Documentation Home
> Trusted Solaris Label Administration
Trusted Solaris Label Administration
Book Information
Preface
Chapter 1 Introduction to Trusted Solaris Label Encodings
When Using Either a Government-furnished or Already-Existing Labels File
If Your Site Does Not Have a Labels File
After Installation
Before Installation
Creating Labels With Complex Relationships
Review of Label-Encodings Related Concepts
How Labels Are Used
How Labels Are Defined
Introduction to Clearances, Minimum Labels, and Account Label Ranges
Account Label Range
Two Types of Clearance
Session Clearance
Label Ranges on Things Being Accessed
What Labels Ranges Do
Types of Labels
Classifications
Words
Compartments
Examples of Compartments
How Compartment Words Are Defined
Sensitivity Labels (SLs): Uses and Format
Sensitivity Label Components
Sensitivity Label Internal Representation
Authorizations for Upgrading and Downgrading SLs
Restricting Users to a Single Label
Specifying the Session Clearance
Labeled Workspaces
More About Clearance Labels
Clearance Label Components
Clearance Labels' Internal Representation
How SLs and Clearances Are Used in Access Control Decisions
Example Mandatory Access Control Decision
Label Dominance
Label Translation
Information Labels in Trusted Solaris 7
Avoiding Abbreviations and Acronyms in Labels
Administrative Labels
Issues About the Names of Administrative Labels
Changing the Administrative Labels' Names
Specifying Whether Users See Administrative Labels' Names
External View
Internal View
The Hierarchy of Label View Settings
In the label_encodings File
In the User Manager
How setpattr(2) Sets the PAF_LABEL_VIEW Flag for a Process
In Programs
Valid Labels
Example
Accreditation Ranges
System Accreditation Range
User Accreditation Range
Accreditation Range Examples
Administrative Roles Review
Decision to Make for the Install Team to Follow
Types of Labels That Must Be Specified at Each Site
Configuring How Labels are Printed on Banner/Trailer and Body Pages
Overview of Planning
Planning the Encodings File
Creating Large Numbers of Labels
Creating Unique Labels
Chapter 2 Creating or Editing the Encodings File
Readying the Label Encodings File Before the NIS+ Master or Standalone System is Configured
Labels-Related Files and Central Administration
Actions for Editing and Checking the label_encodings File
Hints
Differences Between Single-label and Installed Label Encodings Files
Multiple Sensitivity Labels Version
Single Sensitivity Label Version
Changing the label_encodings File After System Start Up
Running Without Labels
Word Order Requirements
Label Encodings File Template
Adding or Renaming a Classification
Number of Classifications
Keywords Defined for Classifications
Setting Default and Inverse Words
Setting Up Single-label Operation
Label_encodings-related Procedures
To Modify the label_encodings (4) File
To Copy the label_encodings File to a Floppy Disk
To Copy the label_encodings File from a Floppy Disk
To Add Sun Extensions to a Pre-Existing Label Encodings File
To Set Up No Labels Operation
To Add or Rename a Classification in the Default label_encodings File
To Specify Default and Inverse Words
To Replace the Single Label in the Default Single-label Encodings File
To Make Your Own Single-label Encodings File
To Configure Labels Not Visible to Users
Chapter 3 Specifying Labels and Handling Guidelines for Printer Output
Labels on Body Pages
Labels, Text, and Handling Caveats on Banner and Trailer Pages
Specifying the Protect As Classification
Specifying Printer Banners
Specifying CHANNELS
Procedures
To Configure PRINTER BANNERS
To Configure CHANNELS
Chapter 4 Modifying Sun's Extensions in the Local Definitions Section
Default LOCAL DEFINITIONS Section
Values Specified in the LOCAL DEFINITIONS Section
Changing the Names of Administrative Labels
Specifying Whether Other Labels are Substituted for Administrative Labels
Changing Label Component Names on Label Builders
Specifying Colors for Labels
Order of Color Specification
Color Values
Planning Color Names
Procedures for Modifying Sun Extensions
To Change the Names of Administrative Labels (Optional)
To Specify the System-wide Viewing of Administrative Label Names (Optional)
To Specify the System-wide Viewing of Substitute Names for Administrative Labels (Optional)
To Change Label Component Names Used in Label Builders (Optional)
To Assign a Color to a Label or Word
Chapter 5 Example: Planning an Organization's Labels
Identifying the Site's Label Requirements
Problems Encountered in Trying to Meet Information Protection Goals
How Trusted Solaris Features Address Information Labeling and Access Control Requirements
Climbing the Security Learning Curve
Analyzing the Requirements for Each Label
PROPRIETARY/CONFIDENTIAL: INTERNAL_USE_ONLY
PROPRIETARY/CONFIDENTIAL: NEED_TO_KNOW
PROPRIETARY/CONFIDENTIAL: REGISTERED
Names of Group Associated with the Need to Know
Understanding the Set of Labels
Defining the Set of Labels
Planning the Classifications
Planning the Compartments
Planning the Use of Words in MAC
Planning the Use of Words in Labeling System Output
Planning How to Label Printer Output Pages as Desired
Planning for Supporting Procedures
Rules for Protecting a File or Directory Labeled with the REGISTERED Sensitivity Label
Rules for Configuring Printers
Rules for Handling Printer Output
Planning Classification Values in a Worksheet
Planning Compartment Values and Classification/Compartment Constraints in a Worksheet
Planning Clearances in a Worksheet
Planning the PRINTER BANNERS Wording in a Worksheet
Planning CHANNELS in a Worksheet
Planning the Minimums in an ACCREDITATION RANGE Worksheet
Planning the Colors in the COLOR NAMES Worksheet
Specifying the Labels During Post-Install Configuration
Encoding the VERSION
Encoding the CLASSIFICATIONS
Encoding the SENSITIVITY LABELS
Encoding the INFORMATION LABELS
Encoding the CLEARANCES
Encoding the CHANNELS
Encoding the PRINTER BANNERS
Encoding the ACCREDITATION RANGE
Encoding the Wording for Label Builders, Colors, and Other LOCAL DEFINITIONS Values
Encoding the Heading Names for Label Builders
Encoding the COLOR NAMES
Configuring Users to Enforce Labeling Decisions
Configuring Printing To Enforce Labeling Decisions
Appendix A Example: Label Encodings File
Index
Numbers and Symbols
A
B
C
D
E
F
G
H
I
K
L
M
N
P
R
S
T
U
V
W
© 2010, Oracle Corporation and/or its affiliates