BigAdmin System Administration Portal
Sun Docs
Print-friendly VersionPrint-friendly Version

Solaris Trusted Extensions Technical FAQ

Sharon Veach, November 2007

This FAQ answers technical questions about Solaris Trusted Extensions (Trusted Extensions). For questions about the relationship of Trusted Extensions to the Solaris OS or of Trusted Solaris 8 to Trusted Extensions, see the Solaris Trusted Extensions FAQ.

Solaris Trusted Extensions Technical FAQ

Post your questions to the OpenSolaris Trusted Extensions forum. Click Discussions in the left panel.

Question: Can a Solaris Trusted Extensions (Trusted Extensions) system be an NFS server to Trusted Extensions and non-Trusted Extensions systems? Similarly, can a Trusted Extensions system be an NFS client of Trusted Extensions and non-Trusted Extensions systems?

Question: If a system that is running an older version of the NFS protocol mounts a Trusted Extensions file system, what happens?

Question: Which NFS protocol versions does Trusted Extensions support as multilevel servers?

Question: Can you mount a file system into the global zone with read-write permissions?

Question: I created a security template by editing the /etc/security/tsol/tnrhtp file. In the security template, some labels have compartment bits > 239. I am getting errors. Why?

Question: How do I add the priv_mac_exempt privilege to my server?

Question: In the Solaris 10 11/06 release, how do I do a read-down NFS mount from one labeled zone to another without using the automounter?

Question: Why does the Trusted CDE desktop always start no matter what I choose?

Question: How do I load LDAP server software? I found the software, but I could not load it.

Question: I cannot see the contents of a DVD after I start the Device Allocation Manager. Why?

Question: Why does remote login to a labeled zone fail?

Question: In the Solaris 10 11/06 release, why do I get a zone_create failed error message when I attempt to boot the public zone?

Question: I cannot assign IPv6 IP addresses to zones by using the txzonemgr script. Why?

Question: Why can I copy and paste in different labeled windows when the labeled zones have no win_mac* privileges?

Question: How can I get DNS server information when I'm in a labeled zone?

Question: I want my public labeled zone to serve web pages, thus providing some security. However, I am unable to bind to port 80 within the public-facing labeled zone. I even set the webservd entry in the /etc/user_attr file to def_label=PUB, but that did not fix the problem.

Question: User access to workspace functions fails to generate a display back to the console. What is preventing the user from running workspace applications (email, calendar, this host terminal session, home folder in the File Manager, editor) successfully within the PUBLIC and the CNF: Internal Use Only workspaces? The condition is the same when the user attempts a single-label login session. The [This Host] icon generates the following error: Action Failed: Reconnect to Solaris Zone? The other menu icons do not report any errors to the screen.

 

For More Information

Here are some additional resources:

Discuss and comment on this resource in the BigAdmin Wiki


Unless otherwise licensed, code in all technical manuals herein (including articles, FAQs, samples) is provided under this License.


BigAdmin
  
 
 
 
 
Would you recommend this Sun site to a friend or colleague?
Contact About Sun News & Events Employment Site Map Privacy Terms of Use Trademarks Copyright Sun Microsystems, Inc.