Users, groups & sudo
/etc/passwd and /etc/group, useradd, usermod, passwd, groups and using sudo safely.
Linux was built as a multi-user system from day one. Every file has an owner, every process runs as some user, and permissions decide who can do what. Even on your personal laptop there are dozens of users: most belong to system services, so that a hacked web server can't read your SSH keys. Understanding users and groups is essential for permissions, servers, Docker and security.
Who am I?#
(Output from a typical Ubuntu desktop; your groups will differ.)
- UID (user ID): the number the kernel actually uses. Names are just labels for humans.
- GID: your primary group, used as the group owner of files you create. On Debian/Ubuntu/Fedora each user gets a private group with the same name.
- groups: supplementary groups that grant extra rights. Being in
sudo(Debian/Ubuntu) orwheel(Fedora/RHEL) lets you usesudo.
groups prints just the group names, and id ben shows another user.
Kinds of users#
root can read any file, kill any process and change anything. That's why you work as a normal user and borrow root power only when needed.
The user database: /etc/passwd, /etc/shadow, /etc/group#
Each line has seven colon-separated fields:
Everyone can read /etc/passwd (programs need to map UIDs to names), but only root can read /etc/shadow, where password hashes live. /etc/group lists groups and their members (sudo:x:27:ada,ben).
Don't edit these files by hand. Use the tools below, or getent, which also covers users from LDAP or Active Directory:
List the regular (human) accounts with a little awk, which you'll learn properly later:
sudo: borrowing root's power#
sudo asks for your own password (then remembers it for about 15 minutes), checks the rules in /etc/sudoers, and logs every use (see them with journalctl _COMM=sudo or in /var/log/auth.log). Grant sudo by adding a user to the right group rather than editing the rules:
If you must change the rules, always use sudo visudo: it checks the syntax before saving, so a typo can't lock everyone out of sudo. Drop extra rules in /etc/sudoers.d/ files, e.g. deploy ALL=(ALL) NOPASSWD: /usr/bin/systemctl restart myapp lets the deploy user restart one service without a password.
su - ben switches to another user's full login environment, but needs their password (or use sudo su - ben / sudo -iu ben).
Managing users#
The commands in the rest of this lesson change system accounts, so they were not run on our test machine. They are the standard tools on Debian, Ubuntu and Fedora; try them in a virtual machine or a throwaway cloud server.
useradd without -m creates no home directory, a classic gotcha. On Debian/Ubuntu prefer adduser for humans.
A system user for a service, with no login and no home:
You'll use exactly this in the systemd and deployment lessons, so your app doesn't run as root.
Managing groups#
Group membership is read at login. After adding yourself to a group, log out and back in (or run newgrp developers in the current shell) before it takes effect. This is why docker commands still say "permission denied" right after usermod -aG docker $USER.
A shared project folder for a group (the setgid bit 2 was covered in the permissions lesson):
Common mistakes#
usermod -Gwithout-a, wiping a user's other groups.- Expecting new group membership to apply without logging in again.
- Editing
/etc/sudoerswith a normal editor instead ofvisudo. - Running services, scripts or
pip installas root out of habit. - Sharing one login (or the root password) between people. Give everyone their own account and sudo access so actions are traceable.
What's next#
Next you'll learn about hard links and symbolic links: how one file can have several names, and how shortcuts to files and directories work.
Check your understanding
Quick quiz
1.You added user
bento thedockergroup withsudo usermod -aG docker ben. Why must you be careful with the-aflag?2.Where are users' hashed passwords stored on a modern Linux system?
3.What is the safest way to run a single admin command as a normal user?
Finished reading?
Mark this lesson complete to track your progress.