Linux User and Group Management
linux is a multi-user and multitasking OS. In Linux, you can create any number of user account and groups. A user is always connected to a particular group and there can be any number of groups as well.
The user home directory by default is created under “/home” directory with the user name. E.g. User techbie has home directory “/home/techbie”, the mail account is created under “/var/spool/mail/”.
Each user and group in the system is identified by a unique no called as ID.
/etc/passwd
The file whare system user account definition is done is /etc/passwd. This file has the following strucutre
#cat /etc/passwd
username:a:500:500:Some Comments:/home/username:/bin/sh
username :
The system account username. It should not start with a number or include uppercase letters
a
The password. As a points to /etc/shadow for the password. An * means the account is disabled. A random group of letters and numbers represents the encrypted password
500
the user ID(UID) for the user
500
the group ID (GID) associated with that user
Some comments
Any information can be used in this field
/home/username
By default, RHEL places new home directories in /home/username
/bin/sh
Default user shell
In order add/delete users to the system this file can be edited directly with vipw or using useradd/userdel commends a described in next sections
/etc/group
The file where system group account definition is done is /etc/group . This file has the following structure
#cat /etc/group groupname:x:500:user1,user2
groupname
The system account groupname user gets this own group. BY default when a user is crated is related to a group with groupname equal to username
x
The group password. An x points to /etc/gshadow for the password as user password on /etc/passwd random group of letters and numbers represents the encrypted password
500
The group ID (GID) associated with user
user1, user2
Lists of users that belong t the group If it’s blank means that there is a username that is identical to the groupname
In order to add/delete groups to the system this file can be edited directly with vigr or using useradd/userdel commands as described in net section
/etc/shadow
The /etc/shadow file is can be read for every user on the system so include the encrypted password there is not a good idea. For this reason the file /etc/shadow accessible to root only is used to store the encrypted password
#/etc/shadow
username: $1sdsew$ed%wqee@132ewSDADdsa :14860:0:99999:7:::
Username
Username shadow entry, it is related with username account on /etc/passwd
$1sdsew$ed%wqee@132ewSDADdsa
Encrypted password. An x in the second column of /etc/passwd means that the encrypted password is stored here
14860
Last password changed date. In Linux epoch number if days: number of days after January 1, 1970
0
The values of 0 here means that this user can keep this password forever
99999
The system will ask to user to change his password after 99999 days since account creation
::
The values means the number if days before password expiration when is made a warning is given in this case none
::
the sets the no of days after password expiration when an account is made inactive in this case none
::
the values means the number if days after password expiration when an account is disabled in this case none
Adding user account:
When a user account needs to be added to the system the commend useradd must be used:
# useradd -u 678 -c “Test add user” -d /home/techbie -s /bin/bash techbie
With this command we have created the user account techbie with UID=678 which home directory in /home/techbie and default shell bash. By default the user is assigned to a new created group silicon with GID=678. This values can be changed using the -g option
#cat /etc/passwd
techbie:x:678:678:Test add user:/home/techbie:/bin/bash
Deleting user Account:
When a user account needs to be removed in the system the commend userdel must be used:
# userdel r techbie
With this commend all information about techbie account in removed on the system, including all home directory and mail spool files.
Modifying user Account:
I order to change the parameters of an existing account the commends usermod and/or chage can be used
# usermod e 2016-07-30 techbie
Sets the expiration account day for user “techbie” to 2016-07-30
# usermod G sales techbie
Sets ‘techbie’ account group ownership to sales group
# chage E -1 techbie
Removes any account expiration date for user “techbie”
# usermod expiredate 2016-07-30 techbie
Sets the expiredate for a user account techbie
# passwd d techbie
Disable the user account techbie
# passwd u techbie
Unlock the user account techbie
Linux User and Group Management的更多相关文章
- Linux指令--/etc/group文件
		
Linux /etc/group文件与/etc/passwd和/etc/shadow文件都是有关于系统管理员对用户和用户组管理时相关的文件.linux /etc/group文件是有关于系统管理员对用户 ...
 - 每天一个linux命令: /etc/group文件详解
		
Linux /etc/group文件与/etc/passwd和/etc/shadow文件都是有关于系统管理员对用户和用户组管理时相关的文件.linux /etc/group文件是有关于系统管理员对用户 ...
 - (linux)idr(integer ID management)机制
		
 最近研究进程间通信,遇到了idr相关的函数,为了扫清障碍,先研究了linux的idr机制. IDR(integer ID management)的要完成的任务是给要管理的对象分配一个唯一的ID,于 ...
 - Linux LVM Logical Volume Management 逻辑卷的管理
		
博主是一个数据库DBA,但是一般来说,是不做linux服务器LVM 逻辑卷的创建.扩容和减容操作的,基本上有系统管理员操作,一是各司其职,专业的事专业的人做,二是做多了你的责任也多了,哈哈! 但是li ...
 - linux 学习随笔-group和user管理
		
1:/etc/passwd 打开该文件,可以看到每一行内容被分割成了7个字段比如:root:x:0:0:root:/root:/bin/bash 第一个字段表示用户名为root用户 第二个字段存放了该 ...
 - <<Linux kernel development>> Process Management
		
The Process On modern operating systems,processes provide two virtualizations:a virtualized processo ...
 - Neutron 理解(14):Neutron ML2 + Linux bridge + VxLAN 组网
		
学习 Neutron 系列文章: (1)Neutron 所实现的虚拟化网络 (2)Neutron OpenvSwitch + VLAN 虚拟网络 (3)Neutron OpenvSwitch + GR ...
 - linux根文件系统制作
		
在嵌入式中移植的内核下载到开发板上,是没有办法真正的启动Linux操作系统的,会出现无法加载文件系统的错误. 那么根文件系统在系统启动中到底是什么时候挂载的呢?先将/dev/ram0挂载,而后执行/l ...
 - Linux就这个范儿 第16章 谁都可以从头再来--从头开始编译一套Linux系统  nsswitch.conf配置文件
		
Linux就这个范儿 第16章 谁都可以从头再来--从头开始编译一套Linux系统 nsswitch.conf配置文件 朋友们,今天我对你们说,在此时此刻,我们虽然遭受种种困难和挫折,我仍然有一个梦 ...
 
随机推荐
- 使用virtualenv发布Python程序
			
客户环境不能上网,开始想把所有依赖包下载下来,进入客户环境进行安装.但为了避免出差,部署工作交给其他同事了,我想还是需要更简单的方式. 实验了一下virtualenv是可以的 1. 创建一个新的环境( ...
 - 连接RDS数据库
 - mysql权限修改记录
			
select user, password, host from mysql.user; GRANT ALL PRIVILEGES ON *.* TO 'root'@'147.114.169.197' ...
 - alias用于设置当前数据表的别名,
			
alias用于设置当前数据表的别名,便于使用其他的连贯操作例如join方法等. 示例: $Model = M('User'); $Model->alias('a')->join('__DE ...
 - idea加载完文件报错:java:-source 1.7中不支持lambda表达式  解决方案
			
1.file - Project Structure ctrl+alt+shift+s 2.modules 中把7换成8
 - js 类数组转化数组
			
一.常见类数组集合 (1).arguements function fn(){ var arr = [].slice.call(arguements,0); } (2).HTMLCollection ...
 - kubeadm安装Kubernetes 1.15 实践
			
原地址参考github 一.环境准备(在全部设备上进行) 3 台 centos7.5 服务器,网络使用 Calico. IP地址 节点角色 CPU 内存 Hostname 10.0.1.45 mast ...
 - SpringBoot学习笔记(七):SpringBoot使用AOP统一处理请求日志、SpringBoot定时任务@Scheduled、SpringBoot异步调用Async、自定义参数
			
SpringBoot使用AOP统一处理请求日志 这里就提到了我们Spring当中的AOP,也就是面向切面编程,今天我们使用AOP去对我们的所有请求进行一个统一处理.首先在pom.xml中引入我们需要的 ...
 - Angular+Bootstrap3导航菜单
			
Angular+Bootstrap3导航菜单 AngularJS体验式编程系列文章,将介绍如何用angularjs构建一个强大的web前端系统.angularjs是由Google团队开发的一款非常优秀 ...
 - C开发系列-指针
			
指针 通过一段简单的程序,引入指针的概念 #include <iostream> using namespace std; // changeValue函数的定义 void changeV ...