x386.org

User and Group Administration

User and group management essentials

0. Specs


0.1. The What

This tutorial covers basic user and group administration on Debian 12/13 and Ubuntu 24.04/26.04 Servers.

The commands and concepts also work on Debian, Ubuntu, and their derivatives' desktop environments (Ubuntu, Kubuntu, Xubuntu, Lubuntu, MX Linux, Mint, etc.).

0.2. Sources


1. User Add and Delete


Add two new users (jdoe and jdoe2) with home directories and bash as their default shell:

sudo useradd -m -s /bin/bash jdoe
sudo useradd -m -s /bin/bash jdoe2

Verify that the users were created successfully:

id jdoe
grep jdoe /etc/passwd

Change a user's password interactively:

sudo passwd jdoe

Change a user's password non-interactively (useful for scripts):

echo "jdoe:SecurePass123" | sudo chpasswd

Delete a user and their home directory:

sudo userdel -r jdoe


2. User Information Files


/etc/passwd file: This file contains user account information. Each line represents one user with fields separated by colons.

exforge:x:1000:1000:Exforge,,,:/home/exforge:/bin/bash

Format: username:password:UID:GID:GECOS:home_directory:shell

  • Username: User login name
  • Password: x indicates the password is stored in /etc/shadow
  • UID: User ID number
  • GID: Primary group ID number
  • GECOS: Comment field (typically full name and contact information)
  • Home directory: User's home directory path
  • Shell: User's default shell

/etc/shadow file:

This secure file contains encrypted passwords and password aging information.

exforge:$6$z09H4l.6$h....A/tDL0:18221:0:99999:7:::

Format: username:password:last_change:min_age:max_age:warn:inactive:expire

  • Username: User login name
  • Password: Encrypted password hash
  • last_change: Days since Jan 1, 1970 that password was last changed
  • min_age: Minimum days required between password changes
  • max_age: Maximum days password is valid
  • warn: Days before password expires that user is warned
  • inactive: Days after password expires until account is disabled
  • expire: Date when account will be disabled

/etc/skel directory: The contents of this directory are copied to new users' home directories when their accounts are created. You can place default configuration files (like .bashrc, .profile) here.


3. Root user


The root account is locked by default in Ubuntu and optionally locked in Debian during installation.

To set a password for root (which unlocks the account):

sudo passwd

To switch to the root account temporarily without unlocking it (uses your sudo privileges):

sudo -i

To switch to another user (requires the target user's password):

su - username

To switch to another user using sudo privileges (doesn't require the target user's password):

sudo su - username


4. Batch User Creation


Create a text file for user data:

touch users.txt

Set secure permissions on the file:

chmod 600 users.txt

Add user information to the file:

sudo nano users.txt

Use the following format: username:password:UID:GID:full_name:home_directory:shell

user1:password:::User1:/home/user1:/bin/bash
user2:password:::User2:/home/user2:/bin/bash
user3:password:::User3:/home/user3:/bin/bash

Process the file to create the users:

sudo newusers users.txt

Verify the users were created:

grep -E 'user1|user2|user3' /etc/passwd

Security Note: It's good practice to change the users' passwords after batch creation, as the plaintext passwords in the file may be a security risk:

sudo passwd user1


5. Group Management


View your current group memberships:

groups

Or view all groups on the system:

cat /etc/group

The /etc/group file format is similar to /etc/passwd: group_name:password:GID:user_list

Create new groups:

sudo groupadd admins
sudo groupadd admins2

Delete a group:

sudo groupdel admins2

List members of a specific group:

getent group admins

Add a user to a group as a secondary group membership:

sudo usermod -aG admins jdoe2
sudo usermod -a -G admins user1

Change a user's primary group:

sudo usermod -g admins jdoe2

Remove a user from a group:

sudo gpasswd -d jdoe2 admins


6. User Account Modifications


Change a user's home directory and move the contents:

sudo usermod -d /home/jsmith -m jdoe2

Change a username:

sudo usermod -l jsmith jdoe2

Lock a user account (prevents login):

sudo passwd -l jsmith

Unlock a user account:

sudo passwd -u jsmith

View password expiration information:

sudo chage -l jsmith


7. sudo Group


Members of the sudo group can use the sudo command to execute commands with elevated privileges.

Configure sudo privileges:

sudo visudo

This command safely edits the sudo configuration file (/etc/sudoers) in the default editor.

Example sudoers configurations with explanations:

Allow all members of the sudo group to run any command as any user:

%sudo   ALL=(ALL:ALL) ALL
# %sudo  - All members of the 'sudo' group
# ALL    - From any terminal/host
# (ALL:ALL) - Can run commands as ANY user and ANY group
# ALL    - Can run ANY command

Specific user restriction - user charlie can only run apt as user dscully and group admins on host ubuntu-server:

charlie  ubuntu-server=(dscully:admins) /usr/bin/apt
# charlie        - Username
# ubuntu-server  - Only on this specific host
# (dscully:admins) - Can run commands as user dscully and group admins
# /usr/bin/apt   - Only the apt command

Allow user ansible to run any command without a password prompt:

ansible ALL=(ALL) NOPASSWD: ALL

View your current sudo privileges:

sudo -l
x386.org