Linux Basics · Lesson 13 · 15 min

Managing users & groups

A new classmate joins your robotics club and needs an account on the club server. They should be able to update the club website, but not read everyone else's files. That's a real admin job. Let's do it on both families.

You will learn

  • Where Linux keeps accounts: /etc/passwd, /etc/shadow, /etc/group
  • Creating users: useradd vs adduser, and why they behave differently on each family
  • Adding people to groups safely (and the usermod -G trap)
  • Building a shared team folder, and removing users

Where accounts live

Every account is one line in /etc/passwd. Anyone can read that file, and it's safe to, because it contains no passwords:

alexusername:xpw is in shadow:1001UID:1001GID:Alex Smithfull name:/home/alexhome:/bin/bashshell
Same on both
getent passwd alex     # one user's line
id alex                # their UID and every group they're in
groups alex            # just the group names

Creating a user

Rocky / RHEL
sudo useradd -c "Alex Smith" alex
sudo passwd alex

useradd creates the account and a home folder, with shell /bin/bash. It sets no password, so you do that with passwd. On Rocky, adduser is just another name for useradd.

Ubuntu / Debian
sudo adduser alex

adduser is a friendly helper. It makes the home folder, then asks for a password and details. Ubuntu's low-level useradd creates no home folder unless you add -m, and it gives the user /bin/sh. That's why people on Ubuntu use adduser.

Password tips

Nothing appears while you type a password. Rocky warns about weak passwords (“BAD PASSWORD: The password is shorter than 8 characters”), but as root you can still set one. Please don't. Long passphrases like purple-robot-eats-42-tacos are both stronger and easier to remember.

Groups: the right way to share

Groups let you give a whole team access at once. Adding someone to an existing group is where people make their most famous mistake:

Rocky / RHEL
sudo usermod -aG wheel alex        # make alex an admin
sudo gpasswd -a alex webteam       # another safe way
Ubuntu / Debian
sudo usermod -aG sudo alex         # make alex an admin
sudo gpasswd -a alex webteam       # another safe way
sudo adduser alex webteam          # Ubuntu-only shortcut
The -a trap

usermod -aG means add to these Groups. Forget the a (usermod -G webteam alex) and Linux replaces all of Alex's groups with just webteam. If you do that to yourself, you've just removed your own admin rights! Changes to groups apply the next time the user logs in.

A shared team folder

Now let's put it together: a folder the whole web team can edit.

Same on both
sudo groupadd webteam                # 1. make the group
sudo gpasswd -a alex webteam         # 2. add the members
sudo gpasswd -a student webteam
sudo mkdir -p /srv/web               # 3. make the folder
sudo chgrp webteam /srv/web          # 4. hand it to the group
sudo chmod 2775 /srv/web             # 5. rwxrwxr-x + the "setgid" bit

That leading 2 is the setgid bit. It makes new files created inside automatically belong to webteam, so teammates can always edit each other's work. In ls -l it shows up as an s: drwxrwsr-x.

Locking and removing users

Same on both
sudo usermod -L alex      # lock the password (they can't log in with it)
sudo usermod -U alex      # unlock
sudo userdel alex         # delete the account, KEEP their files
sudo userdel -r alex      # delete the account AND their home folder

Before deleting someone, admins often back up their home folder first (Linux Sysadmin, lesson 8). Also check nothing important runs as them. Their crontab goes when they do!

Try it: set up the club server

Quick check

1. On Ubuntu you ran sudo useradd sam. Sam logs in but has no home folder. Why?

2. Which command makes alex an admin on Rocky without removing their other groups?

3. Where are password hashes stored?

Finished the missions and the quiz? Mark it done to track your progress.