Administrator Guide

Table Of Contents
User data encryption using ZFS file system
Dell Hybrid Client is designed to protect a domain user's data such as user files, user database, and user application details.
Dell Hybrid Client uses the ZFS file system to encrypt the user home directory. Each user home directory is encrypted with
an autogenerated passphrase. This feature is available from Dell Hybrid Client version 1.5 onwards. When a user logs in to the
device, the user home directory of the user is automatically mounted by ZFS. When the user logs out of the device, the user
home directory is unmounted by ZFS.
ZFS uses a storage pool that is called Zpool for storing data on a single device. A user quota is defined to limit the amount of
disk space that is available to a file system or home directory of a particular user.
User quota and Zpool dynamic expansionThe size of the storage pool and user quota are increased automatically as
more user files or directories are added. For example, When a user copies files larger than the allocated user quota, first the
size of the user quota is dynamically increased to accommodate the data. A notification is displayed on the Dell Hybrid Client
screen to indicate that the user quota has increased. If the user quota expansion reaches the threshold limit of the entire
storage pool, the Zpool is dynamically increased to accommodate the user quota expansion. A notification is displayed on the
Dell Hybrid Client screen to indicate that the zpool has increased.
User quota dynamic contractionThe size of the user quota is decreased automatically as more user files are removed.
For example, When a user deletes large amount of files, the size of the user quota is dynamically decreased to free up the
disk space. A notification is displayed on the Dell Hybrid Client screen to indicate that the user quota has decreased.
For more information about the ZFS file system, see the Ubuntu documentation at ubuntu.com.
User data cleanup
As an administrator, you can use Wyse Management Suite to clear user data of a particular user.
Steps
1. Log in to Wyse Management Suite.
2. Go to the Devices page and locate your device that is powered by Dell Hybrid Client.
3. Click the device name.
The Device Details page is displayed.
4. From the More Actions drop-down list, click Clear User(s) Data.
An alert window is displayed.
5. Enter the name of the user.
6. Click Send Command.
The user home directory is deleted from the storage pool.
Configure the security profile settings
Dell Hybrid Client enables you to set Security Profiles to provide an enhanced device security for deploying unsigned third-
party applications. This feature is available from Dell Hybrid Client version 1.5 onwards.
Steps
1. Log in to Wyse Management Suite.
2. Go to the Groups & Configs page, and select your preferred device group.
NOTE: The security profile option is applicable only for Device Policy Groups.
3. Click Edit Policies > Hybrid Client.
The Configuration Control | Hybrid Client page is displayed.
4. Click the Advanced tab.
5. Expand Privacy & Security and click Security Profile.
6. From the Security Profile drop-down list, select one of the following options:
HighThis profile enables you to install Dell-signed, custom-signed, and unsigned Debian files with metadata. Based on
the metadata, the firejail is applied.
NOTE: The firewall and Kernel hardening features are disabled.
84 Device security