# User and Group Administration

> Chapter 8 of the Courseiva LPI-LPIC1 curriculum — https://courseiva.com/learn/lpi-lpic1/user-and-group-administration

**Official objective:** 104.2 — Manage local user and group accounts, passwords, and related configuration files.

## Introduction

Exam objective 104.2 covers managing local user and group accounts, passwords, and configuration files—the backbone of Linux security and resource sharing. Without this system, every person using a Linux computer would have the same powers and access, leading to chaos and accidental file deletions. For LPIC-1, you must master how to create, modify, and delete users and groups because controlling who can do what on a system is the first step toward being a competent Linux administrator.

## The Apartment Building Analogy

Have you ever lived in a building with a shared mailbox area? If you have, you know it's a system that works well until someone starts getting your mail. In user and group administration, every person using a Linux system is like a tenant in an apartment building. Each tenant (user) has their own flat (home directory) with a key (password) that only they should possess. The building manager (the root user) can access every flat for maintenance but gives each tenant a unique key to their own space. 

Now, what about groups? Think of them as the building's social clubs: the 'Book Club' or the 'Running Group'. Belonging to the 'Running Group' means you get access to the communal running track behind the building, regardless of which individual flat you live in. A user can be a member of multiple clubs, and the club permissions (group permissions) allow them to read or write in certain shared folders (like the club noticeboard). 

Finally, the configuration files like /etc/passwd and /etc/group are the building's master ledger—a list of all tenants, their flat numbers, and which clubs they've joined. If the ledger gets corrupted, tenants can't get into their flats or the club room. This is why managing these files with commands like useradd, usermod, and groupmod is crucial: you are updating the building's records so that everyone has exactly the right access to the right spaces, and no one accidentally gets into the wrong flat.

## Core explanation

In Linux, every process and every file is owned by a user. This ownership is what enforces security and privacy. If you log in as user 'alice', you can read Alice's files, but you cannot read Bob's files unless Bob explicitly grants you permission. This is the fundamental concept of user administration.

At the heart of this system lies the file /etc/passwd. Despite its name, this file stores a list of all user accounts on the system along with key details. Each line represents one user, with fields separated by colons. For example: alice:x:1001:1001:Alice Smith:/home/alice:/bin/bash. Let's break that down. The first field is the username ('alice'). The second field used to hold the encrypted password, but today it holds just an 'x', meaning the real password is stored in a separate, locked-down file called /etc/shadow. The third field is the User ID (UID), a numeric identifier. The fourth field is the Group ID (GID), which specifies the user's primary group. Next comes a comment field (often the user's full name), then the path to the user's home directory, and finally the user's default shell (the program that starts when they log in).

The file /etc/shadow is more sensitive. It contains the actual password hash (a scrambled version of the password), plus password expiry information. Only the root user can read this file, preventing regular users from grabbing password hashes and trying to crack them.

Similarly, group information lives in /etc/group. A line might look like: developers:x:3000:alice,bob,charlie. This shows the group name ('developers'), a placeholder for the group password (again, usually 'x'), the Group ID (3000), and a comma-separated list of members who belong to this group. Groups allow you to assign permissions to multiple users at once. For instance, instead of giving read permission to every single employee, you create a 'sales' group, assign the sales folder's group ownership to that group, and then add the relevant users to it.

How do you create these accounts? Using the command useradd. To create a new user named 'carol' with a home directory: useradd -m carol. The -m flag creates the /home/carol directory. To set her password, you run passwd carol and enter it twice. The passwd command writes the hash to /etc/shadow.

To modify an existing user, you use usermod. Want to add 'carol' to the 'developers' group? usermod -a -G developers carol. The -a flag means 'append', so you don't remove her from any groups she might already be in. The -G flag specifies the supplementary group (not her primary group).

To delete a user, use userdel. userdel -r carol removes the user and also deletes their home directory and mail spool. Without -r, the home directory remains orphaned.

For groups, the commands are groupadd, groupmod, and groupdel. groupadd finance creates a new group. groupmod -n accounting finance renames 'finance' to 'accounting'. groupdel accounting removes the group (as long as it's not any user's primary group).

Why does all this matter? Because without this structure, there is no access control. Every user could read every file, change every configuration, and delete critical system files. By assigning users and groups, you enforce the principle of least privilege—giving each person only the access they need to do their job. For LPIC-1, you need to know these commands inside out, understand the format of the three key files (passwd, shadow, group), and be able to troubleshoot common issues like 'user not in sudoers file' or 'group not found'.

## Real-world context

Imagine you are the sole IT administrator for a small marketing agency called 'Pixel & Page'. The company has 20 employees: designers, copywriters, and account managers. Your boss asks you to set up a Linux file server so everyone can share project files but with strict access controls.

Here is what you actually do, step by step.

First, you create groups for each team. You run:
- groupadd designers
- groupadd copywriters
- groupadd account_managers

Next, you create the user accounts. For a new designer named 'Diana', you run useradd -m -G designers diana. This creates her home directory and puts her in the 'designers' group as a supplementary member. Then you set her password with passwd diana. You repeat this for every employee.

Now you create the shared directories. You make a folder /projects/designs and change its group to 'designers': chown root:designers /projects/designs. You set the permissions so that members of the 'designers' group can read and write files inside it, but others cannot: chmod 2770 /projects/designs. The 2 in front sets the setgid bit, meaning new files created inside that directory will automatically inherit the 'designers' group, not the creator's primary group—this is crucial so that Diana can edit a file created by another designer without permission errors.

But a problem arises. An account manager named 'Mike' needs to read some design files for a client presentation. You add him to the 'designers' group temporarily: usermod -a -G designers mike. Now he can access the files. When the presentation is over, you remove him: gpasswd -d mike designers. This is the daily reality of user and group administration: constantly adjusting memberships to reflect changing project roles.

Eventually, a copywriter named 'Sarah' leaves the company. You need to disable her account so she can't log in, but you might need to keep her files for audits. You run usermod -L sarah to lock her password (the -L flag puts a '!' at the start of the password hash in /etc/shadow, invalidating it). After the audit period, you run userdel -r sarah to remove her completely.

You also regularly audit the /etc/passwd and /etc/group files to look for unused accounts. A quick command like awk -F: '($3 > 999) {print $1}' /etc/passwd lists all user accounts (UIDs above 999 are typically regular users, not system accounts). You cross-reference with the company's HR list to ensure no unauthorised accounts exist.

This scenario shows that user and group administration is not a one-time setup; it is an ongoing process of granting and revoking access as people join, move between teams, and leave the organisation. For the LPIC-1 exam, you need to be able to perform all these actions from the command line without a graphical interface, because real servers often have no GUI.

## Exam focus

The LPIC-1 exam 104.2 focuses heavily on command syntax and the content of configuration files. You will get questions that test your ability to predict the outcome of a specific command. Here is what you must know cold.

First, you must memorise the structure of /etc/passwd, /etc/shadow, and /etc/group. Expect questions like: 'Which field in /etc/passwd contains the user's home directory?' (the 6th field) or 'What does the 'x' in the password field mean?' (the real password is in /etc/shadow).

The exam loves to test the difference between a user's primary group (defined in /etc/passwd) and their supplementary groups (defined in /etc/group). A common trap: they ask, 'If user alice is in group 'staff' in /etc/passwd, and also in group 'admin' in /etc/group, which group is her primary group?' The answer is her primary group is the one from /etc/passwd.

Key commands to memorise:
- useradd: options include -m, -d, -s, -g, -G, -u, -c.
- usermod: options include -aG (append to supplementary groups), -l (change login name), -L (lock account), -U (unlock).
- userdel: option -r (remove home directory and mail spool).
- groupadd: option -g to specify the GID.
- groupmod: option -n (rename group).
- gpasswd: used to manage group membership list (e.g., gpasswd -a user group adds, gpasswd -d user group removes).
- passwd: to change a password. The root user can set any user's password without knowing the old one.

Trap patterns to watch for:
- They often ask what happens if you run useradd without the -m flag: the home directory is not created.
- They test that usermod without the -a flag will replace the supplementary groups, not add to them. For example, if alice is in groups A, B, C, and you run usermod -G D alice, she will only be in group D. To add D without losing A, B, C, you must use usermod -a -G D alice.
- They test that deleting a group with groupdel fails if it is still the primary group of any user. You must first change those users' primary groups using usermod -g newgroup user.
- They test password ageing using the chage command (e.g., chage -M 30 user sets max days before password must change). Questions may ask which field in /etc/shadow corresponds to the max days (field 5).

Also, expect a question about the /etc/default/useradd file, which holds default values for new users (like the default home directory base path or default shell). Modifying this file changes the behaviour of useradd without needing to specify options each time.

Finally, the exam asks about 'user quotas' (objective 104.4), but in 104.2, they focus purely on account management. Questions will not mix quotas into this objective.

To summarise: if you can write out the syntax of useradd, usermod, userdel, groupadd, groupmod, groupdel, and gpasswd from memory, and explain every field in passwd, shadow, and group, you will pass this section easily.

## Step by step

1. **Create a new user with a home directory** — Run useradd -m newusername. The -m flag tells the system to create the home directory /home/newusername. Without this flag, the user account exists but has no home directory, which can cause login issues.
2. **Set the user's password** — Run passwd newusername. You will be prompted to enter the password twice for confirmation. The system hashes the password and stores it in /etc/shadow. The password must be set before the user can log in.
3. **Add the user to supplementary groups** — Run usermod -a -G group1,group2 newusername. The -a flag is critical: it appends the user to the listed groups without removing them from groups they are already a member of. The -G flag specifies the supplementary groups.
4. **Verify the user's information** — Check the user's details by reading the relevant files: grep newusername /etc/passwd shows UID, GID, home directory, and shell. grep newusername /etc/group shows which groups they belong to. This step ensures the account was created correctly.
5. **Lock or delete the user when they leave** — To immediately revoke access without deleting data, run usermod -L newusername to lock the password. To fully remove the account later, run userdel -r newusername to delete the user and their home directory and mail spool.

## Comparisons

### Primary Group vs Supplementary Group

**Primary Group:**
- Defined in /etc/passwd in the GID field
- A user can have only one primary group
- New files created by the user belong to this group

**Supplementary Group:**
- Defined in /etc/group in the member list
- A user can belong to many supplementary groups
- Used to grant access to shared resources like project directories

### useradd vs usermod

**useradd:**
- Creates a new user account
- Does not modify existing users
- Commonly used with -m to create home directory

**usermod:**
- Modifies an existing user account
- Can change username, groups, home directory, shell
- Commonly used with -aG to add groups

### /etc/passwd vs /etc/shadow

**/etc/passwd:**
- World-readable
- Contains username, UID, GID, home directory, shell
- Password field stores 'x' placeholder

**/etc/shadow:**
- Readable only by root
- Contains password hash and expiry data
- Fields include last change date, max days, warn days

### Locking an account (usermod -L) vs Deleting an account (userdel -r)

**Locking an account (usermod -L):**
- Preserves user's files and home directory
- User cannot log in but account still exists
- Easily reversible with usermod -U

**Deleting an account (userdel -r):**
- Removes user and optionally home directory and mail spool
- Cannot be easily reversed
- Used when employee leaves permanently

## Diagram

_This diagram shows the relationships between user accounts, groups, and configuration files, along with the commands used to manage them._

```mermaid
flowchart TD
    A[User Account /etc/passwd] -->|contains UID and primary GID| B[Primary Group /etc/group]
    A -->|password hash stored in| C[/etc/shadow]
    B --> D[Supplementary Group Memberships]
    D --> E[Group Permissions on Files/Folders]
    A -->|belongs to| D
    F[useradd command] --> A
    G[groupadd command] --> B
    H[usermod command] --> A
    I[gpasswd command] --> D
```

## Common misconceptions

- **Misconception:** The /etc/passwd file stores encrypted passwords. **Reality:** The /etc/passwd file stores only a placeholder 'x' in the password field; actual password hashes are in /etc/shadow, which is only readable by root. (This misconception dates back to older Unix systems where passwords were indeed stored in /etc/passwd. Beginners see the file name and assume it still holds passwords.)
- **Misconception:** Deleting a user with userdel without any flags also deletes their home directory. **Reality:** By default, userdel does not remove the home directory or mail spool. You must use the -r flag to remove those directories. (Beginners think 'delete user' means remove everything, but Linux intentionally leaves the data behind in case an administrator wants to archive or transfer files.)
- **Misconception:** A user can only belong to one group at a time. **Reality:** A user has one primary group (defined in /etc/passwd) and can belong to many supplementary groups (defined in /etc/group). (This confusion arises because in some simple scenarios (e.g., a single-user laptop), you only see one group. But in enterprise systems, users belong to multiple groups to access different shared resources.)
- **Misconception:** The /etc/group file lists only the group name and GID. **Reality:** The /etc/group file also contains a group password field (usually empty or 'x') and a comma-separated list of group members. (Beginners often read shortened explanations online that omit the group password and members fields, leading to an incomplete understanding of the file format.)
- **Misconception:** Using usermod -g newgroup user changes only the supplementary groups. **Reality:** The -g option changes the user's primary group. To change supplementary groups, use -G (with -a to append). (The lowercase 'g' and uppercase 'G' are confusingly similar, and new users often mix them up, especially when reading man pages quickly.)

## Key takeaways

- The three critical files for local user management are /etc/passwd (user accounts), /etc/shadow (password hashes and expiry), and /etc/group (group definitions and memberships).
- The useradd -m flag is essential for creating a home directory for a new user; without it, the directory is not created automatically.
- When adding a user to supplementary groups with usermod, always use the -a flag together with -G to avoid accidentally removing the user from existing groups.
- Locking a user account with usermod -L places an exclamation mark in the password hash field of /etc/shadow, making the password invalid.
- You cannot delete a group with groupdel if it is any user's primary group; you must first change those users' primary groups to another group.
- The /etc/shadow file is readable only by the root user, which is why passwords are stored there instead of in the world-readable /etc/passwd.

## FAQ

**What is the difference between /etc/passwd and /etc/shadow?**

/etc/passwd stores user account information (username, UID, GID, home directory, shell) and is world-readable. /etc/shadow stores the encrypted password hash and password expiry data and is only readable by root.

**Why can't I delete a group with groupdel?**

If the group is set as any existing user's primary group (the GID field in /etc/passwd), groupdel will refuse to delete it. You must first change those users' primary groups using usermod -g newgroup user.

**What does the -a flag do in usermod -a -G?**

The -a flag stands for 'append'. It ensures that the user is added to the groups listed with -G without losing membership in any other supplementary groups they already belong to.

**How do I create a user without a home directory?**

Simply omit the -m flag when running useradd. For example, useradd tempuser creates the account but does not create /home/tempuser. This is useful for system accounts that don't need a home directory.

**What command do I use to rename a user?**

Use usermod -l newname oldname. For example, usermod -l jane john renames the user from 'john' to 'jane'. You may also need to rename the home directory manually with mv.

**How do I see what groups a user is in?**

Use the groups command followed by the username, e.g., groups alice. This shows all groups (primary and supplementary) that the user belongs to.

## Check your understanding

1. **Which file stores the encrypted password hash for user accounts?**

   Answer: /etc/shadow

2. **What is the purpose of the -a flag when running usermod -a -G developers alice?**

   Answer: The -a flag appends alice to the 'developers' group without removing her from any other supplementary groups she already belongs to.

3. **You run userdel bob and Bob's home directory is still there. Why?**

   Answer: Because userdel without the -r flag does not remove the home directory. You need to run userdel -r bob to remove the home directory and mail spool.

4. **What happens if you run groupdel on a group that is a primary group for some users?**

   Answer: The command fails with an error. You must first change those users' primary groups to another group using usermod -g.

5. **What does the 'x' in the password field of /etc/passwd mean?**

   Answer: It means the real password is stored in the /etc/shadow file. The 'x' is a placeholder.

---

Interactive version with quiz and diagrams: https://courseiva.com/learn/lpi-lpic1/user-and-group-administration
