JavaScript is required to for searching.
Skip Navigation Links
Exit Print View
Trusted Extensions Configuration and Administration     Oracle Solaris 11 Information Library
search filter icon
search icon

Document Information

Preface

Part I Initial Configuration of Trusted Extensions

1.  Security Planning for Trusted Extensions

2.  Configuration Roadmap for Trusted Extensions

3.  Adding the Trusted Extensions Feature to Oracle Solaris (Tasks)

4.  Configuring Trusted Extensions (Tasks)

5.  Configuring LDAP for Trusted Extensions (Tasks)

Part II Administration of Trusted Extensions

6.  Trusted Extensions Administration Concepts

7.  Trusted Extensions Administration Tools

8.  Security Requirements on a Trusted Extensions System (Overview)

9.  Performing Common Tasks in Trusted Extensions (Tasks)

10.  Users, Rights, and Roles in Trusted Extensions (Overview)

11.  Managing Users, Rights, and Roles in Trusted Extensions (Tasks)

12.  Remote Administration in Trusted Extensions (Tasks)

13.  Managing Zones in Trusted Extensions (Tasks)

14.  Managing and Mounting Files in Trusted Extensions (Tasks)

15.  Trusted Networking (Overview)

16.  Managing Networks in Trusted Extensions (Tasks)

17.  Trusted Extensions and LDAP (Overview)

18.  Multilevel Mail in Trusted Extensions (Overview)

19.  Managing Labeled Printing (Tasks)

20.  Devices in Trusted Extensions (Overview)

21.  Managing Devices for Trusted Extensions (Tasks)

22.  Trusted Extensions Auditing (Overview)

23.  Software Management in Trusted Extensions (Reference)

A.  Site Security Policy

Creating and Managing a Security Policy

Site Security Policy and Trusted Extensions

Computer Security Recommendations

Physical Security Recommendations

Personnel Security Recommendations

Common Security Violations

Additional Security References

B.  Configuration Checklist for Trusted Extensions

Checklist for Configuring Trusted Extensions

C.  Quick Reference to Trusted Extensions Administration

Administrative Interfaces in Trusted Extensions

Oracle Solaris Interfaces Extended by Trusted Extensions

Tighter Security Defaults in Trusted Extensions

Limited Options in Trusted Extensions

D.  List of Trusted Extensions Man Pages

Trusted Extensions Man Pages in Alphabetical Order

Oracle Solaris Man Pages That Are Modified by Trusted Extensions

Glossary

Index

Trusted Extensions Man Pages in Alphabetical Order

The following man pages are relevant only on a system that is configured with Trusted Extensions. The description includes links to examples or explanations of these features in the Trusted Extensions document set.

Trusted Extensions Man Page

Purpose and Links to Additional Information

add_allocatable(1M)

Enables a device to be allocated by adding the device to device allocation databases. By default, removable devices are allocatable.

See How to Configure a Device in Trusted Extensions.

atohexlabel(1M)

Converts a human-readable label to its internal text equivalent.

For an example, see How to Obtain the Hexadecimal Equivalent for a Label.

blcompare(3TSOL)

Compares binary labels.

blminmax(3TSOL)

Determines the bound of two labels.

chk_encodings(1M)

Checks the label encodings file syntax.

For examples, see How to Debug a label_encodings File in Trusted Extensions Label Administration and Example 4-1.

fgetlabel(2)

Gets the file's label

getlabel(1)

Displays the label of the selected files or directories.

For an example, see How to Display the Labels of Mounted Files.

getlabel(2)

Gets the label of a file

getpathbylabel(3TSOL)

Gets the zone pathname

getplabel(3TSOL)

Gets the label of a process

getuserrange(3TSOL)

Gets the label range of a user

getzoneidbylabel(3TSOL)

Gets zone ID from zone label

getzonelabelbyid(3TSOL)

Gets zone label from zone ID

getzonelabelbyname(3TSOL)

Gets zone label from zone name

getzonepath(1)

Displays the root path of the zone that corresponds to the specified label.

Acquiring a Sensitivity Label in Trusted Extensions Developer’s Guide

getzonerootbyid(3TSOL)

Gets zone root pathname from zone root ID

getzonerootbylabel(3TSOL)

Gets zone root pathname from zone label

getzonerootbyname(3TSOL)

Gets zone root pathname from zone name

hextoalabel(1M)

Converts an internal text label to its human-readable equivalent

For an example, see How to Obtain a Readable Label From Its Hexadecimal Form.

labelclipping(3TSOL)

Translates a binary label and clips the label to the specified width

label_encodings(4)

Describes the label encodings file

label_to_str(3TSOL)

Converts labels to human-readable strings

labels(5)

Describes Trusted Extensions label attributes

libtsnet(3LIB)

Is the Trusted Extensions network library

libtsol(3LIB)

Is the Trusted Extensions library

m_label(3TSOL)

Allocates and frees resources for a new label

pam_tsol_account(5)

Checks account limitations that are due to labels

For an example of its use, see How to Log In and Administer a Remote Trusted Extensions System.

plabel(1)

Gets the label of a process

remove_allocatable(1M)

Prevents allocation of a device by removing its entry from device allocation databases

For an example, see How to Configure a Device in Trusted Extensions.

sel_config(4)

Is the selection rules for copy, cut, paste, and drag-and-drop operations

See Rules When Changing the Level of Security for Data.

setflabel(3TSOL)

Moves a file to a zone with the corresponding sensitivity label

setlabel(1)

Relabels the selected item. Requires the solaris.label.file.downgrade or solaris.label.file.upgrade authorization. These authorizations are in the Object Label Management rights profile.

str_to_label(3TSOL)

Parses human-readable strings to a label

tncfg(1M)

Manages the trusted network databases. An alternative to the txzonmgr GUI for managing the trusted network. The list subcommand displays the security characteristics of network interfaces. tncfg provides more complete information than the tninfo command.

For many examples, see Chapter 16, Managing Networks in Trusted Extensions (Tasks).

tnctl(1M)

Configures Trusted Extensions network parameters. You can also use the tncfg command.

For an example, see Example 12-1.

tnd(1M)

Executes the trusted network daemon when the LDAP naming service is enabled.

tninfo(1M)

Displays kernel-level Trusted Extensions network information and statistics.

How to Debug the Trusted Extensions Network. You can also use the tncfg command and the txzonemgr GUI.

For a comparison with the tncfg command, see How to Troubleshoot Mount Failures in Trusted Extensions.

trusted_extensions(5)

Introduces Trusted Extensions

txzonemgr(1M)

Manages labeled zones and network interfaces. Command-line options enable automatic creation of two zones. This command accepts a configuration file as input and enables the deletion of zones. txzonemgr is a zenity (1) script.

See Creating Labeled Zones and Troubleshooting the Trusted Network (Task Map).

TrustedExtensionsPolicy(4)

Is the configuration file for Trusted Extensions X Server Extension

tsol_getrhtype(3TSOL)

Gets the host type from Trusted Extensions network information

tgnome-selectlabel utility

Enables you to create a label builder GUI

For more information, see tgnome-selectlabel Utility in Trusted Extensions Developer’s Guide.

updatehome(1)

Updates the home directory copy and link files for the current label

See How to Configure Startup Files for Users in Trusted Extensions.

XTSOLgetClientAttributes(3XTSOL)

Gets the label attributes of an X client

XTSOLgetPropAttributes(3XTSOL)

Gets the label attributes of a window property

XTSOLgetPropLabel(3XTSOL)

Gets the label of a window property

XTSOLgetPropUID(3XTSOL)

Gets the UID of a window property

XTSOLgetResAttributes(3XTSOL)

Gets all label attributes of a window or a pixmap

XTSOLgetResLabel(3XTSOL)

Gets the label of a window, a pixmap, or a colormap

XTSOLgetResUID(3XTSOL)

Gets the UID of a window or a pixmap

XTSOLgetSSHeight(3XTSOL)

Gets the height of the screen stripe

XTSOLgetWorkstationOwner(3XTSOL)

Gets the ownership of the workstation

XTSOLIsWindowTrusted(3XTSOL)

Determines if a window is created by a trusted client

XTSOLMakeTPWindow(3XTSOL)

Make this window a Trusted Path window

XTSOLsetPolyInstInfo(3XTSOL)

Sets polyinstantiation information

XTSOLsetPropLabel(3XTSOL)

Sets the label of a window property

XTSOLsetPropUID(3XTSOL)

Sets the UID of a window property

XTSOLsetResLabel(3XTSOL)

Sets the label of a window or a pixmap

XTSOLsetResUID(3XTSOL)

Sets the UID of a window, a pixmap, or a colormap

XTSOLsetSessionHI(3XTSOL)

Sets the session high sensitivity label to the window server

XTSOLsetSessionLO(3XTSOL)

Sets the session low sensitivity label to the window server

XTSOLsetSSHeight(3XTSOL)

Sets the height of the screen stripe

XTSOLsetWorkstationOwner(3XTSOL)

Sets the ownership of the workstation