Linux User and User Group Management
The Linux system is a multi-user, multi-tasking time-sharing operating system. Any user who wants to use system resources must first apply to the system administrator for an account, and then enter the system with that account identity.
On one hand, user accounts can help the system administrator track users who use the system and control their access to system resources; on the other hand, they can also help users organize files and provide security protection for users.
Each user account has a unique username and its own password.
After entering the correct username and password at login, the user can enter the system and their own home directory.
To implement user account management, the work to be completed mainly includes the following aspects:
- Adding, deleting, and modifying user accounts.
- Management of user passwords.
- Management of user groups.
I. Management of Linux System User Accounts
The management of user accounts mainly involves the addition, modification, and deletion of user accounts.
Adding a user account means creating a new account in the system, and then allocating resources such as user ID, user group, home directory, and login Shell to the new account. A newly added account is locked and cannot be used.
1. Use the useradd command to add a new user account. Its syntax is as follows:
useradd 选项 用户名
Parameter description:
-
Options:
- -c comment Specify a descriptive comment.
- -d directory Specify the user's home directory. If this directory does not exist, you can use the -m option at the same time to create the home directory.
- -g user group Specify the user group to which the user belongs.
- -G user group, user group Specify the additional groups to which the user belongs.
- -s Shell file Specify the user's login Shell.
- -u user ID Specify the user ID of the user. If the -o option is also used, the identification number of another user can be reused.
-
Username:
Specify the login name of the new account.
Example 1
# useradd –d /home/sam -m sam
This command creates a user named sam. The -d and -m options are used to create a home directory /home/sam for the login name sam (/home is the parent directory where the default user home directories are located).
Example 2
# useradd -s /bin/sh -g group –G adm,root gem
This command creates a new user gem. The login Shell for this user is/bin/sh, and it belongs to the group user group, and also belongs to the adm and root user groups, among which the group user group is its primary group.
A new group may be created here:#groupadd group及groupadd adm
Adding a user account means adding a record for the new user in the /etc/passwd file, and at the same time updating other system files such as /etc/shadow, /etc/group, etc.
Linux provides an integrated system management tool called userconf, which can be used for unified management of user accounts.
2. Deleting an account
If a user's account is no longer used, it can be deleted from the system. Deleting a user account means deleting the user's record in system files such as /etc/passwd, and if necessary, also deleting the user's home directory.
To delete an existing user account, use theuserdelcommand. Its format is as follows:
userdel 选项 用户名
The commonly used option is-r, which is used to delete the user's home directory together with the account.
For example:
# userdel -r sam
This command deletes user sam's records in system files (mainly /etc/passwd, /etc/shadow, /etc/group, etc.) and also deletes the user's home directory.
3. Modifying an account
Modifying a user account means changing the user's relevant attributes according to the actual situation, such as user ID, home directory, user group, login Shell, etc.
To modify the information of an existing user, use theusermodcommand. Its format is as follows:
usermod 选项 用户名
Commonly used options include-c, -d, -m, -g, -G, -s, -u以及-o等, the meanings of these options are the same as those in theuseraddcommand's options, and can specify new resource values for the user.
In addition, some systems can use the option: -l new username
This option specifies a new account, that is, changes the original username to a new username.
For example:
# usermod -s /bin/ksh -d /home/z –g developer sam
This command changes user sam's login Shell to ksh, changes the home directory to /home/z, and changes the user group to developer.
4. Management of user passwords
An important part of user management is the management of user passwords. When a user account is first created, it has no password, but it is locked by the system and cannot be used. It can only be used after a password is specified for it, even if an empty password is specified.
The Shell command for specifying and modifying a user password ispasswd. Superusers can specify passwords for themselves and other users, while ordinary users can only use it to modify their own passwords. The format of the command is:
passwd 选项 用户名
Available options:
- -l Lock the password, that is, disable the account.
- -u Unlock the password.
- -d Make the account have no password.
- -f Force the user to change the password at the next login.
If the username is defaulted, the current user's password is modified.
For example, assuming the current user is sam, the following command modifies that user's own password:
$ passwd Old password:****** New password:******* Re-enter new password:*******
If you are a superuser, you can specify any user's password in the following form:
# passwd sam New password:******* Re-enter new password:*******
When an ordinary user changes their own password, the passwd command will first ask for the original password, and after verification, require the user to enter the new password twice. If the two entered passwords match, the password is assigned to the user. When a superuser specifies a password for a user, there is no need to know the original password.
For system security, users should choose relatively complex passwords. For example, it is best to use an 8-character password that contains uppercase and lowercase letters and numbers, and it should not be the same as names, birthdays, etc.
To specify an empty password for a user, execute the command in the following form:
# passwd -d sam
This command deletes user sam's password, so that the next time user sam logs in, the system will no longer allow that user to log in.
The passwd command can also use the -l (lock) option to lock a certain user so that they cannot log in, for example:
# passwd -l sam
II. Management of Linux System User Groups
Each user has a user group, and the system can centrally manage all users in a user group. Different Linux systems have different regulations for user groups. For example, under Linux, a user belongs to a user group with the same name as the user, and this user group is created at the same time as the user is created.
The management of user groups involves the addition, deletion, and modification of user groups. The addition, deletion, and modification of groups are in fact updates to the /etc/group file.
1. Use the groupadd command to add a new user group. Its format is as follows:
groupadd 选项 用户组
Available options include:
- -g GID Specify the group ID (GID) for the new user group.
- -o Generally used together with the -g option, indicating that the GID of the new user group can be the same as the GID of an existing user group in the system.
Example 1:
# groupadd group1
This command adds a new group, group1, to the system. The new group's GID is the current maximum existing GID plus 1.
Example 2:
# groupadd -g 101 group2
This command adds a new group, group2, to the system, and specifies the new group's GID as 101.
2. To delete an existing user group, use the groupdel command. Its format is as follows:
groupdel 用户组
For example:
# groupdel group1
This command deletes group1 from the system.
3. Use the groupmod command to modify user group attributes. Its syntax is as follows:
groupmod 选项 用户组
Common options include:
- -g GID Specify a new GID for the user group.
- -o Used together with the -g option, allowing the new GID of the user group to be the same as the GID of an existing user group in the system.
- -n <new user group> Change the user group's name to the new name.
Example 1:
# groupmod -g 102 group2
This command changes the GID of group2 to 102.
Example 2:
# groupmod –g 10000 -n group3 group2
This command changes the GID of group2 to 10000 and renames the group to group3.
4. If a user belongs to multiple user groups at the same time, the user can switch between user groups in order to have the permissions of other user groups.
After logging in, the user can use the newgrp command to switch to another user group. The argument of this command is the destination user group. For example:
$ newgrp root
This command switches the current user to the root user group, provided that the root group is indeed the user's primary group or a supplementary group. Similar to user account management, user group management can also be done through integrated system administration tools.
III. System files related to user accounts
There are many ways to accomplish user management, but every method is actually a modification of the related system files.
Information related to users and user groups is stored in some system files, including /etc/passwd, /etc/shadow, /etc/group, etc.
The contents of these files are introduced separately below.
1. The /etc/passwd file is the most important file involved in user management.
Each user in a Linux system has a corresponding record line in the /etc/passwd file, which records some basic attributes of that user.
This file is readable by all users. Its content is similar to the following example:
# cat /etc/passwd root:x:0:0:Superuser:/: daemon:x:1:1:System daemons:/etc: bin:x:2:2:Owner of system commands:/bin: sys:x:3:3:Owner of system files:/usr/sys: adm:x:4:4:System accounting:/usr/adm: uucp:x:5:5:UUCP administrator:/usr/lib/uucp: auth:x:7:21:Authentication administrator:/tcb/files/auth: cron:x:9:16:Cron daemon:/usr/spool/cron: listen:x:37:4:Network daemon:/usr/net/nls: lp:x:71:18:Printer administrator:/usr/spool/lp: sam:x:200:50:Sam san:/home/sam:/bin/sh
From the example above, we can see that one line in /etc/passwd corresponds to one user. Each line is separated by colons (:) into 7 fields. The format and specific meaning are as follows:
用户名:口令:用户标识号:组标识号:注释性描述:主目录:登录Shell
1) "Username" is a string representing the user account.
Its length usually does not exceed 8 characters, and it is composed of uppercase and lowercase letters and/or digits. A login name cannot contain a colon (:), because the colon is the delimiter here.
For compatibility reasons, login names should preferably not contain a dot (.), and should not begin with a hyphen (-) or a plus sign (+).
2) "Password": In some systems, the encrypted user password is stored here.
Although this field stores only the encrypted password string rather than plaintext, because the /etc/passwd file is readable by all users, it is still a security risk. Therefore, many Linux systems (such as SVR4) now use shadow technology, storing the actually encrypted user password in the /etc/shadow file, and storing only a special character, such as "x" or "*", in the password field of the /etc/passwd file.
3) "User identification number" is an integer used internally by the system to identify the user.
In general, it has a one-to-one correspondence with the username. If several usernames correspond to the same user ID, the system internally treats them as the same user, but they can have different passwords, different home directories, and different login shells.
Usually the user ID ranges from 0 to 65,535. 0 is the ID of the superuser root, 1 to 99 are reserved by the system as administrative accounts, and ordinary users have IDs starting from 100. In Linux systems, this boundary is 500.
4) The "group identification number" field records the user group to which the user belongs.
It corresponds to a record in the /etc/group file.
5) The "annotative description" field records some personal information about the user.
For example, the user's real name, telephone, address, etc. This field has no practical purpose. In different Linux systems, the format of this field is not uniform. In many Linux systems, this field contains an arbitrary descriptive comment, used as the output of the finger command.
6) "Home directory", that is, the user's starting working directory.
It is the directory in which the user is located after logging in to the system. In most systems, users' home directories are organized under the same specific directory, and the name of a user's home directory is the user's login name. Each user has read, write, and execute (search) permissions on their own home directory; other users' access to this directory is set according to specific circumstances.
7) After the user logs in, a process is started that is responsible for passing the user's operations to the kernel. This process is a command interpreter or a specific program that runs after the user logs into the system, that is, the Shell.
Shell is the interface between the user and the Linux system. There are many kinds of Shell in Linux, each with different characteristics. Common ones include sh (Bourne Shell), csh (C Shell), ksh (Korn Shell), tcsh (TENEX/TOPS-20 type C Shell), bash (Bourne Again Shell), etc.
The system administrator can specify a Shell for the user according to system conditions and user habits. If no Shell is specified, the system uses sh as the default login Shell, that is, the value of this field is /bin/sh.
The user's login Shell can also be specified as some specific program (this program is not a command interpreter).
Using this feature, we can restrict the user to run only the specified application. When the application finishes running, the user automatically exits the system. Some Linux systems require that only programs registered in the system can appear in this field.
8) In the system, there is a type of user called pseudo users.
These users also occupy a record in the /etc/passwd file, but they cannot log in because their login Shell is empty. Their existence mainly facilitates system management and satisfies the requirements of corresponding system processes for file ownership.
Common pseudo users are as follows:
伪 用 户 含 义 bin 拥有可执行的用户命令文件 sys 拥有系统文件 adm 拥有帐户文件 uucp UUCP使用 lp lp或lpd子系统使用 nobody NFS使用
Own account files
1. In addition to the pseudo users listed above, there are many standard pseudo users, such as audit, cron, mail, usenet, etc., each of which is also needed by related processes and files.
Because the /etc/passwd file is readable by all users, if a user's password is too simple or has an obvious pattern, an ordinary computer can easily crack it. Therefore, Linux systems with high security requirements separate the encrypted password and store it in a separate file, which is the /etc/shadow file. Only the superuser has read permission for this file, thus ensuring the security of user passwords.
2. The record lines in /etc/shadow correspond one-to-one to those in /etc/passwd. It is automatically generated by the pwconv command based on the data in /etc/passwd.
Its file format is similar to /etc/passwd, consisting of several fields separated by ":". These fields are:
Login name: encrypted password: last modification time: minimum time interval: maximum time interval: warning time: inactive time: expiration time: flag
- "Login name" is the user account that is consistent with the login name in the /etc/passwd file.
- The "Password" field stores the encrypted user password, with a length of 13 characters. If it is empty, the corresponding user has no password and no password is required for login; if it contains characters that do not belong to the set { ./0-9A-Za-z }, the corresponding user cannot log in.
- "Last modified time" indicates the number of days from a certain point in time to the last time the user modified the password. The time origin may be different for different systems. For example, in SCO Linux, this time origin is January 1, 1970.
- "Minimum time interval" refers to the minimum number of days required between two password modifications.
- "Maximum time interval" refers to the maximum number of days the password remains valid.
- "Warning time" field indicates the number of days between when the system begins to warn the user and when the user password actually expires.
- "Inactive time" represents the maximum number of days the account remains valid while the user has no login activity.
- "Expiration time" field gives an absolute number of days. If this field is used, it gives the lifetime of the corresponding account. After expiration, the account is no longer a valid account and can no longer be used for login.
The following is an example of /etc/shadow:
# cat /etc/shadow root:Dnakfw28zf38w:8764:0:168:7::: daemon:*::0:0:::: bin:*::0:0:::: sys:*::0:0:::: adm:*::0:0:::: uucp:*::0:0:::: nuucp:*::0:0:::: auth:*::0:0:::: cron:*::0:0:::: listen:*::0:0:::: lp:*::0:0:::: sam:EkdiSECLWPdSa:9740:0:0::::
3. All information about user groups is stored in the /etc/group file.
Grouping users is a means of managing users and controlling access permissions in the Linux system.
Every user belongs to a certain user group; a group can contain multiple users, and a user can also belong to different groups.
When a user is a member of multiple groups at the same time, the /etc/passwd file records the primary group to which the user belongs, that is, the default group at login, while the other groups are called supplementary groups.
When a user wants to access files belonging to a supplementary group, they must first use the newgrp command to make themselves a member of the group they want to access.
All information about user groups is stored in the /etc/group file. The format of this file is similar to the /etc/passwd file, with several fields separated by colons (:). These fields are:
Group name: password: group ID: list of users in the group
- "Group name" is the name of the user group, composed of letters or digits. Like the login names in /etc/passwd, group names should not be duplicated.
- The "password" field stores the encrypted password of the user group. Generally, user groups in Linux systems do not have a password, so this field is usually empty or contains an asterisk (*).
- The "group ID" is similar to the user ID; it is also an integer used internally by the system to identify the group.
- The "group member list" is a list of all users belonging to this group, with different users separated by commas (,). This user group may be the user's primary group or a supplementary group.
An example of the /etc/group file is as follows:
root::0:root bin::2:root,bin sys::3:root,uucp adm::4:root,adm daemon::5:root,daemon lp::7:root,lp users::20:root,sam
IV. Adding users in batches
Adding and removing users is an easy task for every Linux system administrator. The tricky part is when you need to add dozens, hundreds, or even thousands of users - it is unlikely that we can use useradd to add them one by one. We must find a simple way to create a large number of users. Linux systems provide tools for creating a large number of users, allowing you to create many users immediately. The method is as follows:
(1) First edit a text user file.
Each column should be written according to the/etc/passwdformat of the password file. Note that each user's username, UID, and home directory must not be the same. The password field can be left blank or filled with an x. An example file user.txt is as follows:
user001::600:100:user:/home/user001:/bin/bash user002::601:100:user:/home/user002:/bin/bash user003::602:100:user:/home/user003:/bin/bash user004::603:100:user:/home/user004:/bin/bash user005::604:100:user:/home/user005:/bin/bash user006::605:100:user:/home/user006:/bin/bash
(2) Execute the command as root/usr/sbin/newusers, and from the just-created user fileuser.txtimport data to create users:
# newusers < user.txt
Then you can execute the commandvipworvi /etc/passwdto check/etc/passwdwhether the file already contains the data of these users, and whether the users' home directories have been created.
(3) Execute the command /usr/sbin/pwunconv.
will/etc/shadowThe generatedshadowpassword is decoded, then written back to/etc/passwd, and the/etc/shadowofshadowpassword field is deleted. This is to facilitate the next step of password conversion, that is, first cancel theshadow passwordfunction.
# pwunconv
(4) Edit the password mapping file for each user.
The format is:
Username: password
Example filepasswd.txtcontent is as follows:
user001:123456 user002:123456 user003:123456 user004:123456 user005:123456 user006:123456
(5) Execute the command as root/usr/sbin/chpasswd。
to create user passwords.chpasswdIt will write the/usr/bin/passwdpassword encoded by the command into/etc/passwdthe password field of /etc/passwd.
# chpasswd < passwd.txt
(6) After confirming that the password has been encoded and written into the password field of /etc/passwd.
execute the command/usr/sbin/pwconvto encode the password asshadow password, and write the result to/etc/shadow。
# pwconv
This completes the creation of a large number of users. Afterward, you can go to /home to check whether the permission settings of these users' home directories are all correct, and log in to verify whether the user passwords are correct.
Other Extensions