshooting ( Index Term Link )
 
 no trusted stripe, troubleshooting ( Index Term Link )
 
 Not Found error message ( Index Term Link )
 
 Not in Profile error message ( Index Term Link )
    
O
 
 object
  defined ( Index Term Link )
  reuse ( Index Term Link )
 
 oper role, See Operator role
 
 Operator role, responsibilities ( Index Term Link )
    
P
 
 passwords, user responsibilities ( Index Term Link )
 
 peripheral devices, See devices
 
 permissions
  at discretion of file owner ( Index Term Link )
  user responsibilities ( Index Term Link )
 
 pfsh command, See profile shell
 
 policy, See security policy
 
 Printer tool security in Trusted Extensions ( Index Term Link )
 
 printing, typical labeled banner page ( Index Term Link )
 
 procedures, See users
 
 profile shell, defined ( Index Term Link )
 
 profiles, See rights profiles
 
 protecting files
  by label ( Index Term Link )
  DAC ( Index Term Link )
  MAC ( Index Term Link )
  user responsibilities ( Index Term Link )
    
Q
 
 Query Window Label menu item ( Index Term Link )
    
R
 
 read access, in labeled environment ( Index Term Link )
 
 remote login, to multilevel desktop ( Index Term Link )
 
 responsibilities
  of administrators ( Index Term Link )
  users for password security ( Index Term Link )
  users to clear media ( Index Term Link )
  users to protect data ( Index Term Link )
  users when logging out ( Index Term Link )
 
 reviewing security settings
  Last Login dialog box ( Index Term Link )
  procedure during login ( Index Term Link )
 
 rights profiles, defined ( Index Term Link )
 
 roles
  adding a labeled workspace ( Index Term Link )
  changing workspace label ( Index Term Link )
  common roles ( Index Term Link )
  responsibilities of ( Index Term Link )
  special user account ( Index Term Link )
 
 root role, responsibilities ( Index Term Link )
    
S
 
 secadmin role, See Security Administrator role
 
 Security Administrator role
  contacting about missing trusted indicator ( Index Term Link )
  contacting about missing trusted stripe ( Index Term Link )
  responsibilities ( Index Term Link )
 
 security policy
  defined ( Index Term Link ) ( Index Term Link )
 
 security practices, defined ( Index Term Link )
 
 selection, changing label ( Index Term Link )
 
 Selection Manager ( Index Term Link )
 
 sensitivity labels
  See labels
  label type ( Index Term Link )
 
 session clearances, defined ( Index Term Link )
 
 sessions
  choosing clearance ( Index Term Link )
  effect of selecting level ( Index Term Link )
  setting level ( Index Term Link )
  single-level or multilevel ( Index Term Link )
 
 Shut Down menu item ( Index Term Link )
 
 shutting down a workstation ( Index Term Link )
 
 single-level login, Trusted GNOME ( Index Term Link )
 
 single-level sessions, defined ( Index Term Link )
 
 Solaris Trusted Extensions (CDE), See CDE
 
 spoofing
  defined ( Index Term Link ) ( Index Term Link )
 
 Stop-A (L1-A) keyboard combination ( Index Term Link )
 
 Style Manager
  changing session characteristics ( Index Term Link )
  limitations in Solaris Trusted Extensions (CDE) ( Index Term Link )
  requires the trusted path ( Index Term Link )
 
 subject, defined ( Index Term Link )
 
 Suspend System menu item ( Index Term Link )
 
 switching to a workspace at a different label ( Index Term Link )
 
 system administration, on Trusted Extensions ( Index Term Link )
 
 System Administrator role, responsibilities ( Index Term Link )
    
T
 
 tasks, See users
 
 Text Editor security in Trusted Extensions ( Index Term Link )
 
 Trash Can security in Trusted Extensions ( Index Term Link )
 
 troubleshooting
  $HOME/.copy_files file ( Index Term Link )
  $HOME/.link_files file ( Index Term Link )
  command line error messages ( Index Term Link )
  device allocation ( Index Term Link )
  File Manager not appearing ( Index Term Link )
  login ( Index Term Link )
  minimized Front Panel ( Index Term Link )
  missing trusted indicator ( Index Term Link )
  missing trusted stripe ( Index Term Link )
  password failure ( Index Term Link )
  relabeling files ( Index Term Link )
 
 trusted applications
  by using rights profiles ( Index Term Link )
  on Front Panel ( Index Term Link )
 
 Trusted CDE
  customizing the desktop ( Index Term Link )
  customizing the Workspace Menu ( Index Term Link )
  finding online help for Trusted Extensions ( Index Term Link )
  using the Style Manager ( Index Term Link )
 
 trusted computing base (TCB)
  defined ( Index Term Link )
  procedures that interact with the TCB ( Index Term Link )
  symbol of interacting with ( Index Term Link ) ( Index Term Link )
 
 Trusted Extensions
  overview ( Index Term Link )
  visible features ( Index Term Link )
 
 Trusted GNOME
  customizing the desktop ( Index Term Link )
  online help ( Index Term Link )
  workspace security ( Index Term Link )
 
 trusted grab, key combination ( Index Term Link )
 
 trusted indicator, missing ( Index Term Link )
 
 Trusted Path menu
  Allocate Device ( Index Term Link )
  Assume rolename role ( Index Term Link )
  Change Password ( Index Term Link )
  Change Workspace Label ( Index Term Link )
  described ( Index Term Link )
  location ( Index Term Link )
  Query Window Label ( Index Term Link )
  using ( Index Term Link )
 
 trusted stripe
  described ( Index Term Link )
  location in CDE ( Index Term Link ) ( Index Term Link )
  location in Trusted GNOME ( Index Term Link )
  not on lockscreen ( Index Term Link )
  on multiheaded system ( Index Term Link )
  what to do if missing ( Index Term Link )
 
 trusted symbol
  described ( Index Term Link )
  on Trusted CDE workspace ( Index Term Link )
  tamper-proof icon ( Index Term Link )
 
 types of labels ( Index Term Link )
    
U
 
 unlabeled screens
  lockscreen ( Index Term Link )
  login screen ( Index Term Link )
 
 upgrading information ( Index Term Link )
 
 user clearances, defined ( Index Term Link )
 
 user responsibilities
  password security ( Index Term Link )
  protecting data ( Index Term Link )
  when leaving workstation ( Index Term Link )
 
 users
  accessing initialization files at every label ( Index Term Link )
  adding a labeled workspace ( Index Term Link )
  allocating a device ( Index Term Link )
  assuming a role ( Index Term Link )
  authorized to change label of file ( Index Term Link )
  authorized to change security level of data ( Index Term Link )
  changing workspace label ( Index Term Link )
  changing your password ( Index Term Link )
  customizing the Workspace Menu ( Index Term Link )
  determining the label of a file ( Index Term Link )
  finding online help for Trusted Extensions ( Index Term Link )
  getting online help ( Index Term Link )
  linking files at different labels ( Index Term Link )
  locking your screen ( Index Term Link )
  logging in at a different label ( Index Term Link )
  logging out ( Index Term Link )
  moving a window to a workspace at a different label ( Index Term Link )
  moving data between labels ( Index Term Link )
  moving files between labels ( Index Term Link )
  responsibilities
   clearing devices ( Index Term Link )
   password security ( Index Term Link )
   protecting data ( Index Term Link )
   when leaving workstation ( Index Term Link )
  shutting down a workstation ( Index Term Link )
  switching to a workspace at a different label ( Index Term Link )
  unlocking your screen ( Index Term Link )
  viewing files in a workspace ( Index Term Link )
 
 using a device, See allocating a device
 
 using trusted desktop, single-level or multilevel ( Index Term Link )
    
V
 
 visibility
  desktop security ( Index Term Link )
  labels after login ( Index Term Link )
  reading lower-level home directories ( Index Term Link )
  trusted stripe ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
    
W
 
 Window Label indicator ( Index Term Link )
 
 Workspace Menu
  customizing ( Index Term Link )
  Suspend System ( Index Term Link )
 
 workspace switch area
  illustration ( Index Term Link )
  in Trusted Extensions CDE ( Index Term Link )
 
 workspaces
  labeled ( Index Term Link )
  setting default label ( Index Term Link )
 
 write access, in labeled environment ( Index Term Link )
    
Z
 
 zones
  home directory visibility ( Index Term Link )
  labeled ( Index Term Link )