Trusted Solaris Label Administration

Classifications

The classification is the hierarchical portion of a label or clearance. Each type of label has one and only one classification. The internal representation of each label type has 15 bits available for storing classification values.

Classification Field 

15 bits/32,767 possible values/256 values limit enforced 

The labels translation software enforces a limit of 256 classification values. A numeric value (integer) from 1 to 255 is assigned to each classification in the label_encodings file. The values 0 is reserved for the ADMIN_LOW administrative label. (See also "Administrative Labels".)

The classification portion of a label indicates a relative level of protection based on the sensitivity of the information contained in a file or directory. In a clearance assigned to a user and to processes that execute applications and commands on behalf of the user, a classification can indicate a level of trust.

A classification with a higher value is said to dominate a classification with a lower value. (Dominance is explained more fully under "Label Dominance".)

Commercial (Sun Information Protection Labels) 

Value 

Government  

Value 

Registered

6

Top Secret

6

Need to Know

5

Secret 	

5

Internal Use Only

4

Confidential

4

Public

1

Unclassified

1

At least one sensitivity label, information label, and clearance must be defined. All types of labels need at least a classification component. A set of labels can be made up only of one classification each and no words.

Classifications are defined once for all types of labels in the CLASSIFICATIONS section of the label_encodings(4).

The following table may be used for planning classifications. An asterisk (*) is used where the item is optional.

Table 1-1 Classifications Planner

name= 

sname=/*aname=  

value= 

*initial compartments= bit numbers/WORD