Managing users & groups
A new classmate joins your robotics club and needs an account on the club server. They should be able to update the club website, but not read everyone else's files. That's a real admin job. Let's do it on both families.
You will learn
- Where Linux keeps accounts:
/etc/passwd,/etc/shadow,/etc/group - Creating users:
useraddvsadduser, and why they behave differently on each family - Adding people to groups safely (and the
usermod -Gtrap) - Building a shared team folder, and removing users
Where accounts live
Every account is one line in /etc/passwd. Anyone can read that file, and it's safe to, because it contains no passwords:
- The UID is the user's number. root is 0. Real people start at 1000 on both families. Numbers below that belong to system accounts like
sshdandapache/www-data. - Scrambled password “hashes” are kept in
/etc/shadow, which only root can read (see lesson 10). - Groups and their members are listed in
/etc/group.
getent passwd alex # one user's line id alex # their UID and every group they're in groups alex # just the group names
Creating a user
sudo useradd -c "Alex Smith" alex sudo passwd alex
useradd creates the account and a home folder, with shell /bin/bash. It sets no password, so you do that with passwd. On Rocky, adduser is just another name for useradd.
sudo adduser alex
adduser is a friendly helper. It makes the home folder, then asks for a password and details. Ubuntu's low-level useradd creates no home folder unless you add -m, and it gives the user /bin/sh. That's why people on Ubuntu use adduser.
Nothing appears while you type a password. Rocky warns about weak passwords (“BAD PASSWORD: The password is shorter than 8 characters”), but as root you can still set one. Please don't. Long passphrases like purple-robot-eats-42-tacos are both stronger and easier to remember.
Groups: the right way to share
Groups let you give a whole team access at once. Adding someone to an existing group is where people make their most famous mistake:
sudo usermod -aG wheel alex # make alex an admin sudo gpasswd -a alex webteam # another safe way
sudo usermod -aG sudo alex # make alex an admin sudo gpasswd -a alex webteam # another safe way sudo adduser alex webteam # Ubuntu-only shortcut
-a trapusermod -aG means add to these Groups. Forget the a (usermod -G webteam alex) and Linux replaces all of Alex's groups with just webteam. If you do that to yourself, you've just removed your own admin rights! Changes to groups apply the next time the user logs in.
A shared team folder
Now let's put it together: a folder the whole web team can edit.
sudo groupadd webteam # 1. make the group sudo gpasswd -a alex webteam # 2. add the members sudo gpasswd -a student webteam sudo mkdir -p /srv/web # 3. make the folder sudo chgrp webteam /srv/web # 4. hand it to the group sudo chmod 2775 /srv/web # 5. rwxrwxr-x + the "setgid" bit
That leading 2 is the setgid bit. It makes new files created inside automatically belong to webteam, so teammates can always edit each other's work. In ls -l it shows up as an s: drwxrwsr-x.
Locking and removing users
sudo usermod -L alex # lock the password (they can't log in with it) sudo usermod -U alex # unlock sudo userdel alex # delete the account, KEEP their files sudo userdel -r alex # delete the account AND their home folder
Before deleting someone, admins often back up their home folder first (Linux Sysadmin, lesson 8). Also check nothing important runs as them. Their crontab goes when they do!
Try it: set up the club server
Quick check
1. On Ubuntu you ran sudo useradd sam. Sam logs in but has no home folder. Why?
✓ On Rocky, useradd makes the home folder by default. It's another family difference.
2. Which command makes alex an admin on Rocky without removing their other groups?
✓ -a for append, and wheel is Rocky's admin group.
3. Where are password hashes stored?
✓ The x in /etc/passwd means “look in shadow.”