Browse Docs

๐Ÿ‘ฅ Users & Groups

Configuration files

FileCheck commandPurpose
/etc/passwdpwckuser accounts
/etc/groupgrpckgroups
/etc/shadowโ€”password hashes and aging
/etc/gshadowโ€”group passwords
/etc/skelโ€”files installed by default when a user is created

Basic commands

1useradd -g <GID> -G <GID2> <user>   # create a user in primary group GID (and supplementary group GID2).
2usermod <options> <user>            # modify a user.
3userdel -r <user>                   # delete a user (and its home directory).
4groupadd / groupmod / groupdel      # manage groups.
5
6id -a          # show all info about the current user (UID, GUID, groups, etc.) - more precise than "who am i".
7sg <group> -c '<command>'   # execute a command as a different group ID (to run scripts or write to a file with group rights).

Password management

1passwd -u <user>                       # unlock a user account.
2echo "password" | passwd --stdin <user> # scripted password change.

Account aging

1chage -l <user>   # see the expiration dates.
1# list the expiry of every account
2for account in $(cut -f1 -d: /etc/passwd); do
3  echo "ACCOUNT: $account , EXPIRES: $(chage -l $account | grep 'Account expires' | awk '{print $4, $5, $6}'), CHANGED: $(chage -l $account | grep 'Last password change' | awk '{print $5, $6, $7}')";
4done
1# change the aging info interactively
2chage <user>

To unlock an account, set “Last Password Change” to -1 in chage (or use passwd -u <user>).

Sunday, October 4, 2026 Tuesday, August 15, 2023