Browse Docs

Rights

In this section

  • ๐Ÿ‘ฅ Users & Groups

    Configuration files

    FileCheck commandPurpose
    /etc/passwdpwckuser accounts
    /etc/groupgrpckgroups
    /etc/shadowโ€”password hashes and aging
    /etc/gshadowโ€”group passwords
    /etc/skelโ€”files installed by default when a user is created

    Basic commands

    1useradd -g <GID> -G <GID2> <user>   # create a user in primary group GID (and supplementary group GID2).
    2usermod <options> <user>            # modify a user.
    3userdel -r <user>                   # delete a user (and its home directory).
    4groupadd / groupmod / groupdel      # manage groups.
    5
    6id -a          # show all info about the current user (UID, GUID, groups, etc.) - more precise than "who am i".
    7sg <group> -c '<command>'   # execute a command as a different group ID (to run scripts or write to a file with group rights).
    

    Password management

    1passwd -u <user>                       # unlock a user account.
    2echo "password" | passwd --stdin <user> # scripted password change.
    

    Account aging

    1chage -l <user>   # see the expiration dates.
    
    1# list the expiry of every account
    2for account in $(cut -f1 -d: /etc/passwd); do
    3  echo "ACCOUNT: $account , EXPIRES: $(chage -l $account | grep 'Account expires' | awk '{print $4, $5, $6}'), CHANGED: $(chage -l $account | grep 'Last password change' | awk '{print $5, $6, $7}')";
    4done
    
    1# change the aging info interactively
    2chage <user>
    

    To unlock an account, set “Last Password Change” to -1 in chage (or use passwd -u <user>).

  • ๐Ÿ›ก๏ธ sudo

    /etc/sudoers

    The /etc/sudoers file contains the set of UNIX operating-system privileges that the local administrator has granted to UNIX users.

    In no case should this file be edited directly with vi; it must be edited with visudo.

    1sudo          :  execute a command as root.
    2sudo su       :  become root and stay root.
    3sudoers       :  file listing the commands allowed for certain users as the superuser (or another user).
    4visudo -cs    :  strict syntax check of the sudoers file.
    
    • sudo -i is equivalent to su - in terms of rights.
      • with sudo -i, the user password is asked.
      • with su -, the root password is asked.

    Verification

    1sudo -l -U <user>
    

    Rules

    1# "user" runs "sudo -u target All_the_commands"
    2user server=(target) NOPASSWD: ALL
    

    With aliases

    1Host_Alias LOAD_BALANCERS = server1,server2
    2
    3Cmnd_Alias SET_VIP = \
    4/sbin/ip addr add 192.168.10.12/20 broadcast 192.168.15.255 dev eth0 label eth0\:0, \
    5/sbin/ip addr del 192.168.10.12/20 dev eth0, \
    6/sbin/arping -U -c 1 -I eth0 192.168.10.12
    7
    8loaduser  LOAD_BALANCERS=(root) NOPASSWD: SET_VIP
    9syncuser  LOAD_BALANCERS=(root) NOPASSWD: SET_VIP
    
  • ๐Ÿ” PAM

    /etc/pam.d

    In /etc/pam.d, there is one PAM file per service.

    Syntax: module_type control_flag path_to_module_agent

    Module types

    • auth โ€” authentication.
    • account โ€” account-based restrictions (validity, time of day, etc.).
    • session โ€” things that run at login/logout.
    • password โ€” password updates.

    Control flags

    • required โ€” success needed; a failure is reported but only after the rest of the stack has run.
    • requisite โ€” like required, but a failure returns immediately without running the rest of the stack.
    • sufficient โ€” if this module succeeds, it is the last module tested in the stack.
    • optional โ€” its result is only taken into account if no other module succeeded or failed.
    • [value=action value=action2 ...] โ€” advanced control: map a module result to a specific action.

    Sample:

  • ๐Ÿ“– LDAP & Kerberos

    Kerberos

    1kinit <user>   # obtain a ticket.
    2klist          # list the tickets in the cache.
    

    Services

    1systemctl status slapd   # OpenLDAP server.
    2systemctl status sssd    # System Security Services Daemon.
    
    1ldapsearch -x -h <ldap-host> -b "ou=People,dc=example,dc=com" uid=<user>
    

    DN components:

    • cn : common name
    • ou : organizational unit
    • o : organization
    • c : country
    • dc : domain component

    LDAP - add / modify

     1# LDIF = the commands between EOF
     2# -W prompts for the LDAP admin password
     3# -w passes the password (put it in a variable)
     4# bind_dn : the DN that acts as the LDAP bind user
     5
     6export bind_dn="CN=directory manager,DC=example,DC=org"
     7
     8# Modify an entry
     9ldapadd -W -D "$bind_dn" -h $ldap_server -p 389 <<EOT
    10dn: cn=user,ou=wiki,dc=example,dc=com
    11changetype: modify
    12add: memberUid
    13memberUid: $login
    14EOT
    15
    16# Create a new entry
    17ldapadd -w $LDAPpwd -D "$bind_dn" -h $ldap_server -p 389 <<EOT
    18dn: uid=${login},ou=People,dc=example,dc=org
    19uid: ${login}
    20loginShell: /bin/bash
    21uidNumber: ${uid}
    22gidNumber: 47110
    23homeDirectory: /home/${login}
    24shadowLastChange: 0
    25shadowMax: -1
    26objectClass: account
    27objectClass: posixaccount
    28objectClass: shadowaccount
    29objectClass: top
    30gecos: ${gecos}
    31cn: ${gecos}
    32userPassword: {CRYPT}`perl -e 'print crypt("${login}", "${login}")'`
    33EOT
    
Sunday, October 4, 2026 Monday, January 1, 1