Users, Groups & sudo
A user is a number, a group is a list of numbers, and sudo is a rule file. Read all three and you can say exactly who may do what.
An interactive Linux lesson: 25 steps, about 32 minutes, on a live simulation in your browser.
You are alice, the administrator of web01, the machine that serves the shop's website. Three jobs are waiting: a new hire needs an account, bob needs to restart the web server without being handed the whole machine, and a contractor has left.
Every one of those is a question about identity, so start with your own. whoami prints a name. id prints what the kernel actually holds for this shell.
What you will learn
You are a number
- Who does the machine think you are?: Every process carries one uid and a list of group ids. Those numbers, and nothing else, are who you are to the kernel.
- The name is a lookup: Files and processes store uids. Names exist in one lookup table and are translated only when something is printed.
Three files hold every account
- /etc/passwd, field by field: /etc/passwd is name:x:uid:gid:comment:home:shell. It answers who an account is, never what its password is.
- Where the password really lives: /etc/passwd is public so that names can be looked up. The hashes were moved to /etc/shadow so that only root can read them.
- Groups: one primary, any number more: Primary group: one, from /etc/passwd, stamped on the files you create. Supplementary groups: many, from /etc/group. Access checks use all of them.
- Accounts nobody logs in to: A system user is an identity for a program. A nologin shell stops anyone logging in as it and changes nothing about what it may run as.
Creating and changing accounts
- Break it: useradd with no flags
- useradd -m -s, then passwd: useradd writes lines in three files. -m is what creates the home directory; without it the home is only a field.
- Put people in groups: Grant access to groups, then manage people by moving them in and out of groups.
- usermod -G without -a: usermod -G means "the supplementary groups are exactly these". Only -aG means "add these".
- Drill: put bob back
Groups are fixed at login
- In the group, and still refused: A process's groups are a copy taken at login. Changing /etc/group changes the next login, never a running shell.
- newgrp, or log in again
Becoming someone else
- Break it: su asks for their password: su asks for the target account's password. If you would need to share a password to use it, it is the wrong tool.
- su versus su -: su NAME changes the uid and keeps where you were. su - NAME starts that user's login shell from scratch.
- sudo: one command, as root, logged: sudo checks your identity against a rule file, runs one command as the target user and writes down who asked.
How sudo decides
- The rule that makes you an admin: A sudoers rule reads: who, on which host = (as which user) which commands. Being an admin on Ubuntu means being in group sudo.
- Break it: bob restarts nginx
- Grant one command, to a group: Least privilege in sudo is a rule that names a group and the full path of one command, not membership of the sudo group.
- How narrow is narrow?
When someone leaves
- Lock first, delete later: Locking an account puts ! in front of its hash. It blocks the password and leaves every other way in open.
- Drill: close the other door
- Delete the user, keep the number: Deleting a user deletes a name. Files keep the uid, and the next account given that uid owns them.
Recap & playground
- Cheat sheet
- Playground