trusted_extensions - Solaris Trusted Extensions
Oracle Solaris 的 Trusted Extensions 功能为本地对象和进程、区域和文件系统以及网络通信提供标签。These labels are used to implement a Multilevel Security (MLS) policy that restricts the flow of information based on label relationships.In contrast to Discretionary Access Control (DAC) based on ownership, the MLS policy enforced by Trusted Extensions is an example of Mandatory Access Control (MAC).
缺省情况下,Trusted Extensions 软件是禁用的。可通过 labeladm(8) 命令来启用和禁用(但不是完全配置)该软件,该软件与 labeld(8) 服务(由 FMRI 模式标识)关联:
svc:/system/labeld:*
label_encodings(5)、labels(7)、labeladm(8)、labeld(8)
Trusted Extensions Configuration and Administration
Trusted Extensions Label Administration
Trusted Extensions Developer’s Guide
Trusted Extensions was made available as an add-on for Solaris 10 11/06 (Update 3), and then was integrated fully into Solaris in the Solaris 10 4/08 (Update 5) release.
Prior to that, Multilevel Security for Solaris was provided by the separate Trusted Solaris product, and before that, the SunOS CMW and SunOS MLS products.
Support for a multilevel, labeled desktop environment was removed from Solaris in Oracle Solaris 11.4.0.