| File | Check command | Purpose |
|---|---|---|
/etc/passwd | pwck | user accounts |
/etc/group | grpck | groups |
/etc/shadow | โ | password hashes and aging |
/etc/gshadow | โ | group passwords |
/etc/skel | โ | files installed by default when a user is created |
1useradd -g <GID> -G <GID2> <user> # create a user in primary group GID (and supplementary group GID2).
2usermod <options> <user> # modify a user.
3userdel -r <user> # delete a user (and its home directory).
4groupadd / groupmod / groupdel # manage groups.
5
6id -a # show all info about the current user (UID, GUID, groups, etc.) - more precise than "who am i".
7sg <group> -c '<command>' # execute a command as a different group ID (to run scripts or write to a file with group rights).
1passwd -u <user> # unlock a user account.
2echo "password" | passwd --stdin <user> # scripted password change.
1chage -l <user> # see the expiration dates.
1# list the expiry of every account
2for account in $(cut -f1 -d: /etc/passwd); do
3 echo "ACCOUNT: $account , EXPIRES: $(chage -l $account | grep 'Account expires' | awk '{print $4, $5, $6}'), CHANGED: $(chage -l $account | grep 'Last password change' | awk '{print $5, $6, $7}')";
4done
1# change the aging info interactively
2chage <user>
To unlock an account, set “Last Password Change” to -1 in chage (or use passwd -u <user>).