Prerequisites#
- M12 permissions basics.
- sudo on a practice VM for the create-user lab.
- Read-only inspection works everywhere (including locked-down boxes).
Learning objectives#
- Report your identity with
whoami,id, andgroups. - Explain the seven fields of an
/etc/passwdline at a high level. - Distinguish login name, UID, primary group, and supplementary groups.
- Create a user and group with
useradd/groupadd(oradduseron Debian) where permitted. - Set a password with
passwdand switch users withsu/sudo.
Lab environment#
Read-only parts can use any account. Create-user parts need a VM you control.
mkdir -p /tmp/linux-lab-pushpjeet/m17
cd /tmp/linux-lab-pushpjeet/m17
1. Who am I right now?#
whoami # login name
id # UID, GID, groups
id -u # numeric UID only
id -g # numeric primary GID
id -un # username
id -gn # primary group name
groups # group names
Lab run (drafting box):
box
uid=1000(box) gid=1000(box) groups=1000(box)
Your names will differ (student, ubuntu, ec2-user, …). UID 1000 is a common first human user; UID 0 is root.
2. Reading /etc/passwd (high level)#
Each line is an account record. Example from the lab box:
box:x:1000:1000::/home/box:/bin/bash
| Field # | Example | Meaning |
|---|---|---|
| 1 | box |
Username |
| 2 | x |
Password placeholder (real hash lives in /etc/shadow, root-only) |
| 3 | 1000 |
UID |
| 4 | 1000 |
Primary GID |
| 5 | (empty here) | GECOS / comment (full name, room, …) |
| 6 | /home/box |
Home directory |
| 7 | /bin/bash |
Login shell |
Inspect one account without dumping the whole file:
getent passwd "$(whoami)"
getent passwd root
Root line (typical):
root:x:0:0:root:/root:/bin/bash
getent also works in environments using network account services; prefer it over only cat /etc/passwd when you are unsure.
Groups live in /etc/group (name, placeholder, GID, member list):
getent group "$(id -gn)"
3. Creating users and groups (disposable VM only)#
Commands live in /usr/sbin — need root/sudo.
Debian / Ubuntu friendly: adduser#
Interactive, creates home, asks for password:
sudo adduser labmate
Portable low-level: useradd + passwd#
sudo groupadd trainers # optional extra group
sudo useradd -m -s /bin/bash -G trainers labmate
sudo passwd labmate # set password
| Flag | Meaning |
|---|---|
-m |
Create home directory |
-s /bin/bash |
Login shell |
-G group |
Supplementary groups (comma-separated) |
-g group |
Primary group |
Verify and switch#
id labmate
groups labmate
su - labmate # password of labmate
# or:
sudo -u labmate -i
su - starts a login shell (loads labmate’s environment). Exit with exit.
Clean up after the lab (VM only)#
sudo userdel -r labmate # -r removes home
sudo groupdel trainers # if empty and you created it
4. sudo in one paragraph#
sudo runs a single command as root (or another user) if your account is allowed in sudoers. Prefer sudo apt install … over staying logged in as root all day. Check access with sudo -v or a harmless sudo true.
Common mistakes#
| Mistake | Fix |
|---|---|
Forgetting -m with useradd |
No home → confusing login experience; use -m or adduser |
| Leaving practice users on a shared box | userdel -r when the lab ends |
Editing /etc/passwd by hand as a beginner |
Use useradd / usermod / vipw only when you know the risk |
Expecting su without - to feel like a full login |
Prefer su - for a clean environment |
| Confusing UID with PID | UID = user; PID = process (M13) |
Hands-on lab (40–60 minutes)#
Part A — Inspect (10 min, any host)#
- Run
whoami,id,groups. getent passwd "$(whoami)"and label each field on paper.- Compare with
getent passwd root.
Part B — Second user (30 min, disposable VM)#
- Create
labmatewith home and bash. - Set a password.
su - labmateand create~/hello.txt.- Exit; as your admin user, check
/home/labmate/hello.txtownership withls -l. - Delete
labmatewithuserdel -rwhen finished.
Part C — Stretch#
Create group projectx, add both your admin user and labmate to it, and make a shared directory /srv/projectx with group-write and the setgid bit (revisits M12).
Practice: check your understanding#
Multiple choice#
Q1. In student:x:1001:1001:Student User:/home/student:/bin/bash, what is 1001 immediately after x:?
- A. The SSH port
- B. The UID
- C. The file size
- D. The nice value
Answer: B. The next 1001 is the primary GID.
Q2. Which command prints UID, GID, and groups in one line?
- A.
pwd - B.
id - C.
tar - D.
gzip
Answer: B.
Q3. Why should you avoid practicing userdel on a shared work laptop?
- A. The command does not exist on Linux
- B. You might remove a real account and its home data
- C. It only works on Windows
- D. It disables
aptforever
Answer: B.
Flashcards#
| Front | Back |
|---|---|
| UID | Numeric user id |
| GID | Numeric group id |
/etc/passwd |
Account database (readable; no real password hashes) |
/etc/shadow |
Password hashes (root-only) |
whoami |
Current username |
useradd -m |
Create user and home |
passwd user |
Set / change password |
su - user |
Switch to login shell as user |
userdel -r |
Delete user and home |
| Primary group | Default group for new files (field 4 of passwd) |
Match the columns#
| Item | Match |
|---|---|
| Field 1 of passwd | Username |
| Field 3 | UID |
| Field 6 | Home directory |
| Field 7 | Login shell |
groups |
Show group membership names |
getent passwd u |
Look up account u |
Fill in the blank#
-
Create user with home:
sudo useradd ___ -s /bin/bash labmate
Answer:-m -
Set password:
sudo _______ labmate
Answer:passwd -
Login shell as that user:
su ___ labmate
Answer:- -
Remove user and home:
sudo userdel ___ labmate
Answer:-r
Order the steps — create → passwd → su#
sudo useradd -m -s /bin/bash labmate(orsudo adduser labmate)sudo passwd labmateid labmateto verifysu - labmate- Do a tiny task (create a file)
exitback to your admin account
Correct order: 1 → 2 → 3 → 4 → 5 → 6
Mini terminal challenge#
Challenge: Second user on a VM#
Goal: Create labmate, switch, prove home ownership, clean up.
Setup: Disposable Linux VM with sudo.
Tasks: Follow Part B of the lab.
Verify: While su’d, whoami prints labmate. After userdel -r, getent passwd labmate is empty.
Stretch: Add labmate to group sudo or wheel only if your VM docs say that is appropriate — then remove that privilege before deleting the user.
Module wrap#
You can read identity and /etc/passwd fields, and — on a practice VM — create a user, set a password, switch with su, and clean up. Next: networking checks (M18).