| File | Check command | Purpose |
|---|---|---|
/etc/passwd | pwck | user accounts |
/etc/group | grpck | groups |
/etc/shadow | โ | password hashes and aging |
/etc/gshadow | โ | group passwords |
/etc/skel | โ | files installed by default when a user is created |
1useradd -g <GID> -G <GID2> <user> # create a user in primary group GID (and supplementary group GID2).
2usermod <options> <user> # modify a user.
3userdel -r <user> # delete a user (and its home directory).
4groupadd / groupmod / groupdel # manage groups.
5
6id -a # show all info about the current user (UID, GUID, groups, etc.) - more precise than "who am i".
7sg <group> -c '<command>' # execute a command as a different group ID (to run scripts or write to a file with group rights).
1passwd -u <user> # unlock a user account.
2echo "password" | passwd --stdin <user> # scripted password change.
1chage -l <user> # see the expiration dates.
1# list the expiry of every account
2for account in $(cut -f1 -d: /etc/passwd); do
3 echo "ACCOUNT: $account , EXPIRES: $(chage -l $account | grep 'Account expires' | awk '{print $4, $5, $6}'), CHANGED: $(chage -l $account | grep 'Last password change' | awk '{print $5, $6, $7}')";
4done
1# change the aging info interactively
2chage <user>
To unlock an account, set “Last Password Change” to -1 in chage (or use passwd -u <user>).
The /etc/sudoers file contains the set of UNIX operating-system privileges that the local administrator has granted to UNIX users.
In no case should this file be edited directly with vi; it must be edited with visudo.
1sudo : execute a command as root.
2sudo su : become root and stay root.
3sudoers : file listing the commands allowed for certain users as the superuser (or another user).
4visudo -cs : strict syntax check of the sudoers file.
sudo -i is equivalent to su - in terms of rights.sudo -i, the user password is asked.su -, the root password is asked.1sudo -l -U <user>
1# "user" runs "sudo -u target All_the_commands"
2user server=(target) NOPASSWD: ALL
1Host_Alias LOAD_BALANCERS = server1,server2
2
3Cmnd_Alias SET_VIP = \
4/sbin/ip addr add 192.168.10.12/20 broadcast 192.168.15.255 dev eth0 label eth0\:0, \
5/sbin/ip addr del 192.168.10.12/20 dev eth0, \
6/sbin/arping -U -c 1 -I eth0 192.168.10.12
7
8loaduser LOAD_BALANCERS=(root) NOPASSWD: SET_VIP
9syncuser LOAD_BALANCERS=(root) NOPASSWD: SET_VIP
In /etc/pam.d, there is one PAM file per service.
Syntax: module_type control_flag path_to_module_agent
auth โ authentication.account โ account-based restrictions (validity, time of day, etc.).session โ things that run at login/logout.password โ password updates.required โ success needed; a failure is reported but only after the rest of the stack has run.requisite โ like required, but a failure returns immediately without running the rest of the stack.sufficient โ if this module succeeds, it is the last module tested in the stack.optional โ its result is only taken into account if no other module succeeded or failed.[value=action value=action2 ...] โ advanced control: map a module result to a specific action.Sample:
1kinit <user> # obtain a ticket.
2klist # list the tickets in the cache.
1systemctl status slapd # OpenLDAP server.
2systemctl status sssd # System Security Services Daemon.
1ldapsearch -x -h <ldap-host> -b "ou=People,dc=example,dc=com" uid=<user>
DN components:
cn : common nameou : organizational unito : organizationc : countrydc : domain component 1# LDIF = the commands between EOF
2# -W prompts for the LDAP admin password
3# -w passes the password (put it in a variable)
4# bind_dn : the DN that acts as the LDAP bind user
5
6export bind_dn="CN=directory manager,DC=example,DC=org"
7
8# Modify an entry
9ldapadd -W -D "$bind_dn" -h $ldap_server -p 389 <<EOT
10dn: cn=user,ou=wiki,dc=example,dc=com
11changetype: modify
12add: memberUid
13memberUid: $login
14EOT
15
16# Create a new entry
17ldapadd -w $LDAPpwd -D "$bind_dn" -h $ldap_server -p 389 <<EOT
18dn: uid=${login},ou=People,dc=example,dc=org
19uid: ${login}
20loginShell: /bin/bash
21uidNumber: ${uid}
22gidNumber: 47110
23homeDirectory: /home/${login}
24shadowLastChange: 0
25shadowMax: -1
26objectClass: account
27objectClass: posixaccount
28objectClass: shadowaccount
29objectClass: top
30gecos: ${gecos}
31cn: ${gecos}
32userPassword: {CRYPT}`perl -e 'print crypt("${login}", "${login}")'`
33EOT