← Linux from ScratchCheat sheet
M17Linux from Scratch

M17 — Users and groups (admin lite)

Time: about 45–70 minutes
Lab root: /tmp/linux-lab-pushpjeet/m17 (inspect anywhere; create users only on a disposable VM)

Linux is a multi-user system. Even on a laptop that only you use, services run as separate accounts, and permissions (M12) key off UID, GID, and group membership. This module is “admin lite”: enough to inspect who you are, read account records at a high level, and — on a disposable VM — create a second user and switch into it.

Do not create or delete users on a shared production host as practice.

Prerequisites#

  • M12 permissions basics.
  • sudo on a practice VM for the create-user lab.
  • Read-only inspection works everywhere (including locked-down boxes).

Learning objectives#

  1. Report your identity with whoami, id, and groups.
  2. Explain the seven fields of an /etc/passwd line at a high level.
  3. Distinguish login name, UID, primary group, and supplementary groups.
  4. Create a user and group with useradd / groupadd (or adduser on Debian) where permitted.
  5. Set a password with passwd and switch users with su / sudo.

Lab environment#

Read-only parts can use any account. Create-user parts need a VM you control.

mkdir -p /tmp/linux-lab-pushpjeet/m17
cd /tmp/linux-lab-pushpjeet/m17

1. Who am I right now?#

whoami          # login name
id              # UID, GID, groups
id -u           # numeric UID only
id -g           # numeric primary GID
id -un          # username
id -gn          # primary group name
groups          # group names

Lab run (drafting box):

box
uid=1000(box) gid=1000(box) groups=1000(box)

Your names will differ (student, ubuntu, ec2-user, …). UID 1000 is a common first human user; UID 0 is root.


2. Reading /etc/passwd (high level)#

Each line is an account record. Example from the lab box:

box:x:1000:1000::/home/box:/bin/bash
Field # Example Meaning
1 box Username
2 x Password placeholder (real hash lives in /etc/shadow, root-only)
3 1000 UID
4 1000 Primary GID
5 (empty here) GECOS / comment (full name, room, …)
6 /home/box Home directory
7 /bin/bash Login shell

Inspect one account without dumping the whole file:

getent passwd "$(whoami)"
getent passwd root

Root line (typical):

root:x:0:0:root:/root:/bin/bash

getent also works in environments using network account services; prefer it over only cat /etc/passwd when you are unsure.

Groups live in /etc/group (name, placeholder, GID, member list):

getent group "$(id -gn)"

3. Creating users and groups (disposable VM only)#

Commands live in /usr/sbin — need root/sudo.

Debian / Ubuntu friendly: adduser#

Interactive, creates home, asks for password:

sudo adduser labmate

Portable low-level: useradd + passwd#

sudo groupadd trainers           # optional extra group
sudo useradd -m -s /bin/bash -G trainers labmate
sudo passwd labmate              # set password
Flag Meaning
-m Create home directory
-s /bin/bash Login shell
-G group Supplementary groups (comma-separated)
-g group Primary group

Verify and switch#

id labmate
groups labmate
su - labmate                     # password of labmate
# or:
sudo -u labmate -i

su - starts a login shell (loads labmate’s environment). Exit with exit.

Clean up after the lab (VM only)#

sudo userdel -r labmate          # -r removes home
sudo groupdel trainers           # if empty and you created it

4. sudo in one paragraph#

sudo runs a single command as root (or another user) if your account is allowed in sudoers. Prefer sudo apt install … over staying logged in as root all day. Check access with sudo -v or a harmless sudo true.


Common mistakes#

Mistake Fix
Forgetting -m with useradd No home → confusing login experience; use -m or adduser
Leaving practice users on a shared box userdel -r when the lab ends
Editing /etc/passwd by hand as a beginner Use useradd / usermod / vipw only when you know the risk
Expecting su without - to feel like a full login Prefer su - for a clean environment
Confusing UID with PID UID = user; PID = process (M13)

Hands-on lab (40–60 minutes)#

Part A — Inspect (10 min, any host)#

  1. Run whoami, id, groups.
  2. getent passwd "$(whoami)" and label each field on paper.
  3. Compare with getent passwd root.

Part B — Second user (30 min, disposable VM)#

  1. Create labmate with home and bash.
  2. Set a password.
  3. su - labmate and create ~/hello.txt.
  4. Exit; as your admin user, check /home/labmate/hello.txt ownership with ls -l.
  5. Delete labmate with userdel -r when finished.

Part C — Stretch#

Create group projectx, add both your admin user and labmate to it, and make a shared directory /srv/projectx with group-write and the setgid bit (revisits M12).


Practice: check your understanding#

Multiple choice#

Q1. In student:x:1001:1001:Student User:/home/student:/bin/bash, what is 1001 immediately after x:?

  • A. The SSH port
  • B. The UID
  • C. The file size
  • D. The nice value

Answer: B. The next 1001 is the primary GID.

Q2. Which command prints UID, GID, and groups in one line?

  • A. pwd
  • B. id
  • C. tar
  • D. gzip

Answer: B.

Q3. Why should you avoid practicing userdel on a shared work laptop?

  • A. The command does not exist on Linux
  • B. You might remove a real account and its home data
  • C. It only works on Windows
  • D. It disables apt forever

Answer: B.

Flashcards#

Front Back
UID Numeric user id
GID Numeric group id
/etc/passwd Account database (readable; no real password hashes)
/etc/shadow Password hashes (root-only)
whoami Current username
useradd -m Create user and home
passwd user Set / change password
su - user Switch to login shell as user
userdel -r Delete user and home
Primary group Default group for new files (field 4 of passwd)

Match the columns#

Item Match
Field 1 of passwd Username
Field 3 UID
Field 6 Home directory
Field 7 Login shell
groups Show group membership names
getent passwd u Look up account u

Fill in the blank#

  1. Create user with home: sudo useradd ___ -s /bin/bash labmate
    Answer: -m

  2. Set password: sudo _______ labmate
    Answer: passwd

  3. Login shell as that user: su ___ labmate
    Answer: -

  4. Remove user and home: sudo userdel ___ labmate
    Answer: -r

Order the steps — create → passwd → su#

  1. sudo useradd -m -s /bin/bash labmate (or sudo adduser labmate)
  2. sudo passwd labmate
  3. id labmate to verify
  4. su - labmate
  5. Do a tiny task (create a file)
  6. exit back to your admin account

Correct order: 1 → 2 → 3 → 4 → 5 → 6

Mini terminal challenge#

Challenge: Second user on a VM#

Goal: Create labmate, switch, prove home ownership, clean up.

Setup: Disposable Linux VM with sudo.

Tasks: Follow Part B of the lab.

Verify: While su’d, whoami prints labmate. After userdel -r, getent passwd labmate is empty.

Stretch: Add labmate to group sudo or wheel only if your VM docs say that is appropriate — then remove that privilege before deleting the user.


Module wrap#

You can read identity and /etc/passwd fields, and — on a practice VM — create a user, set a password, switch with su, and clean up. Next: networking checks (M18).


Continue

← Linux from Scratch hub · Cheat sheet · All tutorials