Linux User and Group Management
linux is a multi-user and multitasking OS. In Linux, you can create any number of user account and groups. A user is always connected to a particular group and there can be any number of groups as well.
The user home directory by default is created under “/home” directory with the user name. E.g. User techbie has home directory “/home/techbie”, the mail account is created under “/var/spool/mail/”.
Each user and group in the system is identified by a unique no called as ID.
/etc/passwd
The file whare system user account definition is done is /etc/passwd. This file has the following strucutre
#cat /etc/passwd
username:a:500:500:Some Comments:/home/username:/bin/sh
username :
The system account username. It should not start with a number or include uppercase letters
a
The password. As a points to /etc/shadow for the password. An * means the account is disabled. A random group of letters and numbers represents the encrypted password
500
the user ID(UID) for the user
500
the group ID (GID) associated with that user
Some comments
Any information can be used in this field
/home/username
By default, RHEL places new home directories in /home/username
/bin/sh
Default user shell
In order add/delete users to the system this file can be edited directly with vipw or using useradd/userdel commends a described in next sections
/etc/group
The file where system group account definition is done is /etc/group . This file has the following structure
#cat /etc/group groupname:x:500:user1,user2
groupname
The system account groupname user gets this own group. BY default when a user is crated is related to a group with groupname equal to username
x
The group password. An x points to /etc/gshadow for the password as user password on /etc/passwd random group of letters and numbers represents the encrypted password
500
The group ID (GID) associated with user
user1, user2
Lists of users that belong t the group If it’s blank means that there is a username that is identical to the groupname
In order to add/delete groups to the system this file can be edited directly with vigr or using useradd/userdel commands as described in net section
/etc/shadow
The /etc/shadow file is can be read for every user on the system so include the encrypted password there is not a good idea. For this reason the file /etc/shadow accessible to root only is used to store the encrypted password
#/etc/shadow
username: $1sdsew$ed%wqee@132ewSDADdsa :14860:0:99999:7:::
Username
Username shadow entry, it is related with username account on /etc/passwd
$1sdsew$ed%wqee@132ewSDADdsa
Encrypted password. An x in the second column of /etc/passwd means that the encrypted password is stored here
14860
Last password changed date. In Linux epoch number if days: number of days after January 1, 1970
0
The values of 0 here means that this user can keep this password forever
99999
The system will ask to user to change his password after 99999 days since account creation
::
The values means the number if days before password expiration when is made a warning is given in this case none
::
the sets the no of days after password expiration when an account is made inactive in this case none
::
the values means the number if days after password expiration when an account is disabled in this case none
Adding user account:
When a user account needs to be added to the system the commend useradd must be used:
# useradd -u 678 -c “Test add user” -d /home/techbie -s /bin/bash techbie
With this command we have created the user account techbie with UID=678 which home directory in /home/techbie and default shell bash. By default the user is assigned to a new created group silicon with GID=678. This values can be changed using the -g option
#cat /etc/passwd
techbie:x:678:678:Test add user:/home/techbie:/bin/bash
Deleting user Account:
When a user account needs to be removed in the system the commend userdel must be used:
# userdel r techbie
With this commend all information about techbie account in removed on the system, including all home directory and mail spool files.
Modifying user Account:
I order to change the parameters of an existing account the commends usermod and/or chage can be used
# usermod e 2016-07-30 techbie
Sets the expiration account day for user “techbie” to 2016-07-30
# usermod G sales techbie
Sets ‘techbie’ account group ownership to sales group
# chage E -1 techbie
Removes any account expiration date for user “techbie”
# usermod expiredate 2016-07-30 techbie
Sets the expiredate for a user account techbie
# passwd d techbie
Disable the user account techbie
# passwd u techbie
Unlock the user account techbie
Linux User and Group Management的更多相关文章
- Linux指令--/etc/group文件
Linux /etc/group文件与/etc/passwd和/etc/shadow文件都是有关于系统管理员对用户和用户组管理时相关的文件.linux /etc/group文件是有关于系统管理员对用户 ...
- 每天一个linux命令: /etc/group文件详解
Linux /etc/group文件与/etc/passwd和/etc/shadow文件都是有关于系统管理员对用户和用户组管理时相关的文件.linux /etc/group文件是有关于系统管理员对用户 ...
- (linux)idr(integer ID management)机制
最近研究进程间通信,遇到了idr相关的函数,为了扫清障碍,先研究了linux的idr机制. IDR(integer ID management)的要完成的任务是给要管理的对象分配一个唯一的ID,于 ...
- Linux LVM Logical Volume Management 逻辑卷的管理
博主是一个数据库DBA,但是一般来说,是不做linux服务器LVM 逻辑卷的创建.扩容和减容操作的,基本上有系统管理员操作,一是各司其职,专业的事专业的人做,二是做多了你的责任也多了,哈哈! 但是li ...
- linux 学习随笔-group和user管理
1:/etc/passwd 打开该文件,可以看到每一行内容被分割成了7个字段比如:root:x:0:0:root:/root:/bin/bash 第一个字段表示用户名为root用户 第二个字段存放了该 ...
- <<Linux kernel development>> Process Management
The Process On modern operating systems,processes provide two virtualizations:a virtualized processo ...
- Neutron 理解(14):Neutron ML2 + Linux bridge + VxLAN 组网
学习 Neutron 系列文章: (1)Neutron 所实现的虚拟化网络 (2)Neutron OpenvSwitch + VLAN 虚拟网络 (3)Neutron OpenvSwitch + GR ...
- linux根文件系统制作
在嵌入式中移植的内核下载到开发板上,是没有办法真正的启动Linux操作系统的,会出现无法加载文件系统的错误. 那么根文件系统在系统启动中到底是什么时候挂载的呢?先将/dev/ram0挂载,而后执行/l ...
- Linux就这个范儿 第16章 谁都可以从头再来--从头开始编译一套Linux系统 nsswitch.conf配置文件
Linux就这个范儿 第16章 谁都可以从头再来--从头开始编译一套Linux系统 nsswitch.conf配置文件 朋友们,今天我对你们说,在此时此刻,我们虽然遭受种种困难和挫折,我仍然有一个梦 ...
随机推荐
- POJ - 2778 ~ HDU - 2243 AC自动机+矩阵快速幂
这两题属于AC自动机的第二种套路通过矩阵快速幂求方案数. 题意:给m个病毒字符串,问长度为n的DNA片段有多少种没有包含病毒串的. 根据AC自动机的tire图,我们可以获得一个可达矩阵. 关于这题的t ...
- 最全Linux常用命令大全
查看系统系统信息 arch 显示机器的处理器架构(1) uname -m 显示机器的处理器架构(2) uname -r 显示正在使用的内核版本 dmidecode -q 显示硬件系统部件 - (SMB ...
- Caffe系列1——网络文件和求解分析
1. 首先,我们先看一个完整的文件:lenet_train_test.prototxt name: "LeNet" #整个网络的名称 layer { #数据层——训练数据 name ...
- MVVM test
示例代码 public class RegisterUserViewModel { public UserInfo userInfo { get; set; } public ICommand Cli ...
- import: not authorized `time' @ error/constitute.c/WriteImage/1028. import: not authorized `rospy' @ error/constitute.c/WriteImage/1028.
- iframe跨域数据传递
项目中需要和其他单位合作开发,方案采用iframe嵌入页面,开发过程中设计到了跨域数据的传递,初步方案决定使用html5 API postMessage进行iframe跨域数据传递: 域名A下的页面 ...
- 2019年6月份Github上最热门的开源项目排行出炉,一起来看看本月上榜的开源项目
6月份Github上最热门的开源项目排行出炉,一起来看看本月上榜的开源项目有哪些: 1. the-art-of-command-line https://github.com/jlevy/the-ar ...
- topology进程结束会不会关闭数据库连接
测试环境:redhat,oracle 11.2.0.3.0 测试目标:当java进程关闭之后,进程的数据库连接会不会被释放,何时被释放 实验证明:在运行topology前,执行 select coun ...
- java代码优化写法1(转摘)
源文地址:https://blog.csdn.net/qq_15766297/article/details/70503222 代码优化,一个很重要的课题.可能有些人觉得没用,一些细小的地方有什么好修 ...
- mariadb ROW格式复制下从库结构变更引发1677错误
stop slave;set global slave_type_conversions=ALL_LOSSY;start slave; 详细度娘slave_type_conversions的参数说明